Windows
Analysis Report
PURCHASE ORDER & SAMPLE IMAGE.xlsx
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w7x64
- EXCEL.EXE (PID: 1236 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\EXCEL. EXE" /auto mation -Em bedding MD5: D53B85E21886D2AF9815C377537BCAC3)
- EQNEDT32.EXE (PID: 868 cmdline:
"C:\Progra m Files\Co mmon Files \Microsoft Shared\EQ UATION\EQN EDT32.EXE" -Embeddin g MD5: A87236E214F6D42A65F5DEDAC816AEC8) - word.exe (PID: 1924 cmdline:
C:\Users\u ser\AppDat a\Roaming\ word.exe MD5: 1CEC9C1FA633D554029A6402174612D1) - lyebkz.exe (PID: 2604 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\lyebkz .exe" C:\U sers\user\ AppData\Lo cal\Temp\e ktmwwvwm.t x MD5: 41467466B6E727C3C65D9501F6A23A04) - lyebkz.exe (PID: 1468 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\lyebkz. exe MD5: 41467466B6E727C3C65D9501F6A23A04)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_XML_LegacyDrawing_AutoLoad_Document | detects AutoLoad documents using LegacyDrawing | ditekSHen |
|
Exploits |
---|
Source: | Author: Joe Security: |
Source: | Author: Joe Security: |
Timestamp: | 192.168.2.225.249.163.12491795872030171 01/18/23-09:14:44.835847 |
SID: | 2030171 |
Source Port: | 49179 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491765872851779 01/18/23-09:14:10.473531 |
SID: | 2851779 |
Source Port: | 49176 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491775872851779 01/18/23-09:14:10.519471 |
SID: | 2851779 |
Source Port: | 49177 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491765872030171 01/18/23-09:14:10.473417 |
SID: | 2030171 |
Source Port: | 49176 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491785872840032 01/18/23-09:14:44.736459 |
SID: | 2840032 |
Source Port: | 49178 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491795872851779 01/18/23-09:14:44.836010 |
SID: | 2851779 |
Source Port: | 49179 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491795872840032 01/18/23-09:14:44.836010 |
SID: | 2840032 |
Source Port: | 49179 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491785872030171 01/18/23-09:14:44.736395 |
SID: | 2030171 |
Source Port: | 49178 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491765872840032 01/18/23-09:14:10.473531 |
SID: | 2840032 |
Source Port: | 49176 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491775872840032 01/18/23-09:14:10.519471 |
SID: | 2840032 |
Source Port: | 49177 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491775872030171 01/18/23-09:14:10.519401 |
SID: | 2030171 |
Source Port: | 49177 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.225.249.163.12491785872851779 01/18/23-09:14:44.736459 |
SID: | 2851779 |
Source Port: | 49178 |
Destination Port: | 587 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Exploits |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Network connect: | Jump to behavior | ||
Source: | Network connect: | Jump to behavior |
Source: | Process created: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: |
Source: | Code function: | 5_2_00405D74 | |
Source: | Code function: | 5_2_0040699E | |
Source: | Code function: | 5_2_0040290B |
Software Vulnerabilities |
---|
Source: | Code function: | 2_2_03674CE0 | |
Source: | Code function: | 2_2_03674C4F | |
Source: | Code function: | 2_2_03674D4B | |
Source: | Code function: | 2_2_03674D2B | |
Source: | Code function: | 2_2_03674C77 |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | JA3 fingerprint: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File created: | Jump to behavior |
Source: | DNS traffic detected: |
Source: | Code function: | 2_2_03674CE0 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | Windows user hook set: | Jump to behavior |
Source: | Code function: | 5_2_00405809 |
System Summary |
---|
Source: | Matched rule: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Matched rule: |
Source: | Code function: | 5_2_00403640 |
Source: | Code function: | 5_2_00406D5F | |
Source: | Code function: | 6_2_0040E0AD | |
Source: | Code function: | 6_2_0041095A | |
Source: | Code function: | 6_2_00411203 | |
Source: | Code function: | 6_2_00411A2F | |
Source: | Code function: | 6_2_0041160F | |
Source: | Code function: | 6_2_00410E2F | |
Source: | Code function: | 6_2_00409FAF | |
Source: | Code function: | 6_2_002408B7 | |
Source: | Code function: | 6_2_00240A3B |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 5_2_00403640 |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Code function: | 5_2_004021AA |
Source: | File read: | Jump to behavior |
Source: | Code function: | 5_2_00404AB5 |
Source: | Section loaded: | Jump to behavior |
Source: | OLE indicator, Workbook stream: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static file information: |
Source: | Binary string: |
Source: | Initial sample: |
Source: | Code function: | 6_2_0040296C |
Source: | Code function: | 6_2_00407856 |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Key value created or modified: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Evasive API call chain: | graph_2-233 |
Source: | WMI Queries: |
Source: | Code function: | 6_2_00401000 |
Source: | WMI Queries: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Evasive API call chain: | graph_6-11019 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Code function: | 6_2_00401000 |
Source: | Code function: | 6_2_002407DA |
Source: | Code function: | 5_2_00405D74 | |
Source: | Code function: | 5_2_0040699E | |
Source: | Code function: | 5_2_0040290B |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | API call chain: | graph_5-3480 |
Source: | Binary or memory string: |
Source: | Code function: | 6_2_00402489 |
Source: | Code function: | 6_2_00407856 |
Source: | Code function: | 6_2_0040B8DB |
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 2_2_03674D4B | |
Source: | Code function: | 6_2_0024005F | |
Source: | Code function: | 6_2_0024013E | |
Source: | Code function: | 6_2_00240109 | |
Source: | Code function: | 6_2_0024017B |
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 6_2_0040C003 | |
Source: | Code function: | 6_2_00402489 | |
Source: | Code function: | 6_2_00403689 | |
Source: | Code function: | 6_2_004057A2 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Section loaded: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 6_2_0040F063 | |
Source: | Code function: | 6_2_0040C824 | |
Source: | Code function: | 6_2_0040C83D | |
Source: | Code function: | 6_2_0040D0F3 | |
Source: | Code function: | 6_2_0040C8A7 | |
Source: | Code function: | 6_2_0040F150 | |
Source: | Code function: | 6_2_0040795E | |
Source: | Code function: | 6_2_0040F127 | |
Source: | Code function: | 6_2_0040C9E6 | |
Source: | Code function: | 6_2_0040F1F3 | |
Source: | Code function: | 6_2_0040F1B7 | |
Source: | Code function: | 6_2_00413A47 | |
Source: | Code function: | 6_2_0040CA52 | |
Source: | Code function: | 6_2_0040D34B | |
Source: | Code function: | 6_2_0040EC6E | |
Source: | Code function: | 6_2_00413CDB | |
Source: | Code function: | 6_2_0040ED85 | |
Source: | Code function: | 6_2_0040D611 | |
Source: | Code function: | 6_2_0040EE1D | |
Source: | Code function: | 6_2_0040EE91 |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 6_2_00404922 |
Source: | Code function: | 6_2_00412F46 |
Source: | Code function: | 5_2_00403640 |
Stealing of Sensitive Information |
---|
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 211 Windows Management Instrumentation | Path Interception | 1 Access Token Manipulation | 1 Disable or Modify Tools | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 1 Archive Collected Data | Exfiltration Over Other Network Medium | 3 Ingress Tool Transfer | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | 1 System Shutdown/Reboot |
Default Accounts | 1 Scripting | Boot or Logon Initialization Scripts | 111 Process Injection | 1 Deobfuscate/Decode Files or Information | 11 Input Capture | 2 File and Directory Discovery | Remote Desktop Protocol | 1 Data from Local System | Exfiltration Over Bluetooth | 11 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | 12 Native API | Logon Script (Windows) | Logon Script (Windows) | 1 Scripting | Security Account Manager | 118 System Information Discovery | SMB/Windows Admin Shares | 1 Email Collection | Automated Exfiltration | 1 Non-Standard Port | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | 23 Exploitation for Client Execution | Logon Script (Mac) | Logon Script (Mac) | 2 Obfuscated Files or Information | NTDS | 1 Query Registry | Distributed Component Object Model | 11 Input Capture | Scheduled Transfer | 2 Non-Application Layer Protocol | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 1 Masquerading | LSA Secrets | 341 Security Software Discovery | SSH | 1 Clipboard Data | Data Transfer Size Limits | 23 Application Layer Protocol | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 1 Modify Registry | Cached Domain Credentials | 131 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | 131 Virtualization/Sandbox Evasion | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | 1 Access Token Manipulation | Proc Filesystem | 1 Remote System Discovery | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue | |
Exploit Public-Facing Application | PowerShell | At (Linux) | At (Linux) | 111 Process Injection | /etc/passwd and /etc/shadow | 1 System Network Configuration Discovery | Software Deployment Tools | Data Staged | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Web Protocols | Rogue Cellular Base Station | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
56% | ReversingLabs | Document-Office.Exploit.CVE-2017-11882 | ||
60% | Virustotal | Browse | ||
100% | Avira | EXP/CVE-2017-11882.Gen |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
36% | ReversingLabs | Win32.Trojan.Nemesis | ||
36% | ReversingLabs | Win32.Trojan.Nemesis |
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | TR/Crypt.XPACK.Gen | Download File |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api4.ipify.org | 64.185.227.155 | true | false | high | |
transfer.sh | 144.76.136.153 | true | false | high | |
box.aosxer.com | 5.249.163.12 | true | true | unknown | |
api.ipify.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
144.76.136.153 | transfer.sh | Germany | 24940 | HETZNER-ASDE | false | |
64.185.227.155 | api4.ipify.org | United States | 18450 | WEBNXUS | false | |
5.249.163.12 | box.aosxer.com | Sweden | 42708 | PORTLANEwwwportlanecomSE | true |
Joe Sandbox Version: | 36.0.0 Rainbow Opal |
Analysis ID: | 786424 |
Start date and time: | 2023-01-18 09:12:19 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 7m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | PURCHASE ORDER & SAMPLE IMAGE.xlsx |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.troj.spyw.expl.evad.winXLSX@8/12@9/3 |
EGA Information: |
|
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
09:13:40 | API Interceptor | |
09:13:55 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
144.76.136.153 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
api4.ipify.org | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
HETZNER-ASDE | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
7dcce5b76c8b17472d024758970a406b | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\maxdyn2.1[1].exe
Download File
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 437857 |
Entropy (8bit): | 7.111056886494438 |
Encrypted: | false |
SSDEEP: | 6144:WYa60xbEUHi5vD/IaOHPAhsYOUWlgV75xPV/i+wgn2eMmVdbDyr4L43hTHL:WYCxtY7/83YPPF/i+wwDMm3yr48Tr |
MD5: | 1CEC9C1FA633D554029A6402174612D1 |
SHA1: | E1E78DA0AA4693520428D567C33A3A84FE921D28 |
SHA-256: | FA5CE3B72762CCAD4365AC01E3B6ADFE7864B8D4065D5C7FFA266865746A4706 |
SHA-512: | 064E23A151A88922A84F03EF110AAC9641C42651AD53FC5BCD807EF4751209FB281D5DFED718FF58D7462B75E1EBA93EE9EE173336D280092B43F04585412A1B |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\maxdyn2.1[1].htm
Download File
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 169 |
Entropy (8bit): | 4.51833957423091 |
Encrypted: | false |
SSDEEP: | 3:qVoB3tUROGclXqyvXboAcMBXqWSZUXqXlIVLLPfLRIwcWWGu:q43tISl6kXiMIWSU6XlI5LPtIpfGu |
MD5: | 84855C13836B389D5EC7CFD4C9266173 |
SHA1: | 1CF3056FF23C4176FD7CA9816A000ED461D6D323 |
SHA-256: | 502083C916AE481CDD413B8D93315300653DF5FB3DCC5770C01991DE19977EAE |
SHA-512: | 2479112004884D42D4FFE1174DC358C5D1B0FA2B41641D32F2FB67539C4F834D63CFBBF7E98C63B9A64E49B26390C410BB7E50F1AD4A755F32D081367AF05FCB |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1536 |
Entropy (8bit): | 1.1464700112623651 |
Encrypted: | false |
SSDEEP: | 3:YmsalTlLPltl2N81HRQjlORGt7RQ//W1XR9//3R9//3R9//:rl912N0xs+CFQXCB9Xh9Xh9X |
MD5: | 72F5C05B7EA8DD6059BF59F50B22DF33 |
SHA1: | D5AF52E129E15E3A34772806F6C5FBF132E7408E |
SHA-256: | 1DC0C8D7304C177AD0E74D3D2F1002EB773F4B180685A7DF6BBE75CCC24B0164 |
SHA-512: | 6FF1E2E6B99BD0A4ED7CA8A9E943551BCD73A0BEFCACE6F1B1106E88595C0846C9BB76CA99A33266FFEC2440CF6A440090F803ABBF28B208A6C7BC6310BEB39E |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Roaming\word.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6089 |
Entropy (8bit): | 7.152515480225036 |
Encrypted: | false |
SSDEEP: | 96:Farc6oYdg/DrYum6Pk2XO5oSwY26zxyI6zwOWPMjjSMCV763doT1QBDFRnToEtCg:FarcRF/hX1S92rI6zw3PMjOnVWm4zxt1 |
MD5: | 0BB62A24E1C4BA564B2955208EC425A4 |
