Edit tour
Windows
Analysis Report
winaudio.exe
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Registers a new ROOT certificate
Installs new ROOT certificates
Uses known network protocols on non-standard ports
Machine Learning detection for sample
Contains functionality to inject threads in other processes
Uses 32bit PE files
Contains functionality to check if a debugger is running (IsDebuggerPresent)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Stores large binary data to the registry
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to dynamically determine API calls
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Contains functionality for execution timing, often used to detect debuggers
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Sample file is different than original file name gathered from version info
Extensive use of GetProcAddress (often used to hide API calls)
Contains functionality to read the PEB
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Detected TCP or UDP traffic on non-standard ports
Contains capabilities to detect virtual machines
Contains functionality to query network adapater information
Classification
- System is w10x64
- winaudio.exe (PID: 4820 cmdline:
C:\Users\u ser\Deskto p\winaudio .exe MD5: D2367AD6988BB88F1B03CC7352F9696A) - conhost.exe (PID: 688 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Joe Sandbox ML: |
Source: | Code function: | 0_2_0037BD80 |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Code function: | 0_2_0038F8BD |
Source: | Code function: | 0_2_002D6370 |
Source: | Code function: | 0_2_002BC770 |
Networking |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Code function: | 0_2_0037B080 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
E-Banking Fraud |
---|
Source: | Code function: | 0_2_002CF8B0 |
Source: | Static PE information: |
Source: | Code function: | 0_2_002D7200 | |
Source: | Code function: | 0_2_00346420 | |
Source: | Code function: | 0_2_002DB4A0 | |
Source: | Code function: | 0_2_002D3610 | |
Source: | Code function: | 0_2_002D7760 | |
Source: | Code function: | 0_2_002DAC90 | |
Source: | Code function: | 0_2_002DDC90 | |
Source: | Code function: | 0_2_002FC020 | |
Source: | Code function: | 0_2_00389180 | |
Source: | Code function: | 0_2_002B321D | |
Source: | Code function: | 0_2_002D5210 | |
Source: | Code function: | 0_2_00382343 | |
Source: | Code function: | 0_2_002F64B0 | |
Source: | Code function: | 0_2_00382572 | |
Source: | Code function: | 0_2_00372580 | |
Source: | Code function: | 0_2_002F05E0 | |
Source: | Code function: | 0_2_002CA5C0 | |
Source: | Code function: | 0_2_0039762F | |
Source: | Code function: | 0_2_002D2860 | |
Source: | Code function: | 0_2_00325860 | |
Source: | Code function: | 0_2_002BD8C0 | |
Source: | Code function: | 0_2_00324AD0 | |
Source: | Code function: | 0_2_002CAB50 | |
Source: | Code function: | 0_2_002D3C00 | |
Source: | Code function: | 0_2_0037CCB0 | |
Source: | Code function: | 0_2_00358F40 | |
Source: | Code function: | 0_2_00393FF6 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | ||
Source: | Process created: |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 0_2_002D7140 |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Code function: | 0_2_002D7200 |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Code function: | 0_2_002E1079 | |
Source: | Code function: | 0_2_002B2395 |
Source: | Code function: | 0_2_00346420 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Persistence and Installation Behavior |
---|
Source: | Registry value created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Key value created or modified: | Jump to behavior |
Source: | Code function: | 0_2_00346420 |
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 0_2_00346420 |
Source: | Code function: | 0_2_002B11E0 |
Source: | Window / User API: | Jump to behavior |
Source: | File opened / queried: | Jump to behavior |
Source: | Code function: | 0_2_002DE070 |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_0038F8BD |
Source: | Code function: | 0_2_002D6370 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_0037F7A7 |
Source: | Code function: | 0_2_00346420 |
Source: | Code function: | 0_2_00346420 |
Source: | Code function: | 0_2_002B11E0 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 0_2_00383DA2 |
Source: | Code function: | 0_2_002DD870 | |
Source: | Code function: | 0_2_0037F7A7 | |
Source: | Code function: | 0_2_002E0871 | |
Source: | Code function: | 0_2_002E0EAA |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Code function: | 0_2_002D5C20 |
Source: | Code function: | 0_2_002B1000 |
Source: | Code function: | 0_2_002E107B |
Source: | Code function: | 0_2_002DE5D0 |
Source: | Code function: | 0_2_002D3610 | |
Source: | Code function: | 0_2_002D1C10 |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 2 Command and Scripting Interpreter | Path Interception | 1 Access Token Manipulation | 1 Modify Registry | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | Exfiltration Over Other Network Medium | 12 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | 1 Native API | Boot or Logon Initialization Scripts | 11 Process Injection | 2 Virtualization/Sandbox Evasion | LSASS Memory | 41 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 11 Non-Standard Port | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | 1 Access Token Manipulation | Security Account Manager | 2 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 2 Ingress Tool Transfer | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | 11 Process Injection | NTDS | 2 Process Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 3 Non-Application Layer Protocol | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Data Transfer Size Limits | 4 Application Layer Protocol | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 31 Obfuscated Files or Information | Cached Domain Credentials | 1 Remote System Discovery | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | 2 Install Root Certificate | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | 1 Software Packing | Proc Filesystem | 2 File and Directory Discovery | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue | |
Exploit Public-Facing Application | PowerShell | At (Linux) | At (Linux) | Masquerading | /etc/passwd and /etc/shadow | 13 System Information Discovery | Software Deployment Tools | Data Staged | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Web Protocols | Rogue Cellular Base Station | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
67% | ReversingLabs | Win32.Trojan.Razy | ||
77% | Virustotal | Browse | ||
100% | Avira | HEUR/AGEN.1243897 | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | HEUR/AGEN.1215508 | Download File |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
8awang.com | 103.224.212.220 | true | false | unknown | |
opencdnpicrmb.gshifen.com | 104.193.88.112 | true | false | unknown | |
41ku.cn | 103.86.67.66 | true | false | unknown | |
hiphotos.gshifen.com | 104.193.88.109 | true | false | unknown | |
www.2345.com.w.alikunlun.com | 79.133.177.216 | true | false | unknown | |
gmt.yunliao8.com | unknown | unknown | true | unknown | |
imgsrc.baidu.com | unknown | unknown | false | high | |
www.2345.com | unknown | unknown | false | high | |
pic.rmb.bdstatic.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| low | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
103.86.67.66 | 41ku.cn | Hong Kong | 132721 | PING-GLOBAL-ASPingGlobalAmsterdamPOPASNNL | false | |
185.10.104.120 | unknown | European Union | 55967 | BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtd | false | |
103.224.212.220 | 8awang.com | Australia | 133618 | TRELLIAN-AS-APTrellianPtyLimitedAU | false | |
79.133.177.214 | unknown | Russian Federation | 43882 | SOTLINE-ASRU | false | |
79.133.177.211 | unknown | Russian Federation | 43882 | SOTLINE-ASRU | false | |
104.193.90.80 | unknown | United States | 55967 | BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtd | false | |
185.10.104.115 | unknown | European Union | 55967 | BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtd | false | |
104.193.88.112 | opencdnpicrmb.gshifen.com | United States | 55967 | BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtd | false | |
79.133.177.218 | unknown | Russian Federation | 43882 | SOTLINE-ASRU | false | |
79.133.177.216 | www.2345.com.w.alikunlun.com | Russian Federation | 43882 | SOTLINE-ASRU | false | |
79.133.177.215 | unknown | Russian Federation | 43882 | SOTLINE-ASRU | false | |
104.193.88.109 | hiphotos.gshifen.com | United States | 55967 | BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtd | false |
IP |
---|
192.168.2.1 |
127.0.0.1 |
Joe Sandbox Version: | 36.0.0 Rainbow Opal |
Analysis ID: | 794053 |
Start date and time: | 2023-01-30 07:39:08 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 6m 41s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | winaudio.exe |
Detection: | MAL |
Classification: | mal84.bank.troj.evad.winEXE@2/2@20/14 |
EGA Information: |
|
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): fs.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
⊘No simulations
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
185.10.104.120 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
103.224.212.220 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
8awang.com | Get hash | malicious | Browse |
| |
opencdnpicrmb.gshifen.com | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
BAIDUBeijingBaiduNetcomScienceandTechnologyCoLtd | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
PING-GLOBAL-ASPingGlobalAmsterdamPOPASNNL | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
fd80fa9c6120cdeea8520510f3c644ac | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
⊘No context
Process: | C:\Users\user\Desktop\winaudio.exe |
File Type: | |
Category: | modified |
Size (bytes): | 111069 |
Entropy (8bit): | 7.7610376443952775 |
Encrypted: | false |
SSDEEP: | 1536:xqoUBsTWNw2r31a/vODkM8/6uUZ3/UE59INsjfOi:xqjsyD31auDkMhh/bfINsjR |
MD5: | 1C262030963192BB9B4107B90AC53E67 |
SHA1: | 12C90CE15E21420E00B7D3B360269F9C52D1FDE9 |
SHA-256: | 4192C7662F3774EB9F500DFD80632BDD4075E8B595A213D254DA0522F86AA3B4 |
SHA-512: | D33C9D630297EE6E2E7968FF111F21828A7B1972C6A65C594A6782C7938E39DE354C18B3914CA6C9C5AB127E8F44F917906311A50288431DC2B352FEFFFC6F30 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\winaudio.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20 |
Entropy (8bit): | 1.5 |
Encrypted: | false |
SSDEEP: | 3:q3:q3 |
MD5: | EBB74F5809511F1A535283D293A34D94 |
SHA1: | 311E533BA417AD75D701C8A05D7BCDB6B278B3B2 |
SHA-256: | 81C25D30F3308AB3C92B769842845417633C3C6DCCE47E99ECCCD5B1552AC810 |
SHA-512: | C62A9D2525C82162B29699393378746E56E5679D91460FB9D8A718856EB3FEC1B66AC73AF6A7C84DEB07F5D99E41BAD069015065F50C053CD64763EEB4BA2295 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.878754349315624 |
TrID: |
|
File name: | winaudio.exe |
File size: | 702512 |
MD5: | d2367ad6988bb88f1b03cc7352f9696a |
SHA1: | a5e4f6ed449af51d5d44fb6300bf87549ecdaced |
SHA256: | 0c0a0efd7f2e4a27ddf26e5549d164aa8dc7fd570a4bd41daf07891b2a0b59af |
SHA512: | 8b93bbed355d727dc47a3cabdcda8285f20e367c0892245b018527eea2e98a5980af33ac4945ef9d162f3c5e31fbe114a89330cba48111fe325ed11f1ebe5393 |
SSDEEP: | 12288:LuwwW2lKQC3DHd4PqE1JCcChPDAY54rsP7cpsAnHb2OA/6uyMlEamc42Olmj92ov:Luw0KQKjdK71JRyUY54aAHb2F2O9BsmT |
TLSH: | C2E423B3462E6D37FF86C7BA5835B98B114A3A1014E34CE456B33C9A8F7A61A3D04573 |
File Content Preview: | MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.......I..9...j...j...j...j...j...j...j...j...j...k...j...j...j...k...j.%.j...j6..k...j6..k...j6..k*..j...j...j...j...j...k...j...j... |
Icon Hash: | 00828e8e8686b000 |
Entrypoint: | 0x556940 |
Entrypoint Section: | UPX1 |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x60F7FA6F [Wed Jul 21 10:43:59 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | c99fa9efa02184d67eba9e2c9bf7ef23 |
Instruction |
---|
pushad |
mov esi, 004B1000h |
lea edi, dword ptr [esi-000B0000h] |
push edi |
jmp 00007FC3A520592Dh |
nop |
mov al, byte ptr [esi] |
inc esi |
mov byte ptr [edi], al |
inc edi |
add ebx, ebx |
jne 00007FC3A5205929h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007FC3A520590Fh |
mov eax, 00000001h |
add ebx, ebx |
jne 00007FC3A5205929h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc eax, eax |
add ebx, ebx |
jnc 00007FC3A520592Dh |
jne 00007FC3A520594Ah |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007FC3A5205941h |
dec eax |
add ebx, ebx |
jne 00007FC3A5205929h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc eax, eax |
jmp 00007FC3A52058F6h |
add ebx, ebx |
jne 00007FC3A5205929h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc ecx, ecx |
jmp 00007FC3A5205974h |
xor ecx, ecx |
sub eax, 03h |
jc 00007FC3A5205933h |
shl eax, 08h |
mov al, byte ptr [esi] |
inc esi |
xor eax, FFFFFFFFh |
je 00007FC3A5205997h |
sar eax, 1 |
mov ebp, eax |
jmp 00007FC3A520592Dh |
add ebx, ebx |
jne 00007FC3A5205929h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007FC3A52058EEh |
inc ecx |
add ebx, ebx |
jne 00007FC3A5205929h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007FC3A52058E0h |
add ebx, ebx |
jne 00007FC3A5205929h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc ecx, ecx |
add ebx, ebx |
jnc 00007FC3A5205911h |
jne 00007FC3A520592Bh |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jnc 00007FC3A5205906h |
add ecx, 02h |
cmp ebp, FFFFFB00h |
adc ecx, 02h |
lea edx, dword ptr [edi+ebp] |
cmp ebp, FFFFFFFCh |
jbe 00007FC3A5205930h |
mov al, byte ptr [edx] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x15736c | 0x204 | .rsrc |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x157000 | 0x36c | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x157570 | 0x10 | .rsrc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x156b24 | 0x5c | UPX1 |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
UPX0 | 0x1000 | 0xb0000 | 0x0 | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
UPX1 | 0xb1000 | 0xa6000 | 0xa5c00 | False | 0.9808517156862745 | data | 7.8746525051929925 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x157000 | 0x1000 | 0x600 | False | 0.4225260416666667 | data | 3.5528119263738653 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_VERSION | 0x15705c | 0x310 | data | Chinese | China |
DLL | Import |
---|---|
ADVAPI32.dll | RegCloseKey |
IPHLPAPI.DLL | GetAdaptersInfo |
KERNEL32.DLL | LoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect |
PSAPI.DLL | GetModuleFileNameExA |
USER32.dll | wsprintfA |
VERSION.dll | VerQueryValueA |
WININET.dll | InternetCrackUrlA |
WS2_32.dll | WSASetLastError |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Chinese | China |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 30, 2023 07:40:08.235490084 CET | 49703 | 10100 | 192.168.2.3 | 103.224.212.220 |
Jan 30, 2023 07:40:08.404762983 CET | 10100 | 49703 | 103.224.212.220 | 192.168.2.3 |
Jan 30, 2023 07:40:08.915880919 CET | 49703 | 10100 | 192.168.2.3 | 103.224.212.220 |
Jan 30, 2023 07:40:09.085498095 CET | 10100 | 49703 | 103.224.212.220 | 192.168.2.3 |
Jan 30, 2023 07:40:09.587779045 CET | 49703 | 10100 | 192.168.2.3 | 103.224.212.220 |
Jan 30, 2023 07:40:09.757230997 CET | 10100 | 49703 | 103.224.212.220 | 192.168.2.3 |
Jan 30, 2023 07:40:10.819458961 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:11.030670881 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:11.030863047 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:11.032207966 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:11.243486881 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:11.243551970 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:11.243596077 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:11.243634939 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:11.243707895 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:12.083256960 CET | 49706 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:12.256526947 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.256773949 CET | 49706 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:12.256911993 CET | 49706 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:12.357774019 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.357901096 CET | 49706 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:12.429919958 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431133032 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431159973 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431173086 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431191921 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431204081 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431221962 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431236982 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:12.431287050 CET | 49706 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:12.431346893 CET | 49706 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:12.431950092 CET | 49706 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:12.604921103 CET | 80 | 49706 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:13.276061058 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.447237968 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.447531939 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.447882891 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.552433014 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.552805901 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.618916035 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619106054 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619160891 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619210958 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619257927 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619288921 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.619306087 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619345903 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619352102 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.619383097 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.619402885 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.619431973 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.620448112 CET | 49707 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:13.641254902 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:13.794161081 CET | 80 | 49707 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:13.852669001 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:13.852730989 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:13.852931023 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:13.854280949 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:14.657166004 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:14.826412916 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.826530933 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:14.826695919 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:14.933873892 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.933985949 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:14.995671988 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996628046 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996685028 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996732950 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996772051 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:14.996778011 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996824980 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996825933 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:14.996862888 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996896982 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:14.996907949 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:14.996944904 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:15.014744043 CET | 49708 | 80 | 192.168.2.3 | 104.193.90.80 |
Jan 30, 2023 07:40:15.183971882 CET | 80 | 49708 | 104.193.90.80 | 192.168.2.3 |
Jan 30, 2023 07:40:15.895122051 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.064740896 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.064862013 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.064955950 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.168234110 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.168411970 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.234436035 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234508991 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234559059 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234606981 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234652996 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234709978 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.234709978 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.234754086 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234798908 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234833956 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.234858990 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.234903097 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.248508930 CET | 49709 | 80 | 192.168.2.3 | 104.193.88.109 |
Jan 30, 2023 07:40:16.331585884 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:16.417831898 CET | 80 | 49709 | 104.193.88.109 | 192.168.2.3 |