SHA1: | 290835BE626C75982BCF6FDA4C3A30C0959E933B |
SHA-256: | 49808CA9A19F80AB31F99AFB9BE50C1AD72B454E0E05EC0CEBCB4318AF8F106E |
SHA-512: | 52C6B0568A64B0B1A0D4E50E2EEFFE982D2157E46F4BEAC1239FEF6B4518772C6225C0E4B59B79E3C9FF3B906E95AD82C135B762EA09591CDD260907BF34998F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Roaming\word.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271066 |
Entropy (8bit): | 7.971057420310617 |
Encrypted: | false |
SSDEEP: | 6144:5praAyoXuxoSOiPJqzDTyXtF+yWZtwa/AAISfplt6yJY:P+A1exoXihQDTyXtF+eAISfB6yJY |
MD5: | 4226677AC10D1E9C98E7FA0BE1801081 |
SHA1: | E653B5DDE2497E0EA31564108A0CD6BC30588091 |
SHA-256: | A9166C519742C1F3FDB958B604AA997D9F90619F63BB52EB4F4F2A40119893AE |
SHA-512: | 604AD9EAA2CC53963F2DFF1677F2AEC966023FC13E72163C9DA07F8839FC7ED08733BD388221E1460A38C65B0AAB4088C75C588DC66C0E83DEF8AA431D6DD1E3 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Roaming\word.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 102400 |
Entropy (8bit): | 6.5023788666751425 |
Encrypted: | false |
SSDEEP: | 1536:UoJrPl54EsPLskvqzGUUzKx0sDuEse2OdHL8JiuGISrFuDthslJ5:7JBC/PLdXUUzKxbuBJi9+hsH5 |
MD5: | 41467466B6E727C3C65D9501F6A23A04 |
SHA1: | 9FD6FEEA3C5F566571A5499A3DFF7777C2BD642E |
SHA-256: | 10E0B5018E1B719E9E06C97E5A42E73B6F6E43400D512DFE641488D473B60BB0 |
SHA-512: | 63B304710504834B5E139A48FBD8C6D483FE3D828187752FFB77E1D2AF76BCC08F9F1B8CD7D314EF36AC26F286F95C652298C8EA69A915E4CFB83AAC7A72334E |
Malicious: | true |
Preview: |
Process: | C:\Users\user\AppData\Roaming\word.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 391675 |
Entropy (8bit): | 7.717276941987671 |
Encrypted: | false |
SSDEEP: | 6144:ApraAyoXuxoSOiPJqzDTyXtF+yWZtwa/AAISfplt6yJoG2PLdXUiKx:A+A1exoXihQDTyXtF+eAISfB6yJoGmJK |
MD5: | B3C6FF655C39C19AEB67C868B59D9EEA |
SHA1: | D73532A8010A9A23C33B9518A6BEF306BDFB1A30 |
SHA-256: | 80C5D55745ADA2AFB3D89DB60A30B3BF53144366EACB27E6D64E487350E9452B |
SHA-512: | 58E4F5CD697D2951F6B50BB0008A81A9C4058EA8FF93D23D3D2288F1BB39BF561E2FA5A310ACFB40443D453BFC4B68CCB895476F04A9C0D9381AD04BD8504B4B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1527808 |
Entropy (8bit): | 7.441644636879638 |
Encrypted: | false |
SSDEEP: | 24576:HItAjrBHn7n623BhtYSupBEE4VDHKJ2nIphalaq8E57SiVc8A3QA48kBlPM:UAHj62ju0EOqhhFvEpSwcxdk |
MD5: | D9E7D18852579B0B72FCF6D015753D2D |
SHA1: | 5EA807AB3629865DB9367B9B0BE474416E18A44A |
SHA-256: | 779CADBEF88550653A7A0D84D728D0F63C15D5A37F7F408382CDC5DEDBE14062 |
SHA-512: | B87677ADA7E640A9C24AC2130CE6B3A97A633882B49E4233A534E13E8AD665586610A05B2825369574090C3BEB955C7A216266DC1F36668440B6E60661146D37 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 437857 |
Entropy (8bit): | 7.111056886494438 |
Encrypted: | false |
SSDEEP: | 6144:WYa60xbEUHi5vD/IaOHPAhsYOUWlgV75xPV/i+wgn2eMmVdbDyr4L43hTHL:WYCxtY7/83YPPF/i+wwDMm3yr48Tr |
MD5: | 1CEC9C1FA633D554029A6402174612D1 |
SHA1: | E1E78DA0AA4693520428D567C33A3A84FE921D28 |
SHA-256: | FA5CE3B72762CCAD4365AC01E3B6ADFE7864B8D4065D5C7FFA266865746A4706 |
SHA-512: | 064E23A151A88922A84F03EF110AAC9641C42651AD53FC5BCD807EF4751209FB281D5DFED718FF58D7462B75E1EBA93EE9EE173336D280092B43F04585412A1B |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\lyebkz.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28672 |
Entropy (8bit): | 0.9650411582864293 |
Encrypted: | false |
SSDEEP: | 48:T2loMLOpEO5J/KdGU1jX983Gul4kEBrvK5GYWgqRSESXh:inNww9t9wGAE |
MD5: | 903C35B27A5774A639A90D5332EEF8E0 |
SHA1: | 5A8CE0B6C13D1AF00837AA6CA1AA39000D4EB7CF |
SHA-256: | 1159B5AE357F89C56FA23C14378FF728251E6BDE6EEA979F528DB11C4030BE74 |
SHA-512: | 076BD35B0D59FFA7A52588332A862814DDF049EE59E27542A2DA10E7A5340758B8C8ED2DEFE78C5B5A89EE54C19A89D49D2B86B49BF5542D76C1D4A378B40277 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\yn4sky33.ptd\Firefox\Profiles\7xwghk55.default\cookies.sqlite
Download File
Process: | C:\Users\user\AppData\Local\Temp\lyebkz.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 524288 |
Entropy (8bit): | 0.08107860342777487 |
Encrypted: | false |
SSDEEP: | 48:DO8rmWT8cl+fpNDId7r+gUEl1B6nB6UnUqc8AqwIhY5wXwwAVshT:DOUm7ii+7Ue1AQ98VVY |
MD5: | 1138F6578C48F43C5597EE203AFF5B27 |
SHA1: | 9B55D0A511E7348E507D818B93F1C99986D33E7B |
SHA-256: | EEEDF71E8E9A3A048022978336CA89A30E014AE481E73EF5011071462343FFBF |
SHA-512: | 6D6D7ECF025650D3E2358F5E2D17D1EC8D6231C7739B60A74B1D8E19D1B1966F5D88CC605463C3E26102D006E84D853E390FFED713971DC1D79EB1AB6E56585E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.4377382811115937 |
Encrypted: | false |
SSDEEP: | 3:vZ/FFDJw2fV:vBFFGS |
MD5: | 797869BB881CFBCDAC2064F92B26E46F |
SHA1: | 61C1B8FBF505956A77E9A79CE74EF5E281B01F4B |
SHA-256: | D4E4008DD7DFB936F22D9EF3CC569C6F88804715EAB8101045BA1CD0B081F185 |
SHA-512: | 1B8350E1500F969107754045EB84EA9F72B53498B1DC05911D6C7E771316C632EA750FBCE8AD3A82D664E3C65CC5251D0E4A21F750911AE5DC2FC3653E49F58D |
Malicious: | true |
Preview: |
File type: | |
Entropy (8bit): | 7.9985592022971685 |
TrID: |
|
File name: | PURCHASE ORDER & SAMPLE IMAGE.xlsx |
File size: | 1299605 |
MD5: | 27f586f26da21955c782e9268ad1c4ce |
SHA1: | b9be1204d078c487f6ade5e2a6cd2164c46a7996 |
SHA256: | 2d46eee159ec36ab5e9f8bc29a7e0464c9b1be8c3454cdb8c9880640dcfda02f |
SHA512: | 8dd0dde10816b2f2653492c9a942454862fe4ff6607ceef511bde7899d2678b61d576c6e336a5b351a384e8acc06557ad13877f6c3d290c08d14402f5b038c65 |
SSDEEP: | 24576:M3+8kJrnHnTNAu3BhBYSApBiQSxDH+4+Wn7EpfYlHB0lW9ZbKY+q7JCYcqt:MP0HhAwjAyQ+e4bnoYFBHZF+qNZt |
TLSH: | ED5533E65038D45CEF0998B250EDD7565A31A0D610DBD0E2B2FC5CBA10BBFF5E268AD0 |
File Content Preview: | PK........T.2V.m.]....i.......[Content_Types].xmlUT...BR.cBR.cBR.c.UKO.1.....6.....1......h.....P..M;...N........l.i..|.G.fY.l.!jg....,.+..v\...]..e..U.8..[Ad7..'...C..mc.&....('P..;..fF....7...r&........"Xl`.`..>..ZA.,.>..t..p$6X.[9.....&........9.[.C..F |
Icon Hash: | e4e2aa8aa4b4bcb4 |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Author: | |
Last Saved By: | |
Create Time: | 2022-11-18T02:05:27Z |
Last Saved Time: | 2022-11-18T02:07:12Z |
Creating Application: | |
Security: | 0 |
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
Stream Path: | \x1ole10NATIVe |
File Type: | data |
Stream Size: | 1508006 |
Entropy: | 7.438472943097563 |
Base64 Encoded: | True |
Data ASCII: | Y . . & 2 . . | B . . . V - q . - 3 R . . . 1 . . o . . " F A . W @ K . ! i . . , A f U B x [ ) . u : . . . . V S . % . d . U S H _ ( . 1 R L / [ 3 } u ~ . . k . L q . S x s \\ . H > n x . z k , . c s f t . . * S c , ) . & . . 2 . R ] . 7 1 o U * J E . 7 E v m , & i b 4 . # 3 n o . c . e v . . / p q a 6 H % . M > . 6 . = 6 V [ U m \\ a f ) Y 3 7 : = J . 6 h . . ~ . b i . . c . K . L 7 [ o c ) . ^ _ 9 . L . ) B W + . M t . a . . Q . . w 8 . . 3 7 . . F r j 0 . { . H 0 . { . } . . g . ) H G 9 . . m . |
Data Raw: | 59 b3 93 04 03 20 26 ed 32 ce 01 08 b5 7c b9 c3 42 ba ff f7 d1 8b 19 8b 13 bb 8e d9 56 2d 81 eb de 71 10 2d 8b 33 52 ff d6 05 c7 96 03 31 05 9c b1 06 cf ff e0 6f e9 14 c5 18 22 46 41 00 57 c5 f6 96 40 4b bd f3 19 a7 8e 21 f5 be 69 d9 8c 06 9a 2c 41 66 8c 55 cb d0 42 78 5b 29 0a f4 75 ea 3a e7 96 af 9a 01 96 e6 2e e2 fa 16 9a 9a 56 b8 e7 53 12 bb 25 06 80 99 64 a0 91 9b 03 ee 55 53 |
General | |
Stream Path: | rSp6HEeS5QRFS |
File Type: | empty |
Stream Size: | 0 |
Entropy: | 0.0 |
Base64 Encoded: | False |
Data ASCII: | |
Data Raw: |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.225.249.163.12491795872030171 01/18/23-09:14:44.835847 | TCP | 2030171 | ET TROJAN AgentTesla Exfil Via SMTP | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491765872851779 01/18/23-09:14:10.473531 | TCP | 2851779 | ETPRO TROJAN Agent Tesla Telegram Exfil | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491775872851779 01/18/23-09:14:10.519471 | TCP | 2851779 | ETPRO TROJAN Agent Tesla Telegram Exfil | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491765872030171 01/18/23-09:14:10.473417 | TCP | 2030171 | ET TROJAN AgentTesla Exfil Via SMTP | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491785872840032 01/18/23-09:14:44.736459 | TCP | 2840032 | ETPRO TROJAN Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491795872851779 01/18/23-09:14:44.836010 | TCP | 2851779 | ETPRO TROJAN Agent Tesla Telegram Exfil | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491795872840032 01/18/23-09:14:44.836010 | TCP | 2840032 | ETPRO TROJAN Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491785872030171 01/18/23-09:14:44.736395 | TCP | 2030171 | ET TROJAN AgentTesla Exfil Via SMTP | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491765872840032 01/18/23-09:14:10.473531 | TCP | 2840032 | ETPRO TROJAN Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491775872840032 01/18/23-09:14:10.519471 | TCP | 2840032 | ETPRO TROJAN Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491775872030171 01/18/23-09:14:10.519401 | TCP | 2030171 | ET TROJAN AgentTesla Exfil Via SMTP | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
192.168.2.225.249.163.12491785872851779 01/18/23-09:14:44.736459 | TCP | 2851779 | ETPRO TROJAN Agent Tesla Telegram Exfil | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 18, 2023 09:13:37.180238008 CET | 49173 | 80 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.283632040 CET | 80 | 49173 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.283818960 CET | 49173 | 80 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.285243988 CET | 49173 | 80 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.385544062 CET | 80 | 49173 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.385618925 CET | 80 | 49173 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.385747910 CET | 49173 | 80 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.445662022 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.445740938 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.445817947 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.482435942 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.482506037 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.876799107 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.877036095 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.888057947 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:37.888099909 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.888847113 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:37.888950109 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:38.243690014 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:38.243752003 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:39.916760921 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:39.916841984 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:39.916862011 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:39.916896105 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:39.916919947 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:39.916929007 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:39.916946888 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:39.916954041 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:39.916981936 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:39.917001963 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:39.927768946 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.117497921 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.117599964 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.117796898 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.117796898 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.117837906 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.117939949 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.118000031 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.328938007 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.328959942 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.329016924 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.329107046 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.329137087 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.329157114 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.329185963 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.329344034 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.548795938 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.548815966 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.548871994 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.548922062 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.548962116 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.548983097 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.549010038 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.549099922 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.766771078 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.766789913 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.766839027 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.766870975 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.766910076 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.766937017 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.766962051 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.767075062 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.986762047 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.986785889 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.986843109 