Jan 30, 2023 07:40:16.543731928 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:16.543795109 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:16.543855906 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:16.543899059 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:17.932452917 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.952512026 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.952749968 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.952861071 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.974618912 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.974710941 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.974766016 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.974817038 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.974925041 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.975811958 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.975881100 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.975922108 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.975928068 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.976001024 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.976362944 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:17.976448059 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.976551056 CET | 49710 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:17.996968031 CET | 80 | 49710 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:18.599903107 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.620012999 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.620187998 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.620254040 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.640103102 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.640527964 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.640578032 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.640623093 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.640710115 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.641262054 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.641310930 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.641345978 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.641408920 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.641410112 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.641803026 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.641937971 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.641971111 CET | 49711 | 80 | 192.168.2.3 | 185.10.104.120 |
Jan 30, 2023 07:40:18.661873102 CET | 80 | 49711 | 185.10.104.120 | 192.168.2.3 |
Jan 30, 2023 07:40:18.680522919 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:18.700345993 CET | 49712 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:18.891633987 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:18.891663074 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:18.891912937 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:18.912528992 CET | 10100 | 49712 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:18.912693977 CET | 49712 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:18.912763119 CET | 49712 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:19.124861956 CET | 10100 | 49712 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:19.399028063 CET | 10100 | 49712 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:19.399081945 CET | 10100 | 49712 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:19.399254084 CET | 49712 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:19.399255037 CET | 49712 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:40:19.610352039 CET | 10100 | 49712 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:40:19.768596888 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:19.938124895 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:19.938241959 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:19.938349962 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:20.040960073 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.041062117 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:20.107609987 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108556986 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108606100 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108654022 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108701944 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108735085 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:20.108747005 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108789921 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108794928 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:20.108825922 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.108859062 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:20.108887911 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:20.113101959 CET | 49713 | 80 | 192.168.2.3 | 104.193.88.112 |
Jan 30, 2023 07:40:20.153841019 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.173578024 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.173705101 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.173821926 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.194041014 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.194947958 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.194997072 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.195044994 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.195080042 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.195677042 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.195725918 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.195772886 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.195785046 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.195844889 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.196531057 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.196578026 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.196624994 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.197108030 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.197372913 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.197419882 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.197451115 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.197468042 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.197532892 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.198234081 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.198282957 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.198353052 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.198386908 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.199171066 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.199248075 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.199248075 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.199358940 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.199417114 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.200057030 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.200134993 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.200200081 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.200206995 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.200939894 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.201014042 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.201014996 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.201091051 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.201152086 