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.986949921 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.986984015 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:40.987025023 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.987145901 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:40.987145901 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.205790043 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.205815077 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.205904007 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.206020117 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.206053972 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.206075907 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.206111908 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.206320047 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.492043018 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.492073059 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.492158890 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.492260933 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.492301941 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.492325068 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.492352962 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.493026972 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.695800066 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.695921898 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.695972919 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.696027994 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.696052074 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.696079969 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.697871923 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.903736115 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.903769970 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.903872013 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.903944016 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.903990984 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:41.904014111 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.904046059 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:41.904125929 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.118447065 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.118483067 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.118596077 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.118653059 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.118697882 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.118752956 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.118753910 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.118777990 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.335366964 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.335382938 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.335453987 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.335556984 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.335556984 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.335617065 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.335685968 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.335988045 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.557482004 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.557502985 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.557583094 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.557725906 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.557745934 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.557777882 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.557812929 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.557849884 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.779103994 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.779136896 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.779232025 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.779329062 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.779356956 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.779376984 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.779416084 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.779665947 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.992285013 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.992315054 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.992409945 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.992444038 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.992501020 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.992531061 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:42.992551088 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.992571115 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:42.992594957 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.195091009 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.195148945 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.195192099 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.195224047 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.195245028 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.195272923 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.195302963 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.404614925 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.404634953 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.404720068 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.407582998 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.407650948 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.407700062 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.407731056 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.667983055 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.668000937 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.668098927 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.668214083 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.668272972 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.668344975 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.668345928 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.668441057 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.864828110 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.865022898 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:43.865125895 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:43.865206957 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.082638979 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.082659006 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.082742929 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.082801104 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.082828045 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.082847118 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.082907915 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.301877975 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.301897049 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.301968098 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.302005053 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.302033901 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.302048922 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.302078962 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.302104950 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.521163940 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.521190882 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.521260977 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.521378994 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.521421909 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.521446943 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.521521091 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.737245083 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.737271070 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.737351894 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.737360001 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.737406015 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.737468958 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.737468958 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.737658024 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.955670118 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.955693007 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.955837965 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:44.955943108 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:44.956038952 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.172607899 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.172633886 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.172724962 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.172771931 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.172836065 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.172871113 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.172900915 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.172934055 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.411861897 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.411891937 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.412051916 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.412164927 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.412166119 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.412166119 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.412208080 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.412276983 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.417505980 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.647434950 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.647607088 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.647614956 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.647706985 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.647805929 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.647902012 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.647933006 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.647964001 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.647991896 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.648035049 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:45.648103952 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.658844948 CET | 49174 | 443 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:45.658916950 CET | 443 | 49174 | 144.76.136.153 | 192.168.2.22 |
Jan 18, 2023 09:13:47.734744072 CET | 49173 | 80 | 192.168.2.22 | 144.76.136.153 |
Jan 18, 2023 09:13:50.375940084 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:50.376005888 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:50.376076937 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:50.381963015 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:50.382021904 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:50.593578100 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:50.593705893 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:50.613028049 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:50.613063097 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:50.613466978 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:50.822707891 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:50.822763920 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:51.025367975 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:51.025432110 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:51.124214888 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:51.124394894 CET | 443 | 49175 | 64.185.227.155 | 192.168.2.22 |
Jan 18, 2023 09:13:51.124540091 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:13:51.128101110 CET | 49175 | 443 | 192.168.2.22 | 64.185.227.155 |
Jan 18, 2023 09:14:09.513322115 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:09.547471046 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:09.620074034 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.620223045 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:09.654150963 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.654859066 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:09.816689014 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.819118023 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:09.862719059 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.863631964 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:09.925839901 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.925865889 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.927025080 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:09.970155954 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.970180988 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:09.970788002 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.033765078 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.033795118 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.034210920 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.077294111 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.077316999 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.077759981 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.140856981 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.141030073 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.141267061 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.184232950 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.184400082 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.184632063 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.249211073 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.249617100 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.297579050 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.298491001 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.362848997 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.363501072 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.411957026 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.412193060 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.470576048 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.473251104 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.473417044 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.473531008 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.474004030 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.480230093 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.518968105 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.519309044 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.519401073 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.519470930 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.519629955 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.528392076 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.579925060 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.580013037 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.580506086 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.625828028 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.626013041 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.626106977 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.631409883 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.631589890 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.675424099 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.675527096 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.686727047 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.686893940 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.732920885 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.734703064 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.738323927 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.738351107 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.738465071 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.782140970 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.782186031 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.782397985 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.793741941 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.793880939 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.836050987 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.836429119 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.841180086 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.841365099 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.845184088 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.845216036 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.845428944 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.883816957 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.885790110 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.888948917 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.889071941 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.900585890 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.900692940 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.943214893 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.945058107 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.947866917 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.947969913 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.952224016 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.952246904 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.952263117 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.952277899 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.952397108 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.952459097 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.992424965 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.995671988 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.995712042 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.995737076 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.995764017 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.995876074 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.995876074 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:10.995990992 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:10.996870041 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.007493019 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.007550001 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.007678986 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.051887035 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.051939964 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.052171946 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.054435015 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.054595947 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.059164047 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.059237003 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.059292078 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.059427977 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.059448957 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.059484005 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.059493065 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.059570074 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.059578896 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.059650898 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.095434904 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.095757008 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.102468014 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.102549076 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.102581978 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.102711916 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.102780104 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.102782011 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.102816105 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.102850914 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.102931976 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.102977991 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.102979898 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.103055954 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.103074074 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.103138924 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.103257895 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.103288889 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.103355885 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.103414059 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.107346058 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.109458923 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.114639044 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.114681959 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.114733934 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.114765882 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.114800930 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.114929914 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.115005970 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.159364939 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159410000 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159446001 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159478903 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159591913 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.159591913 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.159645081 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159650087 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.159681082 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159754038 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.159754038 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.159784079 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159821033 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.159876108 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.159888983 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.161200047 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.161334038 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.161339045 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.161379099 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.161448956 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.161448956 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.166299105 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.166433096 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.166445971 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.166546106 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.166593075 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.166685104 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.166779995 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.166896105 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.166898012 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.166963100 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167078018 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167143106 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167197943 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167231083 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167311907 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167349100 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167382002 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167416096 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167449951 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167484045 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167516947 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167551994 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167586088 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167623043 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167655945 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167690992 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167726040 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167759895 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167793036 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167826891 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167861938 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167896032 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.167929888 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.202400923 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.202455044 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.202614069 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.209567070 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209641933 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209666014 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209692001 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209707975 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209834099 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209849119 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209862947 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.209862947 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.209934950 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.209964037 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.209970951 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210037947 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.210038900 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.210093975 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210108042 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210124969 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210206032 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.210222006 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210237980 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210308075 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210354090 