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.201765060 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.214958906 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.215022087 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.215071917 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.215079069 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.215142965 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.215589046 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.215636969 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.215682983 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.215698004 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.216484070 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.216531992 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.216572046 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.216577053 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.216638088 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.217367887 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.217417002 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.217463017 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.217477083 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.218194008 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.218240976 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.218267918 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.218290091 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.218369961 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.219106913 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.219155073 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.219201088 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.219218969 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.219923019 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.219969988 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.219996929 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.220014095 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.220069885 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.220789909 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.220841885 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.220885992 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.220920086 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.221638918 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.221687078 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.221708059 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.221733093 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.221786022 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.222538948 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.222800016 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.222845078 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.222862005 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.222891092 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.222945929 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.223701954 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.223747969 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.223797083 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.223810911 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.224509001 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.224555016 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.224587917 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.224622011 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.224701881 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.225409031 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.225491047 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.225537062 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.225553989 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.226249933 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.226296902 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.226340055 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.226341963 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.226399899 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.227123022 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.227169991 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.227216959 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.227233887 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.228005886 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.228053093 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.228107929 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.234967947 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.235033035 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.235083103 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.235090017 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.235145092 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.235739946 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.235789061 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.235855103 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.236244917 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.236293077 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.236325026 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.236623049 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.237035990 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.237081051 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.237111092 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.237126112 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.237185001 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.237760067 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.237807035 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.237854004 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.237867117 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.238542080 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.238589048 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.238614082 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.238636971 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.238694906 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.239336014 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.239532948 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.239629984 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.240714073 CET | 49714 | 80 | 192.168.2.3 | 185.10.104.115 |
Jan 30, 2023 07:40:20.260505915 CET | 80 | 49714 | 185.10.104.115 | 192.168.2.3 |
Jan 30, 2023 07:40:20.282358885 CET | 80 | 49713 | 104.193.88.112 | 192.168.2.3 |
Jan 30, 2023 07:40:20.346085072 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:20.346144915 CET | 443 | 49715 | 79.133.177.216 | 192.168.2.3 |
Jan 30, 2023 07:40:20.346247911 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.034326077 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.034392118 CET | 443 | 49715 | 79.133.177.216 | 192.168.2.3 |
Jan 30, 2023 07:40:21.141364098 CET | 443 | 49715 | 79.133.177.216 | 192.168.2.3 |