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210403919 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210417986 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210433006 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210478067 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210500956 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210634947 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210661888 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210676908 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210702896 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210753918 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210769892 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210818052 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210887909 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210916996 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.210980892 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211028099 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211076975 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211093903 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211138010 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211184025 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211314917 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211340904 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.211389065 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.216134071 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.216150999 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221633911 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221673012 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221688986 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221703053 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221719027 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221748114 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221801043 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.221817017 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.222095013 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.222122908 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.222141027 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.222157955 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.266971111 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267122030 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267162085 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267199039 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267234087 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267270088 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267306089 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267343044 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267376900 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267430067 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267466068 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267503023 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267537117 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267573118 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267607927 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267646074 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267944098 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.267980099 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.268043041 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.268079042 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.268136978 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.268172979 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.268210888 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.268246889 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.274885893 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.274939060 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.274972916 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.275006056 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.275038004 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.275070906 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.275177956 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.275214911 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.275276899 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.309241056 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.309288979 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.309329987 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.316524029 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.316680908 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.316716909 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.316775084 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.316869974 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.316941977 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.316994905 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317032099 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317228079 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317359924 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317466974 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317538977 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317573071 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317679882 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317713976 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317747116 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317801952 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317835093 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317869902 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317903996 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317938089 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.317991018 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.318025112 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.318061113 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.326529980 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.329830885 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.433290958 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.489886999 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:11.537996054 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:11.694155931 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.660346985 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.660383940 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.767115116 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.767209053 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.767231941 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.767266989 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.767640114 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.767762899 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.767863989 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.767913103 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.768079996 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.768182039 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.771589994 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.863922119 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.874460936 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.874716043 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.877875090 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.878032923 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:43.973747969 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:43.973946095 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.093992949 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.094849110 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.172585964 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.173003912 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.201325893 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.201376915 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.201699018 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.282825947 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.282885075 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.283142090 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.308109999 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.308166981 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.308707952 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.392976046 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.393027067 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.393552065 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.415131092 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.415210009 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.415443897 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.503406048 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.503458977 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.504333019 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.522053003 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.522304058 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.614322901 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.614756107 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.629196882 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.629569054 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.725070953 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.725398064 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.735939026 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.736295938 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.736394882 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.736459017 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.736548901 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.750972033 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.835278034 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.835746050 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.835846901 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.836009979 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.836137056 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.842153072 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.842519045 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.842578888 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.842667103 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.899209976 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.899338007 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.945370913 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.945472002 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.945489883 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.949013948 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.949114084 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:44.994355917 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:44.994704008 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.005640984 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.005680084 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.005743027 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.005743027 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.055155993 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.055340052 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.055432081 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.055489063 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.103162050 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.104316950 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.104350090 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.104604006 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.104675055 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.112056017 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.112082958 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.112348080 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.161839008 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.162092924 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.165035963 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.165185928 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.210309982 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.210747004 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.210834026 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.210908890 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.214274883 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.217061043 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.218660116 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.218713045 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.218727112 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.218786955 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.218835115 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.263268948 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.266869068 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.268383026 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.268513918 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.274317026 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.274641991 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.274816036 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.317318916 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.317403078 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.317677975 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.320420027 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.321064949 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.324956894 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.325030088 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.325090885 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.325109959 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.325138092 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.325169086 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.325174093 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.325208902 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.325211048 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.325243950 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.325257063 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.325284004 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.325316906 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.326915026 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.329946995 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.373394012 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.374653101 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.374787092 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.374824047 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.374856949 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.374883890 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.374891043 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.374974966 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.374974966 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.374974966 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.375004053 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.384593964 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.384651899 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.384673119 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.384979010 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.424161911 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424217939 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424253941 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424288034 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424326897 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424371958 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424396038 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.424418926 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424439907 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.424467087 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.424483061 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.424525023 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.424525023 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.424551010 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.424567938 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.430867910 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431447983 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431519032 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431602955 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431627035 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.431653976 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431663036 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.431675911 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.431693077 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431719065 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.431729078 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.431756973 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431802034 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431811094 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.431854010 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431910992 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.431946993 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432018042 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432070971 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432136059 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432245016 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432308912 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432362080 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432394981 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432425976 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432457924 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432487965 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432523012 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432564020 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432626009 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432665110 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432718992 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432765007 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432811022 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.432952881 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.439944983 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.440017939 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.440056086 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.440090895 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.440124989 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.440201998 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.440325975 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.440325975 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.440365076 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.481925964 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.481992006 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482029915 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482065916 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482101917 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482136965 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482198000 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482234955 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482269049 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482302904 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482336998 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482369900 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482403040 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482438087 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482472897 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.482659101 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.495009899 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.495068073 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.495093107 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.495115042 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.495434999 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.530966997 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531013966 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531045914 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531085968 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531110048 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531133890 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531162977 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531182051 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531210899 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531229973 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531248093 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531270981 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531295061 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531312943 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531332016 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.531374931 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539150000 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539182901 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539215088 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539233923 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539263964 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539292097 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539309025 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.539325953 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.542951107 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.543006897 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.543034077 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.543082952 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.543107986 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.543131113 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.543173075 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.543173075 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.543272972 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.543272972 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.546597958 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.550050974 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550131083 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550175905 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550225019 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550259113 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.550259113 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.550283909 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550323009 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550344944 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.550349951 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550389051 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550393105 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.550420046 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.550429106 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550465107 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550491095 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550514936 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550538063 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550563097 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550682068 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550764084 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550796986 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550820112 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.550843000 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.592538118 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.592580080 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605424881 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605550051 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605618954 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605765104 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605798006 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605832100 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605865955 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605901957 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605937004 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.605969906 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606003046 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606036901 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606070042 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606103897 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606136084 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606169939 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606204987 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606237888 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606271029 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.606307030 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653168917 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653232098 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653253078 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653287888 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653321981 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653392076 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653426886 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653460979 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653495073 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653529882 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.653563976 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660456896 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660525084 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660592079 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660629034 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660737038 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660773039 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660825968 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660892963 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660944939 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.660978079 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.661012888 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.661046982 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.661078930 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.661113977 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.661145926 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.661179066 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.661443949 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:45.704210997 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.771332026 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.820247889 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 |