Jan 30, 2023 07:40:21.141537905 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.144252062 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.144289017 CET | 443 | 49715 | 79.133.177.216 | 192.168.2.3 |
Jan 30, 2023 07:40:21.145040035 CET | 443 | 49715 | 79.133.177.216 | 192.168.2.3 |
Jan 30, 2023 07:40:21.198040962 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.462522984 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.462522984 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.462579966 CET | 443 | 49715 | 79.133.177.216 | 192.168.2.3 |
Jan 30, 2023 07:40:21.463022947 CET | 443 | 49715 | 79.133.177.216 | 192.168.2.3 |
Jan 30, 2023 07:40:21.463092089 CET | 49715 | 443 | 192.168.2.3 | 79.133.177.216 |
Jan 30, 2023 07:40:21.735421896 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:21.735497952 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:21.735599041 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:21.736115932 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:21.736145020 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:21.834330082 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:21.834614992 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:21.846751928 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:21.846808910 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:21.847170115 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:21.901161909 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:22.849235058 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:22.849303007 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:22.849361897 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:22.849759102 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:22.849845886 CET | 443 | 49716 | 79.133.177.211 | 192.168.2.3 |
Jan 30, 2023 07:40:22.849863052 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:22.849905014 CET | 49716 | 443 | 192.168.2.3 | 79.133.177.211 |
Jan 30, 2023 07:40:23.013712883 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.013778925 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.013947010 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.015587091 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.015624046 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.112143040 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.112507105 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.119204998 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.119244099 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.119908094 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.167241096 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.869138956 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.869177103 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.869239092 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.869909048 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.869988918 CET | 443 | 49717 | 79.133.177.214 | 192.168.2.3 |
Jan 30, 2023 07:40:23.869990110 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:23.870151997 CET | 49717 | 443 | 192.168.2.3 | 79.133.177.214 |
Jan 30, 2023 07:40:24.220793962 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.220835924 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.220922947 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.221582890 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.221604109 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.318149090 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.318279028 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.322382927 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.322400093 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.323239088 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.370246887 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.625262022 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.625329018 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.625358105 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.625977039 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.626055956 CET | 443 | 49718 | 79.133.177.218 | 192.168.2.3 |
Jan 30, 2023 07:40:24.626091003 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:24.626147032 CET | 49718 | 443 | 192.168.2.3 | 79.133.177.218 |
Jan 30, 2023 07:40:25.252090931 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.252161026 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.252276897 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.252568007 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.252594948 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.349590063 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.350137949 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.352601051 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.352638960 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.353133917 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.401493073 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.885057926 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.885128975 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.885157108 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.885871887 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.885956049 CET | 443 | 49719 | 79.133.177.215 | 192.168.2.3 |
Jan 30, 2023 07:40:25.885977030 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:40:25.886012077 CET | 49719 | 443 | 192.168.2.3 | 79.133.177.215 |
Jan 30, 2023 07:41:51.878572941 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Jan 30, 2023 07:41:52.089657068 CET | 10100 | 49705 | 103.86.67.66 | 192.168.2.3 |
Jan 30, 2023 07:41:52.089867115 CET | 49705 | 10100 | 192.168.2.3 | 103.86.67.66 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 30, 2023 07:40:01.956288099 CET | 58921 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:02.947030067 CET | 58921 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:03.962863922 CET | 58921 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:06.009882927 CET | 58921 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:06.973474979 CET | 53 | 58921 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:07.966860056 CET | 53 | 58921 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:08.049611092 CET | 49977 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:08.223875046 CET | 53 | 49977 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:08.980637074 CET | 53 | 58921 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:10.799201012 CET | 57840 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:10.817279100 CET | 53 | 57840 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:11.030025959 CET | 53 | 58921 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:11.253972054 CET | 57990 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:12.080869913 CET | 53 | 57990 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:12.463543892 CET | 52387 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:13.274435043 CET | 53 | 52387 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:13.858237982 CET | 56924 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:14.649996042 CET | 53 | 56924 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:15.035599947 CET | 60625 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:15.858453035 CET | 53 | 60625 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:17.378496885 CET | 49302 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:17.924500942 CET | 53 | 49302 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:18.008702040 CET | 53975 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:18.597928047 CET | 53 | 53975 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:18.678886890 CET | 51139 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:18.699131012 CET | 53 | 51139 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:18.908432007 CET | 52955 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:19.756649971 CET | 53 | 52955 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:20.135263920 CET | 60582 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:20.152762890 CET | 53 | 60582 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:20.322169065 CET | 57134 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:20.344877958 CET | 53 | 57134 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:21.708236933 CET | 62050 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:21.728574991 CET | 53 | 62050 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:22.978579044 CET | 56042 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:23.011231899 CET | 53 | 56042 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:24.105391979 CET | 59636 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:24.215467930 CET | 53 | 59636 | 8.8.8.8 | 192.168.2.3 |
Jan 30, 2023 07:40:24.994689941 CET | 55638 | 53 | 192.168.2.3 | 8.8.8.8 |
Jan 30, 2023 07:40:25.250333071 CET | 53 | 55638 | 8.8.8.8 | 192.168.2.3 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 30, 2023 07:40:07.967144966 CET | 192.168.2.3 | 8.8.8.8 | cff3 | (Port unreachable) | Destination Unreachable |
Jan 30, 2023 07:40:08.980931044 CET | 192.168.2.3 | 8.8.8.8 | cff3 | (Port unreachable) | Destination Unreachable |
Jan 30, 2023 07:40:11.030236959 CET | 192.168.2.3 | 8.8.8.8 | cff3 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 30, 2023 07:40:01.956288099 CET | 192.168.2.3 | 8.8.8.8 | 0x2bc9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:02.947030067 CET | 192.168.2.3 | 8.8.8.8 | 0x2bc9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:03.962863922 CET | 192.168.2.3 | 8.8.8.8 | 0x2bc9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:06.009882927 CET | 192.168.2.3 | 8.8.8.8 | 0x2bc9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:08.049611092 CET | 192.168.2.3 | 8.8.8.8 | 0x62cc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:10.799201012 CET | 192.168.2.3 | 8.8.8.8 | 0xa776 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:11.253972054 CET | 192.168.2.3 | 8.8.8.8 | 0xf4c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:12.463543892 CET | 192.168.2.3 | 8.8.8.8 | 0x165f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:13.858237982 CET | 192.168.2.3 | 8.8.8.8 | 0xe19c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:15.035599947 CET | 192.168.2.3 | 8.8.8.8 | 0x3dd0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:17.378496885 CET | 192.168.2.3 | 8.8.8.8 | 0x39fe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:18.008702040 CET | 192.168.2.3 | 8.8.8.8 | 0xac8f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:18.678886890 CET | 192.168.2.3 | 8.8.8.8 | 0x61e2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:18.908432007 CET | 192.168.2.3 | 8.8.8.8 | 0xdbfe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:20.135263920 CET | 192.168.2.3 | 8.8.8.8 | 0xff35 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:20.322169065 CET | 192.168.2.3 | 8.8.8.8 | 0x8eb5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:21.708236933 CET | 192.168.2.3 | 8.8.8.8 | 0x6406 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:22.978579044 CET | 192.168.2.3 | 8.8.8.8 | 0x3ae4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:24.105391979 CET | 192.168.2.3 | 8.8.8.8 | 0x4233 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:24.994689941 CET | 192.168.2.3 | 8.8.8.8 | 0xbec1 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 30, 2023 07:40:06.973474979 CET | 8.8.8.8 | 192.168.2.3 | 0x2bc9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:07.966860056 CET | 8.8.8.8 | 192.168.2.3 | 0x2bc9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:08.223875046 CET | 8.8.8.8 | 192.168.2.3 | 0x62cc | No error (0) | 103.224.212.220 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:08.980637074 CET | 8.8.8.8 | 192.168.2.3 | 0x2bc9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:10.817279100 CET | 8.8.8.8 | 192.168.2.3 | 0xa776 | No error (0) | 103.86.67.66 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:10.817279100 CET | 8.8.8.8 | 192.168.2.3 | 0xa776 | No error (0) | 45.125.217.58 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:10.817279100 CET | 8.8.8.8 | 192.168.2.3 | 0xa776 | No error (0) | 103.86.67.98 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:10.817279100 CET | 8.8.8.8 | 192.168.2.3 | 0xa776 | No error (0) | 103.86.65.194 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:11.030025959 CET | 8.8.8.8 | 192.168.2.3 | 0x2bc9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 30, 2023 07:40:12.080869913 CET | 8.8.8.8 | 192.168.2.3 | 0xf4c3 | No error (0) | pic.rmb.bdstatic.com.a.bdydns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:12.080869913 CET | 8.8.8.8 | 192.168.2.3 | 0xf4c3 | No error (0) | opencdnpicrmb.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:12.080869913 CET | 8.8.8.8 | 192.168.2.3 | 0xf4c3 | No error (0) | opencdnpicrmb.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:12.080869913 CET | 8.8.8.8 | 192.168.2.3 | 0xf4c3 | No error (0) | 104.193.88.112 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:12.080869913 CET | 8.8.8.8 | 192.168.2.3 | 0xf4c3 | No error (0) | 104.193.90.80 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:13.274435043 CET | 8.8.8.8 | 192.168.2.3 | 0x165f | No error (0) | hiphotos.baidu.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:13.274435043 CET | 8.8.8.8 | 192.168.2.3 | 0x165f | No error (0) | hiphotos.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:13.274435043 CET | 8.8.8.8 | 192.168.2.3 | 0x165f | No error (0) | hiphotos.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:13.274435043 CET | 8.8.8.8 | 192.168.2.3 | 0x165f | No error (0) | 104.193.88.109 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:14.649996042 CET | 8.8.8.8 | 192.168.2.3 | 0xe19c | No error (0) | pic.rmb.bdstatic.com.a.bdydns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:14.649996042 CET | 8.8.8.8 | 192.168.2.3 | 0xe19c | No error (0) | opencdnpicrmb.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:14.649996042 CET | 8.8.8.8 | 192.168.2.3 | 0xe19c | No error (0) | opencdnpicrmb.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:14.649996042 CET | 8.8.8.8 | 192.168.2.3 | 0xe19c | No error (0) | 104.193.90.80 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:14.649996042 CET | 8.8.8.8 | 192.168.2.3 | 0xe19c | No error (0) | 104.193.88.112 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:15.858453035 CET | 8.8.8.8 | 192.168.2.3 | 0x3dd0 | No error (0) | hiphotos.baidu.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:15.858453035 CET | 8.8.8.8 | 192.168.2.3 | 0x3dd0 | No error (0) | hiphotos.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:15.858453035 CET | 8.8.8.8 | 192.168.2.3 | 0x3dd0 | No error (0) | hiphotos.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:15.858453035 CET | 8.8.8.8 | 192.168.2.3 | 0x3dd0 | No error (0) | 104.193.88.109 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:17.924500942 CET | 8.8.8.8 | 192.168.2.3 | 0x39fe | No error (0) | pic.rmb.bdstatic.com.a.bdydns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:17.924500942 CET | 8.8.8.8 | 192.168.2.3 | 0x39fe | No error (0) | opencdnpicrmb.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:17.924500942 CET | 8.8.8.8 | 192.168.2.3 | 0x39fe | No error (0) | opencdnpicrmb.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:17.924500942 CET | 8.8.8.8 | 192.168.2.3 | 0x39fe | No error (0) | 185.10.104.115 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.597928047 CET | 8.8.8.8 | 192.168.2.3 | 0xac8f | No error (0) | hiphotos.baidu.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.597928047 CET | 8.8.8.8 | 192.168.2.3 | 0xac8f | No error (0) | hiphotos.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.597928047 CET | 8.8.8.8 | 192.168.2.3 | 0xac8f | No error (0) | hiphotos.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.597928047 CET | 8.8.8.8 | 192.168.2.3 | 0xac8f | No error (0) | 185.10.104.120 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.699131012 CET | 8.8.8.8 | 192.168.2.3 | 0x61e2 | No error (0) | 103.86.67.66 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.699131012 CET | 8.8.8.8 | 192.168.2.3 | 0x61e2 | No error (0) | 45.125.217.58 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.699131012 CET | 8.8.8.8 | 192.168.2.3 | 0x61e2 | No error (0) | 103.86.67.98 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:18.699131012 CET | 8.8.8.8 | 192.168.2.3 | 0x61e2 | No error (0) | 103.86.65.194 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:19.756649971 CET | 8.8.8.8 | 192.168.2.3 | 0xdbfe | No error (0) | pic.rmb.bdstatic.com.a.bdydns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:19.756649971 CET | 8.8.8.8 | 192.168.2.3 | 0xdbfe | No error (0) | opencdnpicrmb.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:19.756649971 CET | 8.8.8.8 | 192.168.2.3 | 0xdbfe | No error (0) | opencdnpicrmb.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:19.756649971 CET | 8.8.8.8 | 192.168.2.3 | 0xdbfe | No error (0) | 104.193.88.112 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:19.756649971 CET | 8.8.8.8 | 192.168.2.3 | 0xdbfe | No error (0) | 104.193.90.80 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.152762890 CET | 8.8.8.8 | 192.168.2.3 | 0xff35 | No error (0) | pic.rmb.bdstatic.com.a.bdydns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.152762890 CET | 8.8.8.8 | 192.168.2.3 | 0xff35 | No error (0) | opencdnpicrmb.jomodns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.152762890 CET | 8.8.8.8 | 192.168.2.3 | 0xff35 | No error (0) | opencdnpicrmb.gshifen.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.152762890 CET | 8.8.8.8 | 192.168.2.3 | 0xff35 | No error (0) | 185.10.104.115 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | www.2345.com.w.alikunlun.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.216 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.217 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.212 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.215 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.214 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.218 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.213 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:20.344877958 CET | 8.8.8.8 | 192.168.2.3 | 0x8eb5 | No error (0) | 79.133.177.211 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | www.2345.com.w.alikunlun.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.211 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.215 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.213 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.216 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.217 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.212 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.214 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:21.728574991 CET | 8.8.8.8 | 192.168.2.3 | 0x6406 | No error (0) | 79.133.177.218 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | www.2345.com.w.alikunlun.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.214 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.215 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.216 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.211 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.218 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.213 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.212 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:23.011231899 CET | 8.8.8.8 | 192.168.2.3 | 0x3ae4 | No error (0) | 79.133.177.217 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | www.2345.com.w.alikunlun.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.218 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.214 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.211 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.212 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.216 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.215 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.217 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:24.215467930 CET | 8.8.8.8 | 192.168.2.3 | 0x4233 | No error (0) | 79.133.177.213 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | www.2345.com.w.alikunlun.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.215 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.218 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.213 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.212 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.211 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.214 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.216 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2023 07:40:25.250333071 CET | 8.8.8.8 | 192.168.2.3 | 0xbec1 | No error (0) | 79.133.177.217 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.3 | 49705 | 103.86.67.66 | 10100 | C:\Users\user\Desktop\winaudio.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jan 30, 2023 07:40:11.032207966 CET | 117 | OUT | |
Jan 30, 2023 07:40:11.243551970 CET | 117 | IN | |
Jan 30, 2023 07:40:13.641254902 CET | 134 | OUT | |
Jan 30, 2023 07:40:13.852669001 CET | 134 | IN | |
Jan 30, 2023 07:40:16.331585884 CET | 151 | OUT | |
Jan 30, 2023 07:40:16.543731928 CET | 152 | IN | |
Jan 30, 2023 07:40:18.680522919 CET | 168 | OUT | |
Jan 30, 2023 07:40:18.891633987 CET | 168 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.3 | 49706 | 104.193.88.112 | 80 | C:\Users\user\Desktop\winaudio.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jan 30, 2023 07:40:12.256911993 CET | 118 | OUT | |
Jan 30, 2023 07:40:12.431133032 CET | 120 | IN |