Jan 18, 2023 09:14:45.923527956 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 |
Jan 18, 2023 09:14:46.032838106 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 18, 2023 09:13:37.146893978 CET | 55868 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:13:37.166675091 CET | 53 | 55868 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:13:50.304089069 CET | 49688 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:13:50.320935965 CET | 53 | 49688 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:13:50.332366943 CET | 58836 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:13:50.349430084 CET | 53 | 58836 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:14:09.471867085 CET | 50134 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:14:09.493438005 CET | 53 | 50134 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:14:09.494229078 CET | 50134 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:14:09.498119116 CET | 55275 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:14:09.511863947 CET | 53 | 50134 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:14:09.545176983 CET | 53 | 55275 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:14:43.800529003 CET | 59915 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:14:43.820194006 CET | 53 | 59915 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:14:43.820513010 CET | 59915 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:14:43.841638088 CET | 53 | 59915 | 8.8.8.8 | 192.168.2.22 |
Jan 18, 2023 09:14:43.842207909 CET | 59915 | 53 | 192.168.2.22 | 8.8.8.8 |
Jan 18, 2023 09:14:43.862047911 CET | 53 | 59915 | 8.8.8.8 | 192.168.2.22 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 18, 2023 09:13:37.146893978 CET | 192.168.2.22 | 8.8.8.8 | 0x1fed | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:13:50.304089069 CET | 192.168.2.22 | 8.8.8.8 | 0xf7d9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:13:50.332366943 CET | 192.168.2.22 | 8.8.8.8 | 0xbb97 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:14:09.471867085 CET | 192.168.2.22 | 8.8.8.8 | 0x1f14 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:14:09.494229078 CET | 192.168.2.22 | 8.8.8.8 | 0x1f14 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:14:09.498119116 CET | 192.168.2.22 | 8.8.8.8 | 0xaee8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:14:43.800529003 CET | 192.168.2.22 | 8.8.8.8 | 0x2aaf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:14:43.820513010 CET | 192.168.2.22 | 8.8.8.8 | 0x2aaf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2023 09:14:43.842207909 CET | 192.168.2.22 | 8.8.8.8 | 0x2aaf | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 18, 2023 09:13:37.166675091 CET | 8.8.8.8 | 192.168.2.22 | 0x1fed | No error (0) | 144.76.136.153 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.320935965 CET | 8.8.8.8 | 192.168.2.22 | 0xf7d9 | No error (0) | api4.ipify.org | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.320935965 CET | 8.8.8.8 | 192.168.2.22 | 0xf7d9 | No error (0) | 64.185.227.155 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.320935965 CET | 8.8.8.8 | 192.168.2.22 | 0xf7d9 | No error (0) | 173.231.16.75 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.320935965 CET | 8.8.8.8 | 192.168.2.22 | 0xf7d9 | No error (0) | 104.237.62.211 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.349430084 CET | 8.8.8.8 | 192.168.2.22 | 0xbb97 | No error (0) | api4.ipify.org | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.349430084 CET | 8.8.8.8 | 192.168.2.22 | 0xbb97 | No error (0) | 64.185.227.155 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.349430084 CET | 8.8.8.8 | 192.168.2.22 | 0xbb97 | No error (0) | 173.231.16.75 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:13:50.349430084 CET | 8.8.8.8 | 192.168.2.22 | 0xbb97 | No error (0) | 104.237.62.211 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:14:09.493438005 CET | 8.8.8.8 | 192.168.2.22 | 0x1f14 | No error (0) | 5.249.163.12 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:14:09.511863947 CET | 8.8.8.8 | 192.168.2.22 | 0x1f14 | No error (0) | 5.249.163.12 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:14:09.545176983 CET | 8.8.8.8 | 192.168.2.22 | 0xaee8 | No error (0) | 5.249.163.12 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:14:43.820194006 CET | 8.8.8.8 | 192.168.2.22 | 0x2aaf | No error (0) | 5.249.163.12 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:14:43.841638088 CET | 8.8.8.8 | 192.168.2.22 | 0x2aaf | No error (0) | 5.249.163.12 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2023 09:14:43.862047911 CET | 8.8.8.8 | 192.168.2.22 | 0x2aaf | No error (0) | 5.249.163.12 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.22 | 49174 | 144.76.136.153 | 443 | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.22 | 49175 | 64.185.227.155 | 443 | C:\Users\user\AppData\Local\Temp\lyebkz.exe |
Timestamp | kBytes transferred | Direction | Data |
---|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.22 | 49173 | 144.76.136.153 | 80 | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jan 18, 2023 09:13:37.285243988 CET | 0 | OUT | |
Jan 18, 2023 09:13:37.385618925 CET | 1 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.22 | 49174 | 144.76.136.153 | 443 | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-01-18 08:13:38 UTC | 0 | OUT | |
2023-01-18 08:13:39 UTC | 0 | IN | |
2023-01-18 08:13:39 UTC | 0 | IN | |
2023-01-18 08:13:40 UTC | 16 | IN | |
2023-01-18 08:13:40 UTC | 32 | IN | |
2023-01-18 08:13:40 UTC | 48 | IN | |
2023-01-18 08:13:40 UTC | 64 | IN | |
2023-01-18 08:13:40 UTC | 80 | IN | |
2023-01-18 08:13:41 UTC | 96 | IN | |
2023-01-18 08:13:41 UTC | 112 | IN | |
2023-01-18 08:13:41 UTC | 128 | IN | |
2023-01-18 08:13:41 UTC | 144 | IN | |
2023-01-18 08:13:42 UTC | 160 | IN | |
2023-01-18 08:13:42 UTC | 176 | IN | |
2023-01-18 08:13:42 UTC | 192 | IN | |
2023-01-18 08:13:42 UTC | 208 | IN | |
2023-01-18 08:13:42 UTC | 224 | IN | |
2023-01-18 08:13:43 UTC | 240 | IN | |
2023-01-18 08:13:43 UTC | 256 | IN | |
2023-01-18 08:13:43 UTC | 272 | IN | |
2023-01-18 08:13:43 UTC | 288 | IN | |
2023-01-18 08:13:44 UTC | 304 | IN | |
2023-01-18 08:13:44 UTC | 320 | IN | |
2023-01-18 08:13:44 UTC | 336 | IN | |
2023-01-18 08:13:44 UTC | 352 | IN | |
2023-01-18 08:13:44 UTC | 368 | IN | |
2023-01-18 08:13:45 UTC | 384 | IN | |
2023-01-18 08:13:45 UTC | 400 | IN | |
2023-01-18 08:13:45 UTC | 416 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.22 | 49175 | 64.185.227.155 | 443 | C:\Users\user\AppData\Local\Temp\lyebkz.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-01-18 08:13:51 UTC | 428 | OUT | |
2023-01-18 08:13:51 UTC | 428 | IN | |
2023-01-18 08:13:51 UTC | 428 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Jan 18, 2023 09:14:09.816689014 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 220 box.localdomain ESMTP Postfix (Debian/GNU) |
Jan 18, 2023 09:14:09.819118023 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 | EHLO 813435 |
Jan 18, 2023 09:14:09.862719059 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 220 box.localdomain ESMTP Postfix (Debian/GNU) |
Jan 18, 2023 09:14:09.863631964 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 | EHLO 813435 |
Jan 18, 2023 09:14:09.925865889 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 250-box.localdomain 250-PIPELINING 250-SIZE 10240000 250-VRFY 250-ETRN 250-STARTTLS 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250-SMTPUTF8 250 CHUNKING |
Jan 18, 2023 09:14:09.927025080 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 | AUTH login Z21AYW9zeGVyLmNvbQ== |
Jan 18, 2023 09:14:09.970180988 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 250-box.localdomain 250-PIPELINING 250-SIZE 10240000 250-VRFY 250-ETRN 250-STARTTLS 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250-SMTPUTF8 250 CHUNKING |
Jan 18, 2023 09:14:09.970788002 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 | AUTH login Z21AYW9zeGVyLmNvbQ== |
Jan 18, 2023 09:14:10.033795118 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 334 UGFzc3dvcmQ6 |
Jan 18, 2023 09:14:10.077316999 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 334 UGFzc3dvcmQ6 |
Jan 18, 2023 09:14:10.141030073 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 235 2.7.0 Authentication successful |
Jan 18, 2023 09:14:10.141267061 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 | MAIL FROM:<gm@aosxer.com> |
Jan 18, 2023 09:14:10.184400082 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 235 2.7.0 Authentication successful |
Jan 18, 2023 09:14:10.184632063 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 | MAIL FROM:<gm@aosxer.com> |
Jan 18, 2023 09:14:10.249211073 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 250 2.1.0 Ok |
Jan 18, 2023 09:14:10.249617100 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 | RCPT TO:<reportcard@aosxer.com> |
Jan 18, 2023 09:14:10.297579050 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 250 2.1.0 Ok |
Jan 18, 2023 09:14:10.298491001 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 | RCPT TO:<reportcard@aosxer.com> |
Jan 18, 2023 09:14:10.362848997 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 250 2.1.5 Ok |
Jan 18, 2023 09:14:10.363501072 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 | DATA |
Jan 18, 2023 09:14:10.411957026 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 250 2.1.5 Ok |
Jan 18, 2023 09:14:10.412193060 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 | DATA |
Jan 18, 2023 09:14:10.470576048 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 354 End data with <CR><LF>.<CR><LF> |
Jan 18, 2023 09:14:10.518968105 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 354 End data with <CR><LF>.<CR><LF> |
Jan 18, 2023 09:14:11.326529980 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 | . |
Jan 18, 2023 09:14:11.329830885 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 250 2.0.0 Ok: queued as F0388140331 |
Jan 18, 2023 09:14:11.489886999 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 250 2.0.0 Ok: queued as 080C91418C8 |
Jan 18, 2023 09:14:43.660346985 CET | 49176 | 587 | 192.168.2.22 | 5.249.163.12 | QUIT |
Jan 18, 2023 09:14:43.660383940 CET | 49177 | 587 | 192.168.2.22 | 5.249.163.12 | QUIT |
Jan 18, 2023 09:14:43.767231941 CET | 587 | 49177 | 5.249.163.12 | 192.168.2.22 | 221 2.0.0 Bye |
Jan 18, 2023 09:14:43.767863989 CET | 587 | 49176 | 5.249.163.12 | 192.168.2.22 | 221 2.0.0 Bye |
Jan 18, 2023 09:14:44.093992949 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 220 box.localdomain ESMTP Postfix (Debian/GNU) |
Jan 18, 2023 09:14:44.094849110 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 | EHLO 813435 |
Jan 18, 2023 09:14:44.172585964 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 220 box.localdomain ESMTP Postfix (Debian/GNU) |
Jan 18, 2023 09:14:44.173003912 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 | EHLO 813435 |
Jan 18, 2023 09:14:44.201376915 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 250-box.localdomain 250-PIPELINING 250-SIZE 10240000 250-VRFY 250-ETRN 250-STARTTLS 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250-SMTPUTF8 250 CHUNKING |
Jan 18, 2023 09:14:44.201699018 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 | AUTH login Z21AYW9zeGVyLmNvbQ== |
Jan 18, 2023 09:14:44.282885075 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 250-box.localdomain 250-PIPELINING 250-SIZE 10240000 250-VRFY 250-ETRN 250-STARTTLS 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250-SMTPUTF8 250 CHUNKING |
Jan 18, 2023 09:14:44.283142090 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 | AUTH login Z21AYW9zeGVyLmNvbQ== |
Jan 18, 2023 09:14:44.308166981 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 334 UGFzc3dvcmQ6 |
Jan 18, 2023 09:14:44.393027067 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 334 UGFzc3dvcmQ6 |
Jan 18, 2023 09:14:44.415210009 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 235 2.7.0 Authentication successful |
Jan 18, 2023 09:14:44.415443897 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 | MAIL FROM:<gm@aosxer.com> |
Jan 18, 2023 09:14:44.503458977 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 235 2.7.0 Authentication successful |
Jan 18, 2023 09:14:44.504333019 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 | MAIL FROM:<gm@aosxer.com> |
Jan 18, 2023 09:14:44.522053003 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 250 2.1.0 Ok |
Jan 18, 2023 09:14:44.522304058 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 | RCPT TO:<reportcard@aosxer.com> |
Jan 18, 2023 09:14:44.614322901 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 250 2.1.0 Ok |
Jan 18, 2023 09:14:44.614756107 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 | RCPT TO:<reportcard@aosxer.com> |
Jan 18, 2023 09:14:44.629196882 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 250 2.1.5 Ok |
Jan 18, 2023 09:14:44.629569054 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 | DATA |
Jan 18, 2023 09:14:44.725070953 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 250 2.1.5 Ok |
Jan 18, 2023 09:14:44.725398064 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 | DATA |
Jan 18, 2023 09:14:44.735939026 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 354 End data with <CR><LF>.<CR><LF> |
Jan 18, 2023 09:14:44.835278034 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 354 End data with <CR><LF>.<CR><LF> |
Jan 18, 2023 09:14:45.546597958 CET | 49178 | 587 | 192.168.2.22 | 5.249.163.12 | . |
Jan 18, 2023 09:14:45.661443949 CET | 49179 | 587 | 192.168.2.22 | 5.249.163.12 | . |
Jan 18, 2023 09:14:45.704210997 CET | 587 | 49178 | 5.249.163.12 | 192.168.2.22 | 250 2.0.0 Ok: queued as 3D2CE140331 |
Jan 18, 2023 09:14:45.820247889 CET | 587 | 49179 | 5.249.163.12 | 192.168.2.22 | 250 2.0.0 Ok: queued as 53CB01418C8 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:13:19 |
Start date: | 18/01/2023 |
Path: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13fd20000 |
File size: | 28253536 bytes |
MD5 hash: | D53B85E21886D2AF9815C377537BCAC3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 2 |
Start time: | 09:13:40 |
Start date: | 18/01/2023 |
Path: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 543304 bytes |
MD5 hash: | A87236E214F6D42A65F5DEDAC816AEC8 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 5 |
Start time: | 09:13:52 |
Start date: | 18/01/2023 |
Path: | C:\Users\user\AppData\Roaming\word.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 437857 bytes |
MD5 hash: | 1CEC9C1FA633D554029A6402174612D1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Target ID: | 6 |
Start time: | 09:13:52 |
Start date: | 18/01/2023 |
Path: | C:\Users\user\AppData\Local\Temp\lyebkz.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 102400 bytes |
MD5 hash: | 41467466B6E727C3C65D9501F6A23A04 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 7 |
Start time: | 09:13:53 |
Start date: | 18/01/2023 |
Path: | C:\Users\user\AppData\Local\Temp\lyebkz.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 102400 bytes |
MD5 hash: | 41467466B6E727C3C65D9501F6A23A04 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Reputation: | low |
Execution Graph
Execution Coverage: | 34.1% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 86.2% |
Total number of Nodes: | 29 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 03674C4F Relevance: 3.1, APIs: 2, Instructions: 90libraryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03674D2B Relevance: 3.0, APIs: 2, Instructions: 46processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03674C77 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 03674D4B Relevance: 1.5, APIs: 1, Instructions: 18COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 15.6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 16.4% |
Total number of Nodes: | 1385 |
Total number of Limit Nodes: | 25 |
Graph
Function 00403640 Relevance: 84.4, APIs: 34, Strings: 14, Instructions: 450stringfilecomCOMMON
Control-flow Graph
C-Code - Quality: 78% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405D74 Relevance: 19.4, APIs: 7, Strings: 4, Instructions: 148filestringCOMMON
Control-flow Graph
C-Code - Quality: 98% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406D5F Relevance: 5.4, APIs: 4, Instructions: 382COMMONCrypto
Control-flow Graph
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040699E Relevance: 3.0, APIs: 2, Instructions: 14fileCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004040C5 Relevance: 61.6, APIs: 34, Strings: 1, Instructions: 357windowstringCOMMON
Control-flow Graph
C-Code - Quality: 84% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403D17 Relevance: 44.0, APIs: 13, Strings: 12, Instructions: 215stringregistryCOMMON
Control-flow Graph
C-Code - Quality: 96% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004030D0 Relevance: 23.0, APIs: 5, Strings: 8, Instructions: 204memoryCOMMON
Control-flow Graph
C-Code - Quality: 98% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040176F Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 145stringtimeCOMMON
Control-flow Graph
C-Code - Quality: 77% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004069C5 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 36libraryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 93% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 98% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 92% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040603F Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 47stringCOMMON
Control-flow Graph
C-Code - Quality: 53% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00407194 Relevance: 5.2, APIs: 4, Instructions: 236COMMON
C-Code - Quality: 99% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00407395 Relevance: 5.2, APIs: 4, Instructions: 208COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004070AB Relevance: 5.2, APIs: 4, Instructions: 205COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406FFE Relevance: 5.2, APIs: 4, Instructions: 180COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040711C Relevance: 5.2, APIs: 4, Instructions: 170COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00407068 Relevance: 5.2, APIs: 4, Instructions: 168COMMON
C-Code - Quality: 98% |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405D2C Relevance: 4.5, APIs: 3, Instructions: 28fileCOMMON
C-Code - Quality: 41% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004015C1 Relevance: 3.1, APIs: 2, Instructions: 65COMMON
C-Code - Quality: 86% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401389 Relevance: 3.0, APIs: 2, Instructions: 43windowCOMMON
C-Code - Quality: 69% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405C4B Relevance: 3.0, APIs: 2, Instructions: 24processCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406158 Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
C-Code - Quality: 68% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406133 Relevance: 3.0, APIs: 2, Instructions: 13COMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405C16 Relevance: 3.0, APIs: 2, Instructions: 9COMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040620A Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004035F8 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401FA4 Relevance: 1.3, APIs: 1, Instructions: 37COMMON
C-Code - Quality: 78% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405809 Relevance: 66.8, APIs: 36, Strings: 2, Instructions: 284windowclipboardmemoryCOMMON
C-Code - Quality: 95% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404AB5 Relevance: 23.0, APIs: 10, Strings: 3, Instructions: 275stringCOMMON
C-Code - Quality: 78% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004021AA Relevance: 1.6, APIs: 1, Instructions: 129comCOMMON
C-Code - Quality: 67% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040290B Relevance: 1.5, APIs: 1, Instructions: 30fileCOMMON
C-Code - Quality: 39% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405031 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 489windowmemoryCOMMON
C-Code - Quality: 96% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404783 Relevance: 37.0, APIs: 19, Strings: 2, Instructions: 204windowstringCOMMON
C-Code - Quality: 91% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004062AE Relevance: 26.4, APIs: 10, Strings: 5, Instructions: 130memorystringCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 90% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004066A5 Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 196stringCOMMON
C-Code - Quality: 72% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004056CA Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 72stringwindowCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040462B Relevance: 12.1, APIs: 8, Instructions: 68COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004026EC Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 153fileCOMMON
C-Code - Quality: 87% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 91% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404F7F Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402F93 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 36timeCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 93% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404E71 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 84stringCOMMON
C-Code - Quality: 77% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 48% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401D81 Relevance: 7.6, APIs: 5, Instructions: 75windowCOMMON
C-Code - Quality: 77% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401E4E Relevance: 7.5, APIs: 5, Instructions: 43COMMON
C-Code - Quality: 73% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401C43 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowtimeCOMMON
C-Code - Quality: 59% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406536 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 44registryCOMMON
C-Code - Quality: 91% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405F37 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 16stringCOMMON
C-Code - Quality: 58% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040563E Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 46windowCOMMON
C-Code - Quality: 89% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004060BD Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 9.5% |
Dynamic/Decrypted Code Coverage: | 5.7% |
Signature Coverage: | 5.3% |
Total number of Nodes: | 1879 |
Total number of Limit Nodes: | 27 |
Graph
Control-flow Graph
C-Code - Quality: 59% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 002408B7 Relevance: 6.5, APIs: 4, Instructions: 483COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 002407DA Relevance: 1.5, APIs: 1, Instructions: 34COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 85% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 70% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00240838 Relevance: 1.5, APIs: 1, Instructions: 39memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404878 Relevance: 1.5, APIs: 1, Instructions: 20memoryCOMMON
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401906 Relevance: 1.5, APIs: 1, Instructions: 10COMMON
Control-flow Graph
C-Code - Quality: 25% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0024073A Relevance: 1.3, APIs: 1, Instructions: 60memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 85% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040F127 Relevance: 3.0, APIs: 2, Instructions: 14COMMON
C-Code - Quality: 42% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040C824 Relevance: 1.5, APIs: 1, Instructions: 10COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403689 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004043C4 Relevance: 19.3, APIs: 8, Strings: 3, Instructions: 57libraryloaderCOMMONLIBRARYCODE
C-Code - Quality: 92% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 88% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00409025 Relevance: 15.1, APIs: 10, Instructions: 95COMMON
C-Code - Quality: 83% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004084CD Relevance: 9.0, APIs: 6, Instructions: 44COMMON
C-Code - Quality: 91% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405178 Relevance: 7.6, APIs: 5, Instructions: 71COMMON
C-Code - Quality: 95% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004084C2 Relevance: 7.6, APIs: 5, Instructions: 59COMMON
C-Code - Quality: 85% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 89% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404A01 Relevance: 7.5, APIs: 5, Instructions: 44memoryCOMMONLIBRARYCODE
C-Code - Quality: 41% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040AA24 Relevance: 6.0, APIs: 4, Instructions: 46memoryCOMMON
C-Code - Quality: 95% |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004048A9 Relevance: 6.0, APIs: 4, Instructions: 34memoryCOMMON
C-Code - Quality: 92% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 90% |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 77% |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |