Windows
Analysis Report
92f25a21-b9c1-4aee-af3e-cacf098605e9
Overview
General Information
Detection
Score: | 76 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Compliance
Score: | 18 |
Range: | 0 - 100 |
Signatures
Classification
- System is w10x64_ra
- 92f25a21-b9c1-4aee-af3e-cacf098605e9.exe (PID: 6320 cmdline:
C:\Users\u ser\Deskto p\92f25a21 -b9c1-4aee -af3e-cacf 098605e9.e xe MD5: 2621B754576047A6E94ACBF1DD4FE0EF) - 92f25a21-b9c1-4aee-af3e-cacf098605e9.exe (PID: 6388 cmdline:
"C:\Users\ user\Deskt op\92f25a2 1-b9c1-4ae e-af3e-cac f098605e9. exe" --loc al-service MD5: 2621B754576047A6E94ACBF1DD4FE0EF) - 92f25a21-b9c1-4aee-af3e-cacf098605e9.exe (PID: 6396 cmdline:
"C:\Users\ user\Deskt op\92f25a2 1-b9c1-4ae e-af3e-cac f098605e9. exe" --loc al-control MD5: 2621B754576047A6E94ACBF1DD4FE0EF) - 92f25a21-b9c1-4aee-af3e-cacf098605e9.exe (PID: 6904 cmdline:
"C:\Users\ user\Deskt op\92f25a2 1-b9c1-4ae e-af3e-cac f098605e9. exe" --ins tall "C:\P rogram Fil es (x86)\A nyDesk" -- start-with -win --cre ate-shortc uts --crea te-taskbar -icon --cr eate-deskt op-icon -- install-dr iver:mirro r --instal l-driver:p rinter --u pdate-auto --svc-con f "C:\User s\user\App Data\Roami ng\AnyDesk \service.c onf" --sys -conf "C:\ Users\user \AppData\R oaming\Any Desk\syste m.conf" MD5: 2621B754576047A6E94ACBF1DD4FE0EF) - expand.exe (PID: 7088 cmdline:
expand -F: * "C:\User s\user\App Data\Roami ng\AnyDesk \printer_d river\v4.c ab" "C:\Us ers\user\A ppData\Roa ming\AnyDe sk\printer _driver" MD5: 8C2235852F8C2659EB6CA4A0C6B3B3F1) - conhost.exe (PID: 7096 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F) - rundll32.exe (PID: 1176 cmdline:
C:\Windows \System32\ rundll32.e xe" printu i.dll, Pri ntUIEntry /if /b "An yDesk Prin ter" /f "C :\Users\us er\AppData \Roaming\A nyDesk\pri nter_drive r\AnyDeskP rintDriver .inf" /r " AD_Port" / m "AnyDesk v4 Printe r Driver MD5: D0432468FA4B7F66166C430E1334DBDA)
- svchost.exe (PID: 6520 cmdline:
C:\Windows \System32\ svchost.ex e -k Netwo rkService -p -s DoSv c MD5: 9520A99E77D6196D0D09833146424113)
- svchost.exe (PID: 6564 cmdline:
C:\Windows \System32\ svchost.ex e -k Netwo rkService -p MD5: 9520A99E77D6196D0D09833146424113)
- SgrmBroker.exe (PID: 6612 cmdline:
C:\Windows \system32\ SgrmBroker .exe MD5: C51AA0BB954EA45E85572E6CC29BA6F4)
- svchost.exe (PID: 6644 cmdline:
C:\Windows \System32\ svchost.ex e -k Local ServiceNet workRestri cted -p -s wscsvc MD5: 9520A99E77D6196D0D09833146424113)
- AnyDesk.exe (PID: 6944 cmdline:
"C:\Progra m Files (x 86)\AnyDes k\AnyDesk. exe" --ser vice MD5: 2621B754576047A6E94ACBF1DD4FE0EF)
- AnyDesk.exe (PID: 7044 cmdline:
"C:\Progra m Files (x 86)\AnyDes k\AnyDesk. exe" --con trol MD5: 2621B754576047A6E94ACBF1DD4FE0EF)
- AnyDesk.exe (PID: 6160 cmdline:
"C:\Progra m Files (x 86)\AnyDes k\AnyDesk. exe" --new -install MD5: 2621B754576047A6E94ACBF1DD4FE0EF)
- svchost.exe (PID: 5944 cmdline:
C:\Windows \system32\ svchost.ex e -k DcomL aunch -p - s DeviceIn stall MD5: 9520A99E77D6196D0D09833146424113) - drvinst.exe (PID: 5292 cmdline:
DrvInst.ex e "4" "0" "C:\Users\ user\AppDa ta\Local\T emp\{a1d03 c80-7a9d-0 740-8675-a d849a86a4e 4}\anydesk printdrive r.inf" "9" "45a2ed01 3" "000000 00000001BC " "WinSta0 \Default" "000000000 0000164" " 208" "c:\u sers\user\ appdata\ro aming\anyd esk\printe r_driver" MD5: 100997A8B475B1D1B173BE8941DFE1A6) - rundll32.exe (PID: 5636 cmdline:
rundll32.e xe C:\Wind ows\system 32\pnpui.d ll,Install SecurityPr omptRunDll W 20 Globa l\{a93448a 4-5e3b-e34 d-a377-ec8 1ab406cb0} Global\{5 6375bfd-f2 4b-3d4c-9c c8-12acbcf 982ed} C:\ Windows\Sy stem32\Dri verStore\T emp\{5190a ac7-b965-5 d4c-a8f2-d 012c5c874c e}\anydesk printdrive r.inf C:\W indows\Sys tem32\Driv erStore\Te mp\{5190aa c7-b965-5d 4c-a8f2-d0 12c5c874ce }\AnyDeskP rintDriver .cat MD5: F68AF942FD7CCC0E7BAB1A2335D2AD26)
- cleanup
Click to jump to signature section
Source: | EXE: | Jump to behavior |
Source: | DLL: | Jump to behavior |
Compliance |
---|
Source: | Static PE information: |
Source: | EXE: | Jump to behavior |
Source: | DLL: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | JA3 fingerprint: |
Source: | IP Address: |
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary or memory string: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Static PE information: |
Source: | File created: |
Source: | File deleted: |
Source: | File created: |
Source: | Code function: | 1_3_0417CF5E | |
Source: | Code function: | 1_3_0417CF5E | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_041580C6 | |
Source: | Code function: | 1_3_0417CF5E | |
Source: | Code function: | 1_3_0417CF5E | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_041580C6 | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 1_3_0417DFC9 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D89BC0 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 2_3_03D13300 | |
Source: | Code function: | 3_3_03E42687 | |
Source: | Code function: | 3_3_03E42687 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E86EC2 | |
Source: | Code function: | 3_3_03E86EC2 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E86EC2 | |
Source: | Code function: | 3_3_03E86EC2 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 | |
Source: | Code function: | 3_3_03E85291 |
Source: | Code function: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process token adjusted: |
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: |
Source: | Key value queried: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | Process created: |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window detected: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | Unpacked PE file: |
Source: | Code function: | 1_3_0393612C | |
Source: | Code function: | 1_3_0393612C | |
Source: | Code function: | 1_3_0392EB69 | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_0392EB09 | |
Source: | Code function: | 1_3_0392EB09 | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_0392EB09 | |
Source: | Code function: | 1_3_0392EB09 | |
Source: | Code function: | 1_3_0393612C | |
Source: | Code function: | 1_3_0393612C | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_03953FF9 | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_039338DD | |
Source: | Code function: | 1_3_04160A7A |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: |
Source: | Registry key monitored for changes: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | Last function: | ||
Source: | Last function: |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Process information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | File Volume queried: | ||
Source: | File Volume queried: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Registry key value queried: | ||
Source: | Registry key value queried: |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | Key value created or modified: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Registry key created or modified: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 521 Windows Management Instrumentation | 2 DLL Search Order Hijacking | 2 DLL Search Order Hijacking | 111 Disable or Modify Tools | 1 Input Capture | 1 File and Directory Discovery | Remote Services | 1 Archive Collected Data | Exfiltration Over Other Network Medium | 12 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | 12 Command and Scripting Interpreter | 2 Registry Run Keys / Startup Folder | 11 Process Injection | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 224 System Information Discovery | Remote Desktop Protocol | 1 Input Capture | Exfiltration Over Bluetooth | 1 Non-Standard Port | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | 2 Registry Run Keys / Startup Folder | 2 Obfuscated Files or Information | Security Account Manager | 1 Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 2 Non-Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | 1 Software Packing | NTDS | 431 Security Software Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 3 Application Layer Protocol | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 2 DLL Search Order Hijacking | LSA Secrets | 1 Process Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 1 File Deletion | Cached Domain Credentials | 331 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | 32 Masquerading | DCSync | 1 Remote System Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | 331 Virtualization/Sandbox Evasion | Proc Filesystem | Network Service Scanning | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue | |
Exploit Public-Facing Application | PowerShell | At (Linux) | At (Linux) | 11 Process Injection | /etc/passwd and /etc/shadow | System Network Connections Discovery | Software Deployment Tools | Data Staged | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Web Protocols | Rogue Cellular Base Station | Data Destruction | |
Supply Chain Compromise | AppleScript | At (Windows) | At (Windows) | 1 Hidden Files and Directories | Network Sniffing | Process Discovery | Taint Shared Content | Local Data Staging | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | File Transfer Protocols | Data Encrypted for Impact | ||
Compromise Software Dependencies and Development Tools | Windows Command Shell | Cron | Cron | 1 Rundll32 | Input Capture | Permission Groups Discovery | Replication Through Removable Media | Remote Data Staging | Exfiltration Over Physical Medium | Mail Protocols | Service Stop |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs | |||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
1% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
d1atxff5avezsq.cloudfront.net | 18.66.97.18 | true | false | high | |
boot.net.anydesk.com | 185.229.191.41 | true | false | high | |
relay-10d0d168.net.anydesk.com | 208.115.231.206 | true | false | high | |
api.playanext.com | unknown | unknown | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | low | ||
false | low |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.66.97.76 | unknown | United States | 3 | MIT-GATEWAYSUS | false | |
185.229.191.39 | unknown | Czech Republic | 60068 | CDN77GB | false | |
185.229.191.41 | boot.net.anydesk.com | Czech Republic | 60068 | CDN77GB | false | |
18.66.97.82 | unknown | United States | 3 | MIT-GATEWAYSUS | false | |
239.255.102.18 | unknown | Reserved | unknown | unknown | false | |
208.115.231.206 | relay-10d0d168.net.anydesk.com | United States | 46475 | LIMESTONENETWORKSUS | false |
Joe Sandbox Version: | 37.0.0 Beryl |
Analysis ID: | 840831 |
Start date and time: | 2023-04-04 12:01:36 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 10m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip) |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 1 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | 92f25a21-b9c1-4aee-af3e-cacf098605e9 |
Detection: | MAL |
Classification: | mal76.evad.win@24/71@9/6 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: | Failed |
- Exclude process from analysis (whitelisted): WmiPrvSE.exe
- Excluded domains from analysis (whitelisted): login.live.com, ctldl.windowsupdate.com
- Execution Graph export aborted for target 92f25a21-b9c1-4aee-af3e-cacf098605e9.exe, PID 6320 because there are no executed function
- Execution Graph export aborted for target 92f25a21-b9c1-4aee-af3e-cacf098605e9.exe, PID 6388 because there are no executed function
- Execution Graph export aborted for target 92f25a21-b9c1-4aee-af3e-cacf098605e9.exe, PID 6396 because there are no executed function
- Not all processes where analyzed, report is missing behavior information
- Report creation exceeded maximum time and may have missing disassembly code information.
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
12:02:56 | API Interceptor | |
12:04:20 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
18.66.97.76 | Get hash | malicious | HTMLPhisher | Browse | ||
185.229.191.39 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | CryptOne, Mofksys | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
185.229.191.41 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
boot.net.anydesk.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DCRat, EICAR | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CryptOne, Mofksys | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
d1atxff5avezsq.cloudfront.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, RedLine | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CDN77GB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
MIT-GATEWAYSUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | DanaBot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
c91bde19008eefabce276152ccd51457 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CryptOne, Mofksys | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Program Files (x86)\AnyDesk\gcapi.dll | Get hash | malicious | DanaBot | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | DanaBot | Browse | |||
Get hash | malicious | DanaBot | Browse | |||
Get hash | malicious | DanaBot | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | RedLine | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3853384 |
Entropy (8bit): | 7.9990645721025375 |
Encrypted: | true |
SSDEEP: | 98304:6W0Ughn1zD8gmJUikb59sFaZw3abaqt8+Uen/xIZ:6WBCn5D8gmJUrvsFaZw3HsJIZ |
MD5: | 2621B754576047A6E94ACBF1DD4FE0EF |
SHA1: | 246F36118C53AC7421518DBC9BB4259128F3C417 |
SHA-256: | 109B03FFC45231E5A4C8805A10926492890F7B568F8A93ABE1FA495B4BD42975 |
SHA-512: | 6B3D58AFC82297626BC85D0EA0BD9A16626C34CA3A13BC6CDF3EEA396946685641D8659A472FF8C6526E3EFBDFD439B05B79965ED195FD1B734A935FFBB00812 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 394240 |
Entropy (8bit): | 6.700175464943679 |
Encrypted: | false |
SSDEEP: | 6144:Tv/ioKdMF+LZD/ZRj1vwWrrUFMNoz4pFGxjEB1NYAOrabN2GZvFcD7:Td+LZrNwWrrwMNoz4vG1OYZabtK7 |
MD5: | 1CE7D5A1566C8C449D0F6772A8C27900 |
SHA1: | 60854185F6338E1BFC7497FD41AA44C5C00D8F85 |
SHA-256: | 73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF |
SHA-512: | 7E3411BE8614170AE91DB1626C452997DC6DB663D79130872A124AF982EE1D457CEFBA00ABD7F5269ADCE3052403BE31238AECC3934C7379D224CB792D519753 |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Preview: |
Process: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
File Type: | |
Category: | modified |
Size (bytes): | 15121 |
Entropy (8bit): | 4.285196607006061 |
Encrypted: | false |
SSDEEP: | 96:VDtB0IA9b0mj+5rcgHpCWlWhxYJ8LHHD9Q5/LJAm5VWQSGr6k:50IA9bfYK/2d |
MD5: | BDAD802CF6D62C37135B57B6BEE1965C |
SHA1: | 16C7B04384E941B82D117E1D045AEAB431010F66 |
SHA-256: | AE725D80D450AC9AD5B7C4D6861BD040F8BCC733767626EF6E5B8B6056D01CC9 |
SHA-512: | C42941AA4848173231BDF56D5E7CCAC4279257A3ABAA6A1F26B55604869E67EB2812D03B7D8264404583E267286ADE900B19E404A78AF17807E7FD2CF7E252FA |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2762 |
Entropy (8bit): | 6.018445904068247 |
Encrypted: | false |
SSDEEP: | 48:uISTK3iJFyGm431gbMPbiqloJFRWjLboNFCZljSPtgMx5+FFH0lJTZrgmWh7c:uISTUiW43WbMPblGJFcfboNcZYWaYD8N |
MD5: | 4EC555CCEA1B60A27825E3332476EC2F |
SHA1: | 85DD1BE031FC9B2E3F6D1929E30D9F8DECCBACB0 |
SHA-256: | A1F90D903445ED57DB5BD03853021FC7A3E1B51EB0CCB55FC0D091243166B6CA |
SHA-512: | F11F7B88D05196EF296CFBF91DCFB49E34B588CFEBFF7DCCD9BC6EE6E90309CCFD999778F99EA523E9795640F65E300D7B787CEE9C783C7DFFB41C72FCD36E54 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 879 |
Entropy (8bit): | 4.872426810749163 |
Encrypted: | false |
SSDEEP: | 12:oizQCJkDLrhdOqTO67lG5sIiBs7SDL+7lNqQHvWhQ44LroBGgFBG0wlcp+gG8W:oZdOqT3GiBsee5sAw34LtBJlSrG |
MD5: | 64D48EF95000F671E249566BE90B41BA |
SHA1: | AF6E32EB682C602E65A614882B07FD2F55313289 |
SHA-256: | F9569FDB05BEF1E57DBFF8BDED454E03EE6D5085E3E34189365411180E9D2F72 |
SHA-512: | 28F8CCAA7D600280857272C5E9A2E4F5F99C16EB1FAF8C32D47BF74628E1B02B9910BE6AF8D0E4A729DFFB075AAE34C50356FA204F641EB38E7B8B3DDD45DBC0 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1975 |
Entropy (8bit): | 3.3561116249716587 |
Encrypted: | false |
SSDEEP: | 24:8uFcBGdOE4MCdvEepAs/A+dyxdfLUUjsabwMbdym2:8uVdOxes/RdSdfgna0MBy |
MD5: | 7EFC53209567973100B0030A1E0D2887 |
SHA1: | B207528184EF2D7CF28C98E634D7070A1C4EE810 |
SHA-256: | 923D0B57D5A0A8E2F56DC0E85058BA9FA4604095931D131AA058C69907BB6635 |
SHA-512: | A72E5AD0CEFF2874716CF7D81F8EC2D442D2E4ABFEB64A19C166FAE960385ABEFF800925B0BDF8398201B8B2F25293D08CCC5618307359ED52AF16A40CCFE85E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1102 |
Entropy (8bit): | 4.630772014357285 |
Encrypted: | false |
SSDEEP: | 24:8+cBGdOE4MCdvEepAs/P1dXnMkDoUUjKrabwMb6m2:8+VdOxes/P1dXnMY9la0MO |
MD5: | CE333BCEDC052D763500C8A4A87124BE |
SHA1: | 370CA876EEF2A3C90C6E741349D1E3C2D48DF332 |
SHA-256: | 00E64F9962F45B80EE0F225773D0331B9D8AB5C8077C9E17048960791C5D352E |
SHA-512: | 6E9A56B0B9E58962D385FEE4FE9ED5A0532896B7586BBFF980F941AE7E019DC0E621F4F79285613D0A13AB0865E0A5704F05B4B0A3581EF5A9C8540F81764A14 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1997 |
Entropy (8bit): | 3.368182633349687 |
Encrypted: | false |
SSDEEP: | 24:8tBcBGdOE4MCdvEepAs/A+dSNbydfLUUjsabwMbdym2:8tBVdOxes/RdAydfgna0MBy |
MD5: | E998909572A3BFAE769946ADE54E2E9E |
SHA1: | 8B1CF8740EC9D084AF66F3161595353E8167000A |
SHA-256: | C519D32628EDD19C7F6E292EC1E4446E35C062BF49425A7EEFFB9E448AF73671 |
SHA-512: | 24B985827EF15F797E5796D3A14D6628529A0DA1EF4E6D5AA175E0243BA1EF4CAF2C1576C40FD851BDEAF76389B728FDBB521F78515E599F0BCE7D9C4A551C46 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1957 |
Entropy (8bit): | 3.351696474439772 |
Encrypted: | false |
SSDEEP: | 24:8kgENydOE4M/lEepAs/AbdyxdfLUUjsabwMbdym2:8k7IdOU8s/MdSdfgna0MBy |
MD5: | 46D70ECD124D2DF5EDCAE22F56548A4F |
SHA1: | D394FDFBFCB5E0508303A658A24E42D0C74E7C48 |
SHA-256: | 43D764CCD22B611E5B680D1C27B169A50ED3251AD697FCCC19F8F0517A04BFFF |
SHA-512: | 817F5BCBCE159C93129C2C1888EE0F02D2C4D845D5380B1BEAFBC00C3E3E541AD4DDF582629414654A538227A4097D956D50ADC30BCD208F3CE8C31E8D51DB2C |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 394240 |
Entropy (8bit): | 6.700175464943679 |
Encrypted: | false |
SSDEEP: | 6144:Tv/ioKdMF+LZD/ZRj1vwWrrUFMNoz4pFGxjEB1NYAOrabN2GZvFcD7:Td+LZrNwWrrwMNoz4vG1OYZabtK7 |
MD5: | 1CE7D5A1566C8C449D0F6772A8C27900 |
SHA1: | 60854185F6338E1BFC7497FD41AA44C5C00D8F85 |
SHA-256: | 73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF |
SHA-512: | 7E3411BE8614170AE91DB1626C452997DC6DB663D79130872A124AF982EE1D457CEFBA00ABD7F5269ADCE3052403BE31238AECC3934C7379D224CB792D519753 |
Malicious: | false |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Local\Temp\{a1d03c80-7a9d-0740-8675-ad849a86a4e4}\AnyDeskPrintDriver-manifest.ini (copy)
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271 |
Entropy (8bit): | 5.266454556037467 |
Encrypted: | false |
SSDEEP: | 6:/5QXK4VCzXL2ory+eC2rgN+jAJh6piBVAZVhe81W8l2+:Cazb2Yy+eC2xKh64Ke8xN |
MD5: | 0D7876B516B908AAB67A8E01E49C4DED |
SHA1: | 0900C56619CD785DECA4C302972E74D5FACD5EC9 |
SHA-256: | 98933DE1B6C34B4221D2DD065715418C85733C2B8CB4BD12AC71D797B78A1753 |
SHA-512: | 6874F39FFF34F9678E22C47B67F5CD33B825C41F0B0FD84041450A94CC86CC94811293BA838F5267C9CD167D9ABCF74E00A2F3C65E460C67E668429403124546 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\{a1d03c80-7a9d-0740-8675-ad849a86a4e4}\AnyDeskPrintDriver.cat (copy)
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9492 |
Entropy (8bit): | 6.985301072138844 |
Encrypted: | false |
SSDEEP: | 192:/JgfSpJNc5d2WC8Nv7tPDWpHsq7wH0JOqNG8Fp28Wh8nsiq:/X9N8LPDGV75JNNzFwhhiY |
MD5: | 6D1663F0754E05A5B181719F2427D20A |
SHA1: | 5AFFB483E8CA0E73E5B26928A3E47D72DFD1C46E |
SHA-256: | 12AF5F4E8FC448D02BCFD88A302FEBE6820A5A497157EF5DCA2219C50C1621E3 |
SHA-512: | 7895F6E35591270BFA9E373B69B55389D250751B56B7EA0D5B10AB770283B8166182C75DCA4EBBECDD6E9790DBBFDA23130FB4F652545FD39C95619B77195424 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\{a1d03c80-7a9d-0740-8675-ad849a86a4e4}\AnyDeskPrintDriver.gpd (copy)
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12156 |
Entropy (8bit): | 4.438774767382979 |
Encrypted: | false |
SSDEEP: | 192:94I4jNuqQ7QKNbcVHrdxhMXopCIrVjFfJU:MNk/NbcVHrdjMXoPBjFfJU |
MD5: | E0D32D133D4FE83B0E90AA22F16F4203 |
SHA1: | A06B053A1324790DFD0780950D14D8FCEC8A5EB9 |
SHA-256: | 6E996F3523BCF961DE2FF32E5A35BCBB59CB6FE343357EFF930CD4D6FA35F1F4 |
SHA-512: | C0D24104D0B6CB15FF952CBEF66013E96E5ED2D4D3B4A17ABA3E571A1B9F16BD0E5C141E6AABAC5651B4A198DBD9E65571C8C871E737EB5DCF47196C87B8907B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\{a1d03c80-7a9d-0740-8675-ad849a86a4e4}\AnyDeskPrintDriverRenderFilter-PipelineConfig.xml (copy)
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 584 |
Entropy (8bit): | 4.933762469125028 |
Encrypted: | false |
SSDEEP: | 12:4BRL8gVDc8Ez37BDckvLzLkiYd/SUX+EfDUH+CreIByn:4BRLNVDez31DckjfaxnuIDUHV5yn |
MD5: | B76DF597DD3183163A6D19B73D28E6D3 |
SHA1: | 9F7D18A7E09B3818C32C9654FB082A784BE35034 |
SHA-256: | CBA7C721B76BB7245CD0F1FBFDF85073D57512EAD2593050CAD12CE76886AC33 |
SHA-512: | 6F74AD6BBBB931FE78A6545BB6735E63C2C11C025253A7CB0C4605E364A1E3AC806338BB62311D715BF791C5A5610EE02942FF5A0280282D68B93708F1317C69 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\{a1d03c80-7a9d-0740-8675-ad849a86a4e4}\AnyDeskPrintDriverRenderFilter.dll (copy)
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284000 |
Entropy (8bit): | 6.27967812164935 |
Encrypted: | false |
SSDEEP: | 6144:AJuaCAjg/xajfxaH+6a8WbEyLfqOxsgFXoh/A4hEz72:AJTdjgQjf2OCOxJoX |
MD5: | 1E4FAAF4E348BA202DEE66D37EB0B245 |
SHA1: | BB706971BD21F07AF31157875E0521631ECF8FA5 |
SHA-256: | 3AA636E7660BE17F841B7F0E380F93FB94F25C62D9100758B1D480CBB863DB9D |
SHA-512: | 008E59D645B30ADD7D595D69BE48192765DAC606801E418EEB79991E0645833ABEACFC55AA29DAE52DC46AAF22B5C6BC1A9579C2005F4324BECE9954EBB182BA |
Malicious: | false |
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284000 |
Entropy (8bit): | 6.27967812164935 |
Encrypted: | false |
SSDEEP: | 6144:AJuaCAjg/xajfxaH+6a8WbEyLfqOxsgFXoh/A4hEz72:AJTdjgQjf2OCOxJoX |
MD5: | 1E4FAAF4E348BA202DEE66D37EB0B245 |
SHA1: | BB706971BD21F07AF31157875E0521631ECF8FA5 |
SHA-256: | 3AA636E7660BE17F841B7F0E380F93FB94F25C62D9100758B1D480CBB863DB9D |
SHA-512: | 008E59D645B30ADD7D595D69BE48192765DAC606801E418EEB79991E0645833ABEACFC55AA29DAE52DC46AAF22B5C6BC1A9579C2005F4324BECE9954EBB182BA |
Malicious: | false |
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 584 |
Entropy (8bit): | 4.933762469125028 |
Encrypted: | false |
SSDEEP: | 12:4BRL8gVDc8Ez37BDckvLzLkiYd/SUX+EfDUH+CreIByn:4BRLNVDez31DckjfaxnuIDUHV5yn |
MD5: | B76DF597DD3183163A6D19B73D28E6D3 |
SHA1: | 9F7D18A7E09B3818C32C9654FB082A784BE35034 |
SHA-256: | CBA7C721B76BB7245CD0F1FBFDF85073D57512EAD2593050CAD12CE76886AC33 |
SHA-512: | 6F74AD6BBBB931FE78A6545BB6735E63C2C11C025253A7CB0C4605E364A1E3AC806338BB62311D715BF791C5A5610EE02942FF5A0280282D68B93708F1317C69 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271 |
Entropy (8bit): | 5.266454556037467 |
Encrypted: | false |
SSDEEP: | 6:/5QXK4VCzXL2ory+eC2rgN+jAJh6piBVAZVhe81W8l2+:Cazb2Yy+eC2xKh64Ke8xN |
MD5: | 0D7876B516B908AAB67A8E01E49C4DED |
SHA1: | 0900C56619CD785DECA4C302972E74D5FACD5EC9 |
SHA-256: | 98933DE1B6C34B4221D2DD065715418C85733C2B8CB4BD12AC71D797B78A1753 |
SHA-512: | 6874F39FFF34F9678E22C47B67F5CD33B825C41F0B0FD84041450A94CC86CC94811293BA838F5267C9CD167D9ABCF74E00A2F3C65E460C67E668429403124546 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9492 |
Entropy (8bit): | 6.985301072138844 |
Encrypted: | false |
SSDEEP: | 192:/JgfSpJNc5d2WC8Nv7tPDWpHsq7wH0JOqNG8Fp28Wh8nsiq:/X9N8LPDGV75JNNzFwhhiY |
MD5: | 6D1663F0754E05A5B181719F2427D20A |
SHA1: | 5AFFB483E8CA0E73E5B26928A3E47D72DFD1C46E |
SHA-256: | 12AF5F4E8FC448D02BCFD88A302FEBE6820A5A497157EF5DCA2219C50C1621E3 |
SHA-512: | 7895F6E35591270BFA9E373B69B55389D250751B56B7EA0D5B10AB770283B8166182C75DCA4EBBECDD6E9790DBBFDA23130FB4F652545FD39C95619B77195424 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12156 |
Entropy (8bit): | 4.438774767382979 |
Encrypted: | false |
SSDEEP: | 192:94I4jNuqQ7QKNbcVHrdxhMXopCIrVjFfJU:MNk/NbcVHrdjMXoPBjFfJU |
MD5: | E0D32D133D4FE83B0E90AA22F16F4203 |
SHA1: | A06B053A1324790DFD0780950D14D8FCEC8A5EB9 |
SHA-256: | 6E996F3523BCF961DE2FF32E5A35BCBB59CB6FE343357EFF930CD4D6FA35F1F4 |
SHA-512: | C0D24104D0B6CB15FF952CBEF66013E96E5ED2D4D3B4A17ABA3E571A1B9F16BD0E5C141E6AABAC5651B4A198DBD9E65571C8C871E737EB5DCF47196C87B8907B |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2202 |
Entropy (8bit): | 3.6217875907609276 |
Encrypted: | false |
SSDEEP: | 12:QgAaZpAPzRprbo370PB2dHl1ElKAO09DK3dQ2xQ2dH12UIQDIPA9YuA9TKAmA9fd:Qi4fbY77sjW3dXbcXTxdqXH6yvMgy |
MD5: | D4CA3F9CEEB46740C6C43826D94ABA18 |
SHA1: | D863CB54AD2FA0CFC0329954CBE49F70F49FDB87 |
SHA-256: | 494E4351B85D2821E53A22434F51A4186AA0F7BE5724922FC96DFB16687AD37C |
SHA-512: | BE08BC144EE2A491FBC80449B4339C01871C6E7D2DDC0E251475D8E426220C6EF35F67698B0586156F0A62B22DB764C43842F577B82C3F9E4E93957F9D617DB4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\{a1d03c80-7a9d-0740-8675-ad849a86a4e4}\anydeskprintdriver.inf (copy)
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2202 |
Entropy (8bit): | 3.6217875907609276 |
Encrypted: | false |
SSDEEP: | 12:QgAaZpAPzRprbo370PB2dHl1ElKAO09DK3dQ2xQ2dH12UIQDIPA9YuA9TKAmA9fd:Qi4fbY77sjW3dXbcXTxdqXH6yvMgy |
MD5: | D4CA3F9CEEB46740C6C43826D94ABA18 |
SHA1: | D863CB54AD2FA0CFC0329954CBE49F70F49FDB87 |
SHA-256: | 494E4351B85D2821E53A22434F51A4186AA0F7BE5724922FC96DFB16687AD37C |
SHA-512: | BE08BC144EE2A491FBC80449B4339C01871C6E7D2DDC0E251475D8E426220C6EF35F67698B0586156F0A62B22DB764C43842F577B82C3F9E4E93957F9D617DB4 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | modified |
Size (bytes): | 52124 |
Entropy (8bit): | 4.3311659956524 |
Encrypted: | false |
SSDEEP: | 384:h2klMK6A2RdQ2vmYu2jaZAPpA6G2Z2yz2YY2fFbaRLVGFlx:tlMK6jfmYpaZZ6dNHFbaRLVGFlx |
MD5: | D2D4342137EF08B20174B53795293647 |
SHA1: | DA75F37BC3206865BD704FB2026D7E9AC2826B1B |
SHA-256: | 843C7EC3E8E318FC6FA54B94BC42F4E6C45A4EC3AE876AFB7F50DF551651A8B8 |
SHA-512: | C701DBC6E10CC045C1B397EC84C149E1E85E038623D48EDFBA0ADAAF12F64148673967436227983296BE2ABBBFB5334553BAB56AA0266D74C34071ED213730DC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\AnyDeskPrintDriver-manifest.ini (copy)
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271 |
Entropy (8bit): | 5.266454556037467 |
Encrypted: | false |
SSDEEP: | 6:/5QXK4VCzXL2ory+eC2rgN+jAJh6piBVAZVhe81W8l2+:Cazb2Yy+eC2xKh64Ke8xN |
MD5: | 0D7876B516B908AAB67A8E01E49C4DED |
SHA1: | 0900C56619CD785DECA4C302972E74D5FACD5EC9 |
SHA-256: | 98933DE1B6C34B4221D2DD065715418C85733C2B8CB4BD12AC71D797B78A1753 |
SHA-512: | 6874F39FFF34F9678E22C47B67F5CD33B825C41F0B0FD84041450A94CC86CC94811293BA838F5267C9CD167D9ABCF74E00A2F3C65E460C67E668429403124546 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12156 |
Entropy (8bit): | 4.438774767382979 |
Encrypted: | false |
SSDEEP: | 192:94I4jNuqQ7QKNbcVHrdxhMXopCIrVjFfJU:MNk/NbcVHrdjMXoPBjFfJU |
MD5: | E0D32D133D4FE83B0E90AA22F16F4203 |
SHA1: | A06B053A1324790DFD0780950D14D8FCEC8A5EB9 |
SHA-256: | 6E996F3523BCF961DE2FF32E5A35BCBB59CB6FE343357EFF930CD4D6FA35F1F4 |
SHA-512: | C0D24104D0B6CB15FF952CBEF66013E96E5ED2D4D3B4A17ABA3E571A1B9F16BD0E5C141E6AABAC5651B4A198DBD9E65571C8C871E737EB5DCF47196C87B8907B |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2202 |
Entropy (8bit): | 3.6217875907609276 |
Encrypted: | false |
SSDEEP: | 12:QgAaZpAPzRprbo370PB2dHl1ElKAO09DK3dQ2xQ2dH12UIQDIPA9YuA9TKAmA9fd:Qi4fbY77sjW3dXbcXTxdqXH6yvMgy |
MD5: | D4CA3F9CEEB46740C6C43826D94ABA18 |
SHA1: | D863CB54AD2FA0CFC0329954CBE49F70F49FDB87 |
SHA-256: | 494E4351B85D2821E53A22434F51A4186AA0F7BE5724922FC96DFB16687AD37C |
SHA-512: | BE08BC144EE2A491FBC80449B4339C01871C6E7D2DDC0E251475D8E426220C6EF35F67698B0586156F0A62B22DB764C43842F577B82C3F9E4E93957F9D617DB4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\AnyDeskPrintDriverRenderFilter-PipelineConfig.xml (copy)
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 584 |
Entropy (8bit): | 4.933762469125028 |
Encrypted: | false |
SSDEEP: | 12:4BRL8gVDc8Ez37BDckvLzLkiYd/SUX+EfDUH+CreIByn:4BRLNVDez31DckjfaxnuIDUHV5yn |
MD5: | B76DF597DD3183163A6D19B73D28E6D3 |
SHA1: | 9F7D18A7E09B3818C32C9654FB082A784BE35034 |
SHA-256: | CBA7C721B76BB7245CD0F1FBFDF85073D57512EAD2593050CAD12CE76886AC33 |
SHA-512: | 6F74AD6BBBB931FE78A6545BB6735E63C2C11C025253A7CB0C4605E364A1E3AC806338BB62311D715BF791C5A5610EE02942FF5A0280282D68B93708F1317C69 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\AnyDeskPrintDriverRenderFilter.dll (copy)
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284000 |
Entropy (8bit): | 6.27967812164935 |
Encrypted: | false |
SSDEEP: | 6144:AJuaCAjg/xajfxaH+6a8WbEyLfqOxsgFXoh/A4hEz72:AJTdjgQjf2OCOxJoX |
MD5: | 1E4FAAF4E348BA202DEE66D37EB0B245 |
SHA1: | BB706971BD21F07AF31157875E0521631ECF8FA5 |
SHA-256: | 3AA636E7660BE17F841B7F0E380F93FB94F25C62D9100758B1D480CBB863DB9D |
SHA-512: | 008E59D645B30ADD7D595D69BE48192765DAC606801E418EEB79991E0645833ABEACFC55AA29DAE52DC46AAF22B5C6BC1A9579C2005F4324BECE9954EBB182BA |
Malicious: | false |
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9492 |
Entropy (8bit): | 6.985301072138844 |
Encrypted: | false |
SSDEEP: | 192:/JgfSpJNc5d2WC8Nv7tPDWpHsq7wH0JOqNG8Fp28Wh8nsiq:/X9N8LPDGV75JNNzFwhhiY |
MD5: | 6D1663F0754E05A5B181719F2427D20A |
SHA1: | 5AFFB483E8CA0E73E5B26928A3E47D72DFD1C46E |
SHA-256: | 12AF5F4E8FC448D02BCFD88A302FEBE6820A5A497157EF5DCA2219C50C1621E3 |
SHA-512: | 7895F6E35591270BFA9E373B69B55389D250751B56B7EA0D5B10AB770283B8166182C75DCA4EBBECDD6E9790DBBFDA23130FB4F652545FD39C95619B77195424 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\e1962c70bafb448bad7b03b1bd5ee792$dpx$.tmp\0088b5eddf71564aac81be369e8c31e6.tmp
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12156 |
Entropy (8bit): | 4.438774767382979 |
Encrypted: | false |
SSDEEP: | 192:94I4jNuqQ7QKNbcVHrdxhMXopCIrVjFfJU:MNk/NbcVHrdjMXoPBjFfJU |
MD5: | E0D32D133D4FE83B0E90AA22F16F4203 |
SHA1: | A06B053A1324790DFD0780950D14D8FCEC8A5EB9 |
SHA-256: | 6E996F3523BCF961DE2FF32E5A35BCBB59CB6FE343357EFF930CD4D6FA35F1F4 |
SHA-512: | C0D24104D0B6CB15FF952CBEF66013E96E5ED2D4D3B4A17ABA3E571A1B9F16BD0E5C141E6AABAC5651B4A198DBD9E65571C8C871E737EB5DCF47196C87B8907B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\e1962c70bafb448bad7b03b1bd5ee792$dpx$.tmp\0a36ee12a9ad3845bf4d8fa62daf37a5.tmp
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284000 |
Entropy (8bit): | 6.27967812164935 |
Encrypted: | false |
SSDEEP: | 6144:AJuaCAjg/xajfxaH+6a8WbEyLfqOxsgFXoh/A4hEz72:AJTdjgQjf2OCOxJoX |
MD5: | 1E4FAAF4E348BA202DEE66D37EB0B245 |
SHA1: | BB706971BD21F07AF31157875E0521631ECF8FA5 |
SHA-256: | 3AA636E7660BE17F841B7F0E380F93FB94F25C62D9100758B1D480CBB863DB9D |
SHA-512: | 008E59D645B30ADD7D595D69BE48192765DAC606801E418EEB79991E0645833ABEACFC55AA29DAE52DC46AAF22B5C6BC1A9579C2005F4324BECE9954EBB182BA |
Malicious: | false |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\e1962c70bafb448bad7b03b1bd5ee792$dpx$.tmp\29294455594d444e97770a37389d8698.tmp
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9492 |
Entropy (8bit): | 6.985301072138844 |
Encrypted: | false |
SSDEEP: | 192:/JgfSpJNc5d2WC8Nv7tPDWpHsq7wH0JOqNG8Fp28Wh8nsiq:/X9N8LPDGV75JNNzFwhhiY |
MD5: | 6D1663F0754E05A5B181719F2427D20A |
SHA1: | 5AFFB483E8CA0E73E5B26928A3E47D72DFD1C46E |
SHA-256: | 12AF5F4E8FC448D02BCFD88A302FEBE6820A5A497157EF5DCA2219C50C1621E3 |
SHA-512: | 7895F6E35591270BFA9E373B69B55389D250751B56B7EA0D5B10AB770283B8166182C75DCA4EBBECDD6E9790DBBFDA23130FB4F652545FD39C95619B77195424 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\e1962c70bafb448bad7b03b1bd5ee792$dpx$.tmp\32ce531a6bee194ab314b1c8febdb8c9.tmp
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2202 |
Entropy (8bit): | 3.6217875907609276 |
Encrypted: | false |
SSDEEP: | 12:QgAaZpAPzRprbo370PB2dHl1ElKAO09DK3dQ2xQ2dH12UIQDIPA9YuA9TKAmA9fd:Qi4fbY77sjW3dXbcXTxdqXH6yvMgy |
MD5: | D4CA3F9CEEB46740C6C43826D94ABA18 |
SHA1: | D863CB54AD2FA0CFC0329954CBE49F70F49FDB87 |
SHA-256: | 494E4351B85D2821E53A22434F51A4186AA0F7BE5724922FC96DFB16687AD37C |
SHA-512: | BE08BC144EE2A491FBC80449B4339C01871C6E7D2DDC0E251475D8E426220C6EF35F67698B0586156F0A62B22DB764C43842F577B82C3F9E4E93957F9D617DB4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\e1962c70bafb448bad7b03b1bd5ee792$dpx$.tmp\3d0cce5d4bae9244b8ec1e3a0ce0bbbf.tmp
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 584 |
Entropy (8bit): | 4.933762469125028 |
Encrypted: | false |
SSDEEP: | 12:4BRL8gVDc8Ez37BDckvLzLkiYd/SUX+EfDUH+CreIByn:4BRLNVDez31DckjfaxnuIDUHV5yn |
MD5: | B76DF597DD3183163A6D19B73D28E6D3 |
SHA1: | 9F7D18A7E09B3818C32C9654FB082A784BE35034 |
SHA-256: | CBA7C721B76BB7245CD0F1FBFDF85073D57512EAD2593050CAD12CE76886AC33 |
SHA-512: | 6F74AD6BBBB931FE78A6545BB6735E63C2C11C025253A7CB0C4605E364A1E3AC806338BB62311D715BF791C5A5610EE02942FF5A0280282D68B93708F1317C69 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\AnyDesk\printer_driver\e1962c70bafb448bad7b03b1bd5ee792$dpx$.tmp\b01d0c5d79f8684dae6d8abbcf4cff9b.tmp
Download File
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271 |
Entropy (8bit): | 5.266454556037467 |
Encrypted: | false |
SSDEEP: | 6:/5QXK4VCzXL2ory+eC2rgN+jAJh6piBVAZVhe81W8l2+:Cazb2Yy+eC2xKh64Ke8xN |
MD5: | 0D7876B516B908AAB67A8E01E49C4DED |
SHA1: | 0900C56619CD785DECA4C302972E74D5FACD5EC9 |
SHA-256: | 98933DE1B6C34B4221D2DD065715418C85733C2B8CB4BD12AC71D797B78A1753 |
SHA-512: | 6874F39FFF34F9678E22C47B67F5CD33B825C41F0B0FD84041450A94CC86CC94811293BA838F5267C9CD167D9ABCF74E00A2F3C65E460C67E668429403124546 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 130790 |
Entropy (8bit): | 7.9981806600213545 |
Encrypted: | true |
SSDEEP: | 3072:TUM0b4NhJ73lElWbZIVb8deFZizw3A64baq6JuPDOuyPlmT:TUMjNhJiWaTuUQ5b+iyuyO |
MD5: | 5A4F0869298454215CCCF8B3230467B3 |
SHA1: | 924D99C6BF1351D83B97DF87924B482B6711E095 |
SHA-256: | 5214E8FF8454C715B10B448E496311B4FF18306ECF9CBB99A97EB0076304CE9A |
SHA-512: | 0ACF25D5666113CE4B39AA4B17CE307BEF1A807AF208560471A508D1ECADFA667D80F97C191E187B8EA6AF02128D55685A4DD0DDC6DD5AABE8B460F6BC727EEE |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2762 |
Entropy (8bit): | 6.018445904068247 |
Encrypted: | false |
SSDEEP: | 48:uISTK3iJFyGm431gbMPbiqloJFRWjLboNFCZljSPtgMx5+FFH0lJTZrgmWh7c:uISTUiW43WbMPblGJFcfboNcZYWaYD8N |
MD5: | 4EC555CCEA1B60A27825E3332476EC2F |
SHA1: | 85DD1BE031FC9B2E3F6D1929E30D9F8DECCBACB0 |
SHA-256: | A1F90D903445ED57DB5BD03853021FC7A3E1B51EB0CCB55FC0D091243166B6CA |
SHA-512: | F11F7B88D05196EF296CFBF91DCFB49E34B588CFEBFF7DCCD9BC6EE6E90309CCFD999778F99EA523E9795640F65E300D7B787CEE9C783C7DFFB41C72FCD36E54 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 819 |
Entropy (8bit): | 4.901622792084201 |
Encrypted: | false |
SSDEEP: | 12:oizQCJPjLZ9yXFTO67lG5sIiBs7SDL+7lNqQHvWhOu4LroBGgFBGEG8W:p19y1T3GiBsee5sAw54LtBEG |
MD5: | FC5FDA3AC9CC00AE7ECBA3EE176FE0B4 |
SHA1: | A831DB2E3BDA99F46F4AE524A2C2E8ACB127099F |
SHA-256: | 343D7E8EBBDBAA3F23AA0C1F760AB2C1A20A7160325E915AB53B93400C64984D |
SHA-512: | DE786C0759FCD1028A0194B34DCE6EF015B380E61AE05EFC8F185DB403927816D45EA7E0C165262F6EA46FDE51F7879B3AACEEC7E62ED90F3C046B47BDAB7648 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2272 |
Entropy (8bit): | 4.466175210156952 |
Encrypted: | false |
SSDEEP: | 48:snN4yLUVoc+dhenN4ES0k1TEEXB8q9lOLc86l:snNXWUwnN5kJVx |
MD5: | 06AC7B9B9B27B0D3F85BD9CDDB77CF27 |
SHA1: | B4F0C77DB7DC50B9D8C3A37C585EAE76876FB911 |
SHA-256: | D3B740FC23E08A76F056469AA5FBD58EF47D94F9F0C35F3BABF151A75BDBF097 |
SHA-512: | FDCC7C20544E14793EBDD02D893B80F34E1F8DAFA8E3D5EE1CFD62A16F384477DF63BCE6C4C0A4C89C3A68C5D6682AA53AF3DDB5036FDBD2EEFA17776A11978A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0EOK48O4PIN0VNVN4F93.temp
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5888810590533837 |
Encrypted: | false |
SSDEEP: | 48:ODbuUjRMyWun6ueoyCDCuUjOtyWun6ufyn:o6Ty/LZTBy/LC |
MD5: | BA39A18157342C4AC8CDBA48FFAF2DA5 |
SHA1: | 5228E8540DE341DAFCE06462E406D4AFDA0EB410 |
SHA-256: | B51069F98E6F6A37AF518CFAA529F3E81837E04D54C8E740D968585BD6B84DCF |
SHA-512: | AB2DF8437B45EC0BEBA80F72A278B784A671FDB8AE76DB95B5AA9793768BC451D12721D80AF9D9FFFD3B1FDF69DEC68D1F0D7762E22A98357F34008FEDB83F24 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms (copy)
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5888810590533837 |
Encrypted: | false |
SSDEEP: | 48:ODbuUjRMyWun6ueoyCDCuUjOtyWun6ufyn:o6Ty/LZTBy/LC |
MD5: | BA39A18157342C4AC8CDBA48FFAF2DA5 |
SHA1: | 5228E8540DE341DAFCE06462E406D4AFDA0EB410 |
SHA-256: | B51069F98E6F6A37AF518CFAA529F3E81837E04D54C8E740D968585BD6B84DCF |
SHA-512: | AB2DF8437B45EC0BEBA80F72A278B784A671FDB8AE76DB95B5AA9793768BC451D12721D80AF9D9FFFD3B1FDF69DEC68D1F0D7762E22A98357F34008FEDB83F24 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF6b9e0c.TMP (copy)
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5888810590533837 |
Encrypted: | false |
SSDEEP: | 48:ODbuUjRMyWun6ueoyCDCuUjOtyWun6ufyn:o6Ty/LZTBy/LC |
MD5: | BA39A18157342C4AC8CDBA48FFAF2DA5 |
SHA1: | 5228E8540DE341DAFCE06462E406D4AFDA0EB410 |
SHA-256: | B51069F98E6F6A37AF518CFAA529F3E81837E04D54C8E740D968585BD6B84DCF |
SHA-512: | AB2DF8437B45EC0BEBA80F72A278B784A671FDB8AE76DB95B5AA9793768BC451D12721D80AF9D9FFFD3B1FDF69DEC68D1F0D7762E22A98357F34008FEDB83F24 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF6cfb79.TMP (copy)
Download File
Process: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5888810590533837 |
Encrypted: | false |
SSDEEP: | 48:ODbuUjRMyWun6ueoyCDCuUjOtyWun6ufyn:o6Ty/LZTBy/LC |
MD5: | BA39A18157342C4AC8CDBA48FFAF2DA5 |
SHA1: | 5228E8540DE341DAFCE06462E406D4AFDA0EB410 |
SHA-256: | B51069F98E6F6A37AF518CFAA529F3E81837E04D54C8E740D968585BD6B84DCF |
SHA-512: | AB2DF8437B45EC0BEBA80F72A278B784A671FDB8AE76DB95B5AA9793768BC451D12721D80AF9D9FFFD3B1FDF69DEC68D1F0D7762E22A98357F34008FEDB83F24 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF6d21ce.TMP (copy)
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5888810590533837 |
Encrypted: | false |
SSDEEP: | 48:ODbuUjRMyWun6ueoyCDCuUjOtyWun6ufyn:o6Ty/LZTBy/LC |
MD5: | BA39A18157342C4AC8CDBA48FFAF2DA5 |
SHA1: | 5228E8540DE341DAFCE06462E406D4AFDA0EB410 |
SHA-256: | B51069F98E6F6A37AF518CFAA529F3E81837E04D54C8E740D968585BD6B84DCF |
SHA-512: | AB2DF8437B45EC0BEBA80F72A278B784A671FDB8AE76DB95B5AA9793768BC451D12721D80AF9D9FFFD3B1FDF69DEC68D1F0D7762E22A98357F34008FEDB83F24 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF6d21fd.TMP (copy)
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5888810590533837 |
Encrypted: | false |
SSDEEP: | 48:ODbuUjRMyWun6ueoyCDCuUjOtyWun6ufyn:o6Ty/LZTBy/LC |
MD5: | BA39A18157342C4AC8CDBA48FFAF2DA5 |
SHA1: | 5228E8540DE341DAFCE06462E406D4AFDA0EB410 |
SHA-256: | B51069F98E6F6A37AF518CFAA529F3E81837E04D54C8E740D968585BD6B84DCF |
SHA-512: | AB2DF8437B45EC0BEBA80F72A278B784A671FDB8AE76DB95B5AA9793768BC451D12721D80AF9D9FFFD3B1FDF69DEC68D1F0D7762E22A98357F34008FEDB83F24 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\FEX60B7P6JTZOT9GHXG0.temp
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.594189271172745 |
Encrypted: | false |
SSDEEP: | 24:bAnydujoUAO+GMmJyWujDOR+GJuj9NWoym2fAnydujoUAO+G1ntyWujDOR+GJujW:ECuUjRMyWun6ueoyICuUjOtyWun6ufyn |
MD5: | C0833C63B38539E373377B742D365BDD |
SHA1: | 5D55798D8473DE45D530780E605F2B954922B2DA |
SHA-256: | 20B0E98AC835772E6223492DA4532656611F89876B94003777A1BF98F20A8F2B |
SHA-512: | 6517D7E5E1908161FC5F73F05667C21418F1DA701B7B1C2686B65783F63920BB962FACA51EC27FE5B0A0ECEB2D2955E1CB8B77C280C9941677A6EB097F044A43 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\IEE55G25CM06RXUTXY9V.temp
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5926105390798146 |
Encrypted: | false |
SSDEEP: | 24:bvnydujoUAO+GMmJyWujDOR+GJuj9NWoym2fvnydujoUAO+G1ntyWujDOR+GJujW:bCuUjRMyWun6ueoyXCuUjOtyWun6ufyn |
MD5: | 92E277006D172822AAEEC33A2ED583E4 |
SHA1: | D208840C14A1E2443F21A27F1ED5A213D5C2C3D6 |
SHA-256: | 567CBC935617E7B30A3BC732FA09E7B28450625065ED476BE991684F93142E51 |
SHA-512: | 7574E02B242C5C7C3BFA8FEA8A3BC2FACC4242F5DD52CAB92D74651AC160A3749A0B11FFFB981CA97675E2783F3C30728C2DF153245D29BADB78F49A41AE4227 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NCL5IHL1YDFBRNH3OAAL.temp
Download File
Process: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3660 |
Entropy (8bit): | 3.2461381974733583 |
Encrypted: | false |
SSDEEP: | 24:ncBGdOE4MCdvEepAs/LmSdfYxWoym2LcBGdOE4MCdvEepAs/ynedfYxjDym2X:nVdOxes/L9dfXoybVdOxes/gedfqyn |
MD5: | B88366CB0E6BEECED15D5993281D61FF |
SHA1: | 68DFC21FBED6DADFC0E17B0189CEF315AEDB585C |
SHA-256: | B05600FF4F783305196C889A8246CDB710B6288920260BC42983DE43137BA988 |
SHA-512: | 39F81AFC84452E87A7241D117375E50FDA7BA2D5E1574C84DD6BBE0B071E26696725EACD08D569A03DEAA5DBD62856C6F3B332C35F05429E96BFAA439E707BB8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QB8JDMCYR4OSDMVOEG2V.temp
Download File
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3490 |
Entropy (8bit): | 3.5926105390798146 |
Encrypted: | false |
SSDEEP: | 24:bvnydujoUAO+GMmJyWujDOR+GJuj9NWoym2fvnydujoUAO+G1ntyWujDOR+GJujW:bCuUjRMyWun6ueoyXCuUjOtyWun6ufyn |
MD5: | 92E277006D172822AAEEC33A2ED583E4 |
SHA1: | D208840C14A1E2443F21A27F1ED5A213D5C2C3D6 |
SHA-256: | 567CBC935617E7B30A3BC732FA09E7B28450625065ED476BE991684F93142E51 |
SHA-512: | 7574E02B242C5C7C3BFA8FEA8A3BC2FACC4242F5DD52CAB92D74651AC160A3749A0B11FFFB981CA97675E2783F3C30728C2DF153245D29BADB78F49A41AE4227 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 394240 |
Entropy (8bit): | 6.700175464943679 |
Encrypted: | false |
SSDEEP: | 6144:Tv/ioKdMF+LZD/ZRj1vwWrrUFMNoz4pFGxjEB1NYAOrabN2GZvFcD7:Td+LZrNwWrrwMNoz4vG1OYZabtK7 |
MD5: | 1CE7D5A1566C8C449D0F6772A8C27900 |
SHA1: | 60854185F6338E1BFC7497FD41AA44C5C00D8F85 |
SHA-256: | 73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF |
SHA-512: | 7E3411BE8614170AE91DB1626C452997DC6DB663D79130872A124AF982EE1D457CEFBA00ABD7F5269ADCE3052403BE31238AECC3934C7379D224CB792D519753 |
Malicious: | false |
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2202 |
Entropy (8bit): | 3.6217875907609276 |
Encrypted: | false |
SSDEEP: | 12:QgAaZpAPzRprbo370PB2dHl1ElKAO09DK3dQ2xQ2dH12UIQDIPA9YuA9TKAmA9fd:Qi4fbY77sjW3dXbcXTxdqXH6yvMgy |
MD5: | D4CA3F9CEEB46740C6C43826D94ABA18 |
SHA1: | D863CB54AD2FA0CFC0329954CBE49F70F49FDB87 |
SHA-256: | 494E4351B85D2821E53A22434F51A4186AA0F7BE5724922FC96DFB16687AD37C |
SHA-512: | BE08BC144EE2A491FBC80449B4339C01871C6E7D2DDC0E251475D8E426220C6EF35F67698B0586156F0A62B22DB764C43842F577B82C3F9E4E93957F9D617DB4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 97395 |
Entropy (8bit): | 5.072295115306676 |
Encrypted: | false |
SSDEEP: | 768:jCNrdVhum5SAARRZum3qmArOkPWyssIHt+iqk:ji3humwAAdgOkPWHAiqk |
MD5: | 5E7D43EF96E006BDC7B0709DB82E48F6 |
SHA1: | 035D5284EAEA887E7FF59E9DE516415A774EA394 |
SHA-256: | CD201A753A32A3A36B1556C44A4FA47235BBC94A6157F66111AC684AF93686F6 |
SHA-512: | AA2F46A9CAEAAA056BB2158DE746FB7CB8BDAD32B8A6E4EFC365707E26B345FEB783EDE28572AE84803B59850C9D5FE62C80D839FA2AE23BFF93CCDE5CCBA63C |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 145846 |
Entropy (8bit): | 4.377547460125908 |
Encrypted: | false |
SSDEEP: | 192:0KqKpKpKQKpKKKpKQKpKKKpKQKpKKKpKQKpKKKpKQKpKKKpKQKpKKKpKQKpKKKpU:R |
MD5: | DDF2CF83C9165D957E1A6C009A1622E7 |
SHA1: | C60C896A738818D754349901F4DC696AECFEBC5B |
SHA-256: | C4E8D4D5A67DAE0144F6E20D094040F1092ABCFB08BB3B82841AB6144869290F |
SHA-512: | B3DF89A902D35536D8870C0A537F58E0229D56CAD6B5AD5E346DF1C121852986417D64E8724630B2766A37D4B54C144A8DB76874A3142E4E536DEEF6B02FD0F7 |
Malicious: | false |
Preview: |
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\dosvc.20230404_100257_365.etl
Download File
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 0.23886881445016456 |
Encrypted: | false |
SSDEEP: | 12:8lcn/e0y52xX/7EzPTG6P0+RSQ9aTQ1olfW+08sRT+U+lxOi:8ltOOG6P0+RSHMizgTa1 |
MD5: | 00105566976551A916123998B6452B9C |
SHA1: | 07DB4ECC15BFA5A819A6F8C4A007042D7F5E865D |
SHA-256: | A91311AF275D4250A78C4456E79F12E89A4B59DE5580DE808D6CF77484221D7F |
SHA-512: | 6B5FC5976B96CD174DFF5E6334E74F5D051E195882BE767202D076C75D33B3B376FA25AFB7CE5DBBEC334864356E0B32BEABD28686DB12DB8ED84D8C313C656C |
Malicious: | false |
Preview: |
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat
Download File
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 2.717069168630028 |
Encrypted: | false |
SSDEEP: | 384:olkhwQfsDtzSLzCh+VWuhlRcevcoK+yUNkdkOTRhepBdyjIHnkFNLVqEHH7v+vUN:oOxetzSnCOFvcoOUS+sXj8G2EHb2vG |
MD5: | A9F963CBBC9F928A7C93A350E6AE5AF7 |
SHA1: | 9E31AFF120B9963FB8D81A257ED15DD65BCD69DA |
SHA-256: | 5A194CA38A9E650093E76814C4AA8DF15B8B429F3DB99ECF964442F0ADB74685 |
SHA-512: | F0681DAECA5789645044B194B1FDB2E182D52F88CED4980E372C9EA4255C45E9D3F967379210A7ECDFE106ECB07AB1FE9CD4DD659622245FB31ED459B6839106 |
Malicious: | false |
Preview: |
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\State\dosvcState.dat.LOG1
Download File
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8192 |
Entropy (8bit): | 2.4630421834187177 |
Encrypted: | false |
SSDEEP: | 48:p1LdJzUvCt5kklHdlCNbPTfh7G8zT8M1Yc+KZwNfUPo9+7lBIJyZfMI7yOicw3I:rLdZH0mHCTfrzAMic+KWS4ABLf9XiG |
MD5: | D561BDA5FC74D394D91927229BB813E2 |
SHA1: | 13989E3D78818DD198B75EF3B41FBA2760A304DE |
SHA-256: | 8CF4FA740503F12F1B7A1CA88B914499A5F28803D2C798F82C86209300E5B073 |
SHA-512: | EC10DDC515C5614A1C8FAC248ADA1E0BCAB1BCE755D651C4D8B800E51D36AA5EEEA7C47DE9B298BAEEE3DEC590ABA68B509FEB776205BCEFF5E02EE37B08B51D |
Malicious: | false |
Preview: |
C:\Windows\System32\DriverStore\Temp\{5190aac7-b965-5d4c-a8f2-d012c5c874ce}\AnyDeskPrintDriver-manifest.ini (copy)
Download File
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271 |
Entropy (8bit): | 5.266454556037467 |
Encrypted: | false |
SSDEEP: | 6:/5QXK4VCzXL2ory+eC2rgN+jAJh6piBVAZVhe81W8l2+:Cazb2Yy+eC2xKh64Ke8xN |
MD5: | 0D7876B516B908AAB67A8E01E49C4DED |
SHA1: | 0900C56619CD785DECA4C302972E74D5FACD5EC9 |
SHA-256: | 98933DE1B6C34B4221D2DD065715418C85733C2B8CB4BD12AC71D797B78A1753 |
SHA-512: | 6874F39FFF34F9678E22C47B67F5CD33B825C41F0B0FD84041450A94CC86CC94811293BA838F5267C9CD167D9ABCF74E00A2F3C65E460C67E668429403124546 |
Malicious: | false |
Preview: |
C:\Windows\System32\DriverStore\Temp\{5190aac7-b965-5d4c-a8f2-d012c5c874ce}\AnyDeskPrintDriver.cat (copy)
Download File
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9492 |
Entropy (8bit): | 6.985301072138844 |
Encrypted: | false |
SSDEEP: | 192:/JgfSpJNc5d2WC8Nv7tPDWpHsq7wH0JOqNG8Fp28Wh8nsiq:/X9N8LPDGV75JNNzFwhhiY |
MD5: | 6D1663F0754E05A5B181719F2427D20A |
SHA1: | 5AFFB483E8CA0E73E5B26928A3E47D72DFD1C46E |
SHA-256: | 12AF5F4E8FC448D02BCFD88A302FEBE6820A5A497157EF5DCA2219C50C1621E3 |
SHA-512: | 7895F6E35591270BFA9E373B69B55389D250751B56B7EA0D5B10AB770283B8166182C75DCA4EBBECDD6E9790DBBFDA23130FB4F652545FD39C95619B77195424 |
Malicious: | false |
Preview: |
C:\Windows\System32\DriverStore\Temp\{5190aac7-b965-5d4c-a8f2-d012c5c874ce}\AnyDeskPrintDriver.gpd (copy)
Download File
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12156 |
Entropy (8bit): | 4.438774767382979 |
Encrypted: | false |
SSDEEP: | 192:94I4jNuqQ7QKNbcVHrdxhMXopCIrVjFfJU:MNk/NbcVHrdjMXoPBjFfJU |
MD5: | E0D32D133D4FE83B0E90AA22F16F4203 |
SHA1: | A06B053A1324790DFD0780950D14D8FCEC8A5EB9 |
SHA-256: | 6E996F3523BCF961DE2FF32E5A35BCBB59CB6FE343357EFF930CD4D6FA35F1F4 |
SHA-512: | C0D24104D0B6CB15FF952CBEF66013E96E5ED2D4D3B4A17ABA3E571A1B9F16BD0E5C141E6AABAC5651B4A198DBD9E65571C8C871E737EB5DCF47196C87B8907B |
Malicious: | false |
Preview: |
C:\Windows\System32\DriverStore\Temp\{5190aac7-b965-5d4c-a8f2-d012c5c874ce}\AnyDeskPrintDriverRenderFilter-PipelineConfig.xml (copy)
Download File
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 584 |
Entropy (8bit): | 4.933762469125028 |
Encrypted: | false |
SSDEEP: | 12:4BRL8gVDc8Ez37BDckvLzLkiYd/SUX+EfDUH+CreIByn:4BRLNVDez31DckjfaxnuIDUHV5yn |
MD5: | B76DF597DD3183163A6D19B73D28E6D3 |
SHA1: | 9F7D18A7E09B3818C32C9654FB082A784BE35034 |
SHA-256: | CBA7C721B76BB7245CD0F1FBFDF85073D57512EAD2593050CAD12CE76886AC33 |
SHA-512: | 6F74AD6BBBB931FE78A6545BB6735E63C2C11C025253A7CB0C4605E364A1E3AC806338BB62311D715BF791C5A5610EE02942FF5A0280282D68B93708F1317C69 |
Malicious: | false |
Preview: |
C:\Windows\System32\DriverStore\Temp\{5190aac7-b965-5d4c-a8f2-d012c5c874ce}\AnyDeskPrintDriverRenderFilter.dll (copy)
Download File
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284000 |
Entropy (8bit): | 6.27967812164935 |
Encrypted: | false |
SSDEEP: | 6144:AJuaCAjg/xajfxaH+6a8WbEyLfqOxsgFXoh/A4hEz72:AJTdjgQjf2OCOxJoX |
MD5: | 1E4FAAF4E348BA202DEE66D37EB0B245 |
SHA1: | BB706971BD21F07AF31157875E0521631ECF8FA5 |
SHA-256: | 3AA636E7660BE17F841B7F0E380F93FB94F25C62D9100758B1D480CBB863DB9D |
SHA-512: | 008E59D645B30ADD7D595D69BE48192765DAC606801E418EEB79991E0645833ABEACFC55AA29DAE52DC46AAF22B5C6BC1A9579C2005F4324BECE9954EBB182BA |
Malicious: | false |
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284000 |
Entropy (8bit): | 6.27967812164935 |
Encrypted: | false |
SSDEEP: | 6144:AJuaCAjg/xajfxaH+6a8WbEyLfqOxsgFXoh/A4hEz72:AJTdjgQjf2OCOxJoX |
MD5: | 1E4FAAF4E348BA202DEE66D37EB0B245 |
SHA1: | BB706971BD21F07AF31157875E0521631ECF8FA5 |
SHA-256: | 3AA636E7660BE17F841B7F0E380F93FB94F25C62D9100758B1D480CBB863DB9D |
SHA-512: | 008E59D645B30ADD7D595D69BE48192765DAC606801E418EEB79991E0645833ABEACFC55AA29DAE52DC46AAF22B5C6BC1A9579C2005F4324BECE9954EBB182BA |
Malicious: | false |
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 584 |
Entropy (8bit): | 4.933762469125028 |
Encrypted: | false |
SSDEEP: | 12:4BRL8gVDc8Ez37BDckvLzLkiYd/SUX+EfDUH+CreIByn:4BRLNVDez31DckjfaxnuIDUHV5yn |
MD5: | B76DF597DD3183163A6D19B73D28E6D3 |
SHA1: | 9F7D18A7E09B3818C32C9654FB082A784BE35034 |
SHA-256: | CBA7C721B76BB7245CD0F1FBFDF85073D57512EAD2593050CAD12CE76886AC33 |
SHA-512: | 6F74AD6BBBB931FE78A6545BB6735E63C2C11C025253A7CB0C4605E364A1E3AC806338BB62311D715BF791C5A5610EE02942FF5A0280282D68B93708F1317C69 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271 |
Entropy (8bit): | 5.266454556037467 |
Encrypted: | false |
SSDEEP: | 6:/5QXK4VCzXL2ory+eC2rgN+jAJh6piBVAZVhe81W8l2+:Cazb2Yy+eC2xKh64Ke8xN |
MD5: | 0D7876B516B908AAB67A8E01E49C4DED |
SHA1: | 0900C56619CD785DECA4C302972E74D5FACD5EC9 |
SHA-256: | 98933DE1B6C34B4221D2DD065715418C85733C2B8CB4BD12AC71D797B78A1753 |
SHA-512: | 6874F39FFF34F9678E22C47B67F5CD33B825C41F0B0FD84041450A94CC86CC94811293BA838F5267C9CD167D9ABCF74E00A2F3C65E460C67E668429403124546 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9492 |
Entropy (8bit): | 6.985301072138844 |
Encrypted: | false |
SSDEEP: | 192:/JgfSpJNc5d2WC8Nv7tPDWpHsq7wH0JOqNG8Fp28Wh8nsiq:/X9N8LPDGV75JNNzFwhhiY |
MD5: | 6D1663F0754E05A5B181719F2427D20A |
SHA1: | 5AFFB483E8CA0E73E5B26928A3E47D72DFD1C46E |
SHA-256: | 12AF5F4E8FC448D02BCFD88A302FEBE6820A5A497157EF5DCA2219C50C1621E3 |
SHA-512: | 7895F6E35591270BFA9E373B69B55389D250751B56B7EA0D5B10AB770283B8166182C75DCA4EBBECDD6E9790DBBFDA23130FB4F652545FD39C95619B77195424 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12156 |
Entropy (8bit): | 4.438774767382979 |
Encrypted: | false |
SSDEEP: | 192:94I4jNuqQ7QKNbcVHrdxhMXopCIrVjFfJU:MNk/NbcVHrdjMXoPBjFfJU |
MD5: | E0D32D133D4FE83B0E90AA22F16F4203 |
SHA1: | A06B053A1324790DFD0780950D14D8FCEC8A5EB9 |
SHA-256: | 6E996F3523BCF961DE2FF32E5A35BCBB59CB6FE343357EFF930CD4D6FA35F1F4 |
SHA-512: | C0D24104D0B6CB15FF952CBEF66013E96E5ED2D4D3B4A17ABA3E571A1B9F16BD0E5C141E6AABAC5651B4A198DBD9E65571C8C871E737EB5DCF47196C87B8907B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2202 |
Entropy (8bit): | 3.6217875907609276 |
Encrypted: | false |
SSDEEP: | 12:QgAaZpAPzRprbo370PB2dHl1ElKAO09DK3dQ2xQ2dH12UIQDIPA9YuA9TKAmA9fd:Qi4fbY77sjW3dXbcXTxdqXH6yvMgy |
MD5: | D4CA3F9CEEB46740C6C43826D94ABA18 |
SHA1: | D863CB54AD2FA0CFC0329954CBE49F70F49FDB87 |
SHA-256: | 494E4351B85D2821E53A22434F51A4186AA0F7BE5724922FC96DFB16687AD37C |
SHA-512: | BE08BC144EE2A491FBC80449B4339C01871C6E7D2DDC0E251475D8E426220C6EF35F67698B0586156F0A62B22DB764C43842F577B82C3F9E4E93957F9D617DB4 |
Malicious: | false |
Preview: |
C:\Windows\System32\DriverStore\Temp\{5190aac7-b965-5d4c-a8f2-d012c5c874ce}\anydeskprintdriver.inf (copy)
Download File
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2202 |
Entropy (8bit): | 3.6217875907609276 |
Encrypted: | false |
SSDEEP: | 12:QgAaZpAPzRprbo370PB2dHl1ElKAO09DK3dQ2xQ2dH12UIQDIPA9YuA9TKAmA9fd:Qi4fbY77sjW3dXbcXTxdqXH6yvMgy |
MD5: | D4CA3F9CEEB46740C6C43826D94ABA18 |
SHA1: | D863CB54AD2FA0CFC0329954CBE49F70F49FDB87 |
SHA-256: | 494E4351B85D2821E53A22434F51A4186AA0F7BE5724922FC96DFB16687AD37C |
SHA-512: | BE08BC144EE2A491FBC80449B4339C01871C6E7D2DDC0E251475D8E426220C6EF35F67698B0586156F0A62B22DB764C43842F577B82C3F9E4E93957F9D617DB4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\drvinst.exe |
File Type: | |
Category: | modified |
Size (bytes): | 184079 |
Entropy (8bit): | 5.362039591146746 |
Encrypted: | false |
SSDEEP: | 1536:sYtgOmpyFfzS0w6iAknSdR3TZifGSmQPypV4M+xEfatrdf8atwLWJrDBrCn2S/++:B6zKjv |
MD5: | C915EF8F2EAF78E5A3B99212DFA18C4A |
SHA1: | 8F032AC53C42E182E677A6E6753BC34E86C19B5B |
SHA-256: | 2E0C0F730AEDFA5F204F88AD5979FBBD65E9464D5223DF355A1CF2A43D66BF88 |
SHA-512: | 40803465A80E3A2166E199BF5E9BEE2A2E0F5616B7D47F3F97D4D10034197845678848893D02BD5D29FB438F274878BC93F1F5BF512E97DE828A97F587225A79 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 394240 |
Entropy (8bit): | 6.700175464943679 |
Encrypted: | false |
SSDEEP: | 6144:Tv/ioKdMF+LZD/ZRj1vwWrrUFMNoz4pFGxjEB1NYAOrabN2GZvFcD7:Td+LZrNwWrrwMNoz4vG1OYZabtK7 |
MD5: | 1CE7D5A1566C8C449D0F6772A8C27900 |
SHA1: | 60854185F6338E1BFC7497FD41AA44C5C00D8F85 |
SHA-256: | 73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF |
SHA-512: | 7E3411BE8614170AE91DB1626C452997DC6DB663D79130872A124AF982EE1D457CEFBA00ABD7F5269ADCE3052403BE31238AECC3934C7379D224CB792D519753 |
Malicious: | false |
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\expand.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 843 |
Entropy (8bit): | 4.825234966005002 |
Encrypted: | false |
SSDEEP: | 24:zKcNDbDY2jzD9dD9DDesb9hCDDmD0DYJQl:zKaDvrjHnZaHCQD |
MD5: | 0D9150FC02540ADB6C18DAEC44B158EB |
SHA1: | 0E794B80927124FC7468EF52025C224BDE6FD380 |
SHA-256: | 36D14FACBE0FC3CA7E61E7CD25BED8294EABA2B69F70225CD40002DF7407E88F |
SHA-512: | 1CE2118D7902BAD1DD2D31677FD3A30F75CF30C81053290EED2AA394E3F63030CD4288EB62ECAB2D42163214EBFA49F7A2888A8B170B24DB26174002A37EA75C |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.9990645721025375 |
TrID: |
|
File name: | 92f25a21-b9c1-4aee-af3e-cacf098605e9 |
File size: | 3853384 |
MD5: | 2621b754576047a6e94acbf1dd4fe0ef |
SHA1: | 246f36118c53ac7421518dbc9bb4259128f3c417 |
SHA256: | 109b03ffc45231e5a4c8805a10926492890f7b568f8a93abe1fa495b4bd42975 |
SHA512: | 6b3d58afc82297626bc85d0ea0bd9a16626c34ca3a13bc6cdf3eea396946685641d8659a472ff8c6526e3efbdfd439b05b79965ed195fd1b734a935ffbb00812 |
SSDEEP: | 98304:6W0Ughn1zD8gmJUikb59sFaZw3abaqt8+Uen/xIZ:6WBCn5D8gmJUrvsFaZw3HsJIZ |
TLSH: | B00633004BDCACD4CA530D34CE464060AAF6C9C8D78045AB4D277BBADBEB7B5172AE95 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........h.}.;.}.;.}.;..";.}.;..#;.}.;...;.}.;...;.}.;Rich.}.;........................PE..L... ..b.........."......*...\:............ |
Icon Hash: | 499669d8d82916a8 |
Entrypoint: | 0x401ce9 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x62F0D620 [Mon Aug 8 09:23:44 2022 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: |
Signature Valid: | true |
Signature Issuer: | CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US |
Signature Validation Error: | The operation completed successfully |
Error Number: | 0 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | EAE713DFC05244CF4301BF1C9F68B1BE |
Thumbprint SHA-1: | 9CD1DDB78ED05282353B20CDFE8FA0A4FB6C1ECE |
Thumbprint SHA-256: | 9D7620A4CEBA92370E8828B3CB1007AEFF63AB36A2CBE5F044FDDE14ABAB1EBF |
Serial: | 0DBF152DEAF0B981A8A938D53F769DB8 |
Instruction |
---|
push ebp |
mov ebp, esp |
sub esp, 64h |
push esi |
lea ecx, dword ptr [ebp-64h] |
call 00007FE3CCD4B7F3h |
lea eax, dword ptr [ebp-64h] |
mov ecx, eax |
mov dword ptr [0138E4F8h], eax |
call 00007FE3CCD4B6B1h |
test al, al |
jne 00007FE3CCD4BE14h |
mov esi, 000003E8h |
lea ecx, dword ptr [ebp-64h] |
call 00007FE3CCD4B69Fh |
mov eax, esi |
pop esi |
leave |
ret |
lea eax, dword ptr [ebp-64h] |
push eax |
lea ecx, dword ptr [ebp-30h] |
call 00007FE3CCD4B4D3h |
lea eax, dword ptr [ebp-30h] |
mov ecx, eax |
mov dword ptr [0138E4FCh], eax |
call 00007FE3CCD4B46Bh |
test al, al |
jne 00007FE3CCD4BE11h |
lea ecx, dword ptr [ebp-30h] |
call 00007FE3CCD4B450h |
mov esi, 000003E9h |
jmp 00007FE3CCD4BDC7h |
cmp dword ptr [ebp-10h], 00000000h |
je 00007FE3CCD4BE0Ah |
push 00000800h |
call dword ptr [ebp-10h] |
cmp dword ptr [ebp-0Ch], 00000000h |
je 00007FE3CCD4BE0Ah |
push 00008001h |
call dword ptr [ebp-0Ch] |
lea eax, dword ptr [ebp-64h] |
push eax |
lea esi, dword ptr [ebp-30h] |
call 00007FE3CCD4BD55h |
pop ecx |
mov esi, eax |
push esi |
call dword ptr [ebp-20h] |
lea ecx, dword ptr [ebp-30h] |
call 00007FE3CCD4B412h |
jmp 00007FE3CCD4BD8Eh |
mov edx, dword ptr [esp+04h] |
push ebx |
mov ebx, dword ptr [esp+10h] |
push esi |
xor esi, esi |
test ebx, ebx |
je 00007FE3CCD4BE31h |
push edi |
mov edi, dword ptr [esp+14h] |
sub edi, 0138E500h |
imul edx, edx, 0019660Dh |
add edx, 3C6EF35Fh |
mov eax, edx |
shr eax, 0Ch |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xf8f000 | 0x4850 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x3a8600 | 0x4648 | .itext |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xf94000 | 0x84 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0xbed000 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x2835 | 0x2a00 | False | 0.5951450892857143 | data | 6.499250014872965 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.itext | 0x4000 | 0xbe8a00 | 0x0 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0xbed000 | 0x2fa | 0x400 | False | 0.724609375 | Matlab v4 mat-file (little endian) \234\322\276, numeric, rows 1659950624, columns 0, imaginary | 5.64813417805907 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xbee000 | 0x3a0904 | 0x3a0600 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0xf8f000 | 0x4850 | 0x4a00 | False | 0.5122466216216216 | data | 6.015287517361402 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xf94000 | 0x300 | 0x400 | False | 0.1455078125 | data | 1.181265380704217 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0xf8f280 | 0x1b8e | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States |
RT_ICON | 0xf90e10 | 0x668 | Device independent bitmap graphic, 48 x 96 x 4, image size 0 | English | United States |
RT_ICON | 0xf91478 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | United States |
RT_ICON | 0xf91760 | 0x1e8 | Device independent bitmap graphic, 24 x 48 x 4, image size 0 | English | United States |
RT_ICON | 0xf91948 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | United States |
RT_ICON | 0xf91ac0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | United States |
RT_ICON | 0xf92b68 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | United States |
RT_GROUP_ICON | 0xf91a70 | 0x4c | data | English | United States |
RT_GROUP_ICON | 0xf92fd0 | 0x22 | data | English | United States |
RT_VERSION | 0xf92ff8 | 0x250 | data | English | United States |
RT_MANIFEST | 0xf93248 | 0x606 | XML 1.0 document, ASCII text | English | United States |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 4, 2023 12:02:57.190291882 CEST | 49758 | 443 | 192.168.2.2 | 185.229.191.41 |
Apr 4, 2023 12:02:57.190373898 CEST | 443 | 49758 | 185.229.191.41 | 192.168.2.2 |
Apr 4, 2023 12:02:57.190484047 CEST | 49758 | 443 | 192.168.2.2 | 185.229.191.41 |
Apr 4, 2023 12:02:57.191843987 CEST | 49758 | 443 | 192.168.2.2 | 185.229.191.41 |
Apr 4, 2023 12:02:57.191875935 CEST | 443 | 49758 | 185.229.191.41 | 192.168.2.2 |
Apr 4, 2023 12:02:57.265551090 CEST | 443 | 49758 | 185.229.191.41 | 192.168.2.2 |
Apr 4, 2023 12:02:57.265768051 CEST | 49758 | 443 | 192.168.2.2 | 185.229.191.41 |
Apr 4, 2023 12:02:57.269299030 CEST | 49758 | 443 | 192.168.2.2 | 185.229.191.41 |
Apr 4, 2023 12:02:57.269325018 CEST | 443 | 49758 | 185.229.191.41 | 192.168.2.2 |
Apr 4, 2023 12:02:57.269679070 CEST | 443 | 49758 | 185.229.191.41 | 192.168.2.2 |
Apr 4, 2023 12:02:57.269774914 CEST | 49758 | 443 | 192.168.2.2 | 185.229.191.41 |
Apr 4, 2023 12:02:57.364588976 CEST | 49758 | 443 | 192.168.2.2 | 185.229.191.41 |
Apr 4, 2023 12:02:57.391417980 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.391330957 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.416028023 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.416191101 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.416994095 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.441459894 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.444766998 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.444880962 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.444979906 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.444991112 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.445065022 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.445138931 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.445163965 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.457070112 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.483083963 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.483335972 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.483572006 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.485265017 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.510272026 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.510365963 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.510468960 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.619151115 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.643681049 CEST | 80 | 49759 | 185.229.191.39 | 192.168.2.2 |
Apr 4, 2023 12:02:58.643775940 CEST | 49759 | 80 | 192.168.2.2 | 185.229.191.39 |
Apr 4, 2023 12:02:58.666512966 CEST | 49760 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.666604042 CEST | 443 | 49760 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.666764021 CEST | 49760 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.668556929 CEST | 49760 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.668625116 CEST | 443 | 49760 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.714660883 CEST | 443 | 49760 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.714839935 CEST | 49760 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.715950966 CEST | 49760 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.715974092 CEST | 443 | 49760 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.716567993 CEST | 443 | 49760 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.716748953 CEST | 49760 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.827389002 CEST | 49760 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.857383966 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.877832890 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.878000975 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.878720045 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.898772001 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.901032925 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.901078939 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.901114941 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.901170969 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.913158894 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.934092999 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.934165001 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:58.934293985 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.935614109 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:58.997612000 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.014251947 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.054358959 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.131417036 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.151629925 CEST | 80 | 49761 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.151819944 CEST | 49761 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.183964968 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.204392910 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.204683065 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.205548048 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.225873947 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.227616072 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.227674007 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.227711916 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.227858067 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.269364119 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.273618937 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.295200109 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.295234919 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.295393944 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.297003031 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.357651949 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.636921883 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.677745104 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.716984987 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.716984987 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.718077898 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.737302065 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.737353086 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.738117933 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778388977 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778472900 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778522968 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778563976 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778563023 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.778599024 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778631926 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.778635025 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778671026 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.778707027 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.792890072 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.793050051 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.794722080 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.814958096 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830132008 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830169916 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830204010 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830239058 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830261946 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.830271006 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830305099 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830328941 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.830338955 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830373049 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.830382109 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.830431938 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.835396051 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.836111069 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.844021082 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.844571114 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.865317106 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.865360975 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.867847919 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.888370037 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.889390945 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.909883022 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.910475969 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931083918 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931155920 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931180954 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931200027 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931225061 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931247950 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931272984 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931305885 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931329966 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931353092 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931375980 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931380987 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931397915 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931422949 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931444883 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931456089 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931456089 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931456089 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931463957 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931483984 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931498051 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931504011 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931529999 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931551933 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931554079 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931576014 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.931585073 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.931639910 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.951853037 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.951913118 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.951950073 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.951982975 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952014923 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952035904 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952035904 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952045918 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952084064 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952111006 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952121973 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952156067 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952194929 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952199936 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952228069 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952244997 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952259064 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952289104 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952301979 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952321053 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952353001 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952383041 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952408075 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952414036 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952431917 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952445984 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952476025 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952490091 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952507973 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952539921 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952569962 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952585936 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952604055 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952635050 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952637911 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952666044 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952694893 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952696085 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952728987 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952754974 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952759981 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952790976 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952816963 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952822924 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952853918 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952877045 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952896118 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952939034 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.952944040 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.952970982 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.953000069 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.953013897 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.953030109 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.953061104 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.953074932 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.953090906 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.953121901 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.953134060 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.953155041 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.953207016 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.953773022 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.954591036 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973368883 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973413944 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973432064 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973445892 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973464966 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973484993 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973505020 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973525047 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973543882 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973556042 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973562956 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973582983 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973603010 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973608971 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973623991 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973634958 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973643064 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973658085 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973664045 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973685026 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973689079 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973705053 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973727942 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973737955 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973747969 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973753929 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973768950 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973783970 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973798990 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973805904 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973813057 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973829031 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973848104 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973861933 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973882914 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973898888 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973918915 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973923922 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973937988 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973948956 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973958015 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973977089 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.973979950 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.973995924 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974014044 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974014997 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974035025 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974035978 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974054098 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974066019 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974072933 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974090099 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974092960 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974112034 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974118948 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974132061 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974150896 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974152088 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974169970 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974189043 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974198103 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974210024 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974211931 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974230051 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974248886 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974251032 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974267960 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974273920 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974287987 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974306107 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974308014 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974324942 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974338055 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974344015 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974365950 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974386930 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974396944 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974405050 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974421024 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974425077 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974458933 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974461079 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974478960 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974488974 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974497080 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974515915 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974519014 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974534988 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974555969 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974564075 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974575043 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974591970 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974610090 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974611044 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974628925 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974634886 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974648952 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974668026 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974673033 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974685907 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974704981 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974709034 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974725008 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974742889 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974750996 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974761009 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974778891 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974782944 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974797964 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974824905 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974839926 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974859953 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974878073 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974881887 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974896908 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974915981 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974922895 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.974934101 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974951982 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974967003 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.974972010 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.975013971 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.978921890 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.979444027 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995184898 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995224953 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995244026 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995279074 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995297909 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995316029 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995332956 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995347977 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995353937 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995369911 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995392084 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995412111 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995415926 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995431900 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995440960 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995452881 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995461941 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995475054 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995493889 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995493889 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995513916 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995521069 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995532990 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995542049 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995552063 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995556116 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995572090 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995575905 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995590925 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995592117 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995613098 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995615959 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995629072 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995631933 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995651007 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995661020 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995671034 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995687008 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995690107 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995708942 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995718956 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995728970 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995744944 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995748043 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995768070 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995770931 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995786905 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995800018 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995806932 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995826006 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995841980 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995843887 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995857000 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995872021 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995887041 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995891094 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995903015 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995909929 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995929003 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995929956 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995944977 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995949030 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995965004 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995969057 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.995990038 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.995997906 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996012926 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996017933 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996035099 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996037006 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996054888 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996056080 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996074915 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996074915 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996093988 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996094942 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996109962 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996114969 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996134996 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996135950 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996149063 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996154070 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996166945 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996172905 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996184111 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996192932 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996212959 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996215105 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996232986 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996239901 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996253014 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996254921 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996273041 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996273994 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996288061 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996293068 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996311903 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996311903 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996323109 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996331930 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996341944 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996350050 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996372938 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996391058 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996391058 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996411085 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996417999 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996429920 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996448994 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996448040 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996469975 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996474028 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996489048 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996503115 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996510029 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996517897 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996531010 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996541023 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996551037 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996565104 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996572018 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996592045 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996598005 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996611118 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996618986 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996630907 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996640921 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996650934 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996664047 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996670961 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996674061 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996690989 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996697903 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996711969 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996717930 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996731043 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996736050 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996751070 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996758938 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996771097 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996782064 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996790886 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996793985 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996812105 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996812105 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996830940 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996838093 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996850967 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996854067 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996870995 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996875048 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996890068 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996898890 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996908903 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996927977 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996938944 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996946096 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996965885 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.996969938 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996984959 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.996984959 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997011900 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997019053 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997039080 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997041941 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997059107 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997066021 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997078896 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997080088 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997098923 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997104883 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997117996 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997117996 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997133017 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997139931 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997159004 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997168064 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997178078 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997186899 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997198105 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997215986 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997216940 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997236013 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997243881 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997253895 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997272015 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997275114 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997293949 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997298002 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997313023 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997323036 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997330904 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997339010 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997351885 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997374058 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997380018 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997392893 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997411966 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997417927 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997431993 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997441053 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997451067 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997461081 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997469902 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997488976 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997493029 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997507095 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997509956 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997524023 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997526884 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997546911 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997554064 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997565031 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997575998 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997582912 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997590065 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997603893 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997610092 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997622967 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997623920 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997642994 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997658968 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997661114 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997672081 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997673988 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997688055 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997699976 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997713089 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997725010 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997736931 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997750044 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997767925 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997786045 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997805119 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997805119 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997824907 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997838974 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997844934 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997864008 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997868061 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997883081 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997888088 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997900963 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997901917 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997921944 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997922897 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997936964 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997941017 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997961044 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997961044 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997973919 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.997980118 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.997998953 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998004913 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998018026 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998035908 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998035908 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998055935 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998070955 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998074055 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998092890 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998110056 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998111010 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998131037 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998143911 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998150110 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998171091 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998188019 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998199940 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998207092 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998226881 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998243093 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998244047 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998262882 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998270988 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998282909 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998301029 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:02:59.998317957 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998356104 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:02:59.998668909 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:00.018515110 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018558025 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018588066 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018615961 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018646955 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018678904 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018709898 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018695116 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:00.018739939 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.018804073 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:00.018826008 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:00.074630976 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:00.095201015 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.095264912 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.095413923 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:00.205617905 CEST | 49763 | 80 | 192.168.2.2 | 18.66.97.82 |
Apr 4, 2023 12:03:00.225019932 CEST | 80 | 49763 | 18.66.97.82 | 192.168.2.2 |
Apr 4, 2023 12:03:00.225344896 CEST | 49763 | 80 | 192.168.2.2 | 18.66.97.82 |
Apr 4, 2023 12:03:00.226269960 CEST | 49763 | 80 | 192.168.2.2 | 18.66.97.82 |
Apr 4, 2023 12:03:00.245480061 CEST | 80 | 49763 | 18.66.97.82 | 192.168.2.2 |
Apr 4, 2023 12:03:00.452503920 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:00.493546009 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:00.548162937 CEST | 80 | 49763 | 18.66.97.82 | 192.168.2.2 |
Apr 4, 2023 12:03:00.589484930 CEST | 49763 | 80 | 192.168.2.2 | 18.66.97.82 |
Apr 4, 2023 12:03:01.225788116 CEST | 49763 | 80 | 192.168.2.2 | 18.66.97.82 |
Apr 4, 2023 12:03:01.245214939 CEST | 80 | 49763 | 18.66.97.82 | 192.168.2.2 |
Apr 4, 2023 12:03:01.245394945 CEST | 49763 | 80 | 192.168.2.2 | 18.66.97.82 |
Apr 4, 2023 12:03:10.454332113 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:10.474627018 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:20.477263927 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:20.497791052 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:30.501075029 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:30.521245003 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:40.522898912 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:40.543318033 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:03:50.544821024 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:03:50.565188885 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:00.570669889 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:00.578016996 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:00.578190088 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:00.591149092 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:10.592518091 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:10.612853050 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:17.336421967 CEST | 49765 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:17.336493969 CEST | 443 | 49765 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:17.336604118 CEST | 49765 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.273983002 CEST | 49765 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.274029970 CEST | 443 | 49765 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.327649117 CEST | 443 | 49765 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.327758074 CEST | 49765 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.497647047 CEST | 49765 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.497693062 CEST | 443 | 49765 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.498264074 CEST | 443 | 49765 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.498341084 CEST | 49765 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.687345028 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.707669020 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.885281086 CEST | 49765 | 443 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.916692972 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.937005997 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.937130928 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.937870026 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.958467007 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.961000919 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.961062908 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.961102009 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.961138010 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.973886967 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.995853901 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.995915890 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:20.996045113 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:20.996993065 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:21.058381081 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:21.236733913 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:21.285109997 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:21.301178932 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:21.321434021 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:21.390070915 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:21.390876055 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:21.411205053 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:21.515947104 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:21.684303999 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.059037924 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.079385042 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.098850012 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.100040913 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.149909973 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.151277065 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.171513081 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.174325943 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.194888115 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.199976921 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.220370054 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.221299887 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.241640091 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241677999 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241697073 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241715908 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241734982 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241755009 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241774082 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241786003 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.241794109 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241812944 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241832972 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.241859913 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.241859913 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.241859913 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.242075920 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262149096 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262185097 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262203932 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262223959 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262244940 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262264013 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262281895 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262291908 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262303114 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262320995 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262340069 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262353897 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262353897 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262358904 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262378931 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262388945 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262398005 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262417078 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262454033 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262470007 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262474060 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262492895 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262497902 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262511015 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262527943 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262547970 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.262552023 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262578964 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.262634039 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.263248920 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.282784939 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282821894 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282843113 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282860994 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282881975 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282893896 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.282900095 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282922029 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282936096 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.282939911 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282959938 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282959938 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.282979012 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.282999992 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283021927 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283025980 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283040047 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283049107 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283058882 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283066988 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283077955 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283097029 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283099890 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283116102 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283124924 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283135891 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283155918 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283166885 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283174992 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283194065 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283193111 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283211946 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283214092 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283231020 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283242941 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283248901 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283268929 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283269882 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283288002 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283298016 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283307076 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283324957 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283333063 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283343077 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283354998 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283363104 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283381939 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283392906 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283401966 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283415079 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283420086 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283437967 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283442020 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283456087 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283469915 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283474922 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283493996 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283510923 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283512115 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283524036 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283544064 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.283559084 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283627987 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.283627987 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.284305096 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303747892 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303783894 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303802967 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303823948 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303844929 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303864002 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303862095 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303863049 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303881884 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303899050 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303899050 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303904057 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303922892 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303925991 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303942919 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303946018 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303961992 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303962946 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.303982019 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.303998947 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304001093 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304017067 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304020882 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304040909 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304043055 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304059029 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304059029 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304079056 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304079056 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304096937 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304101944 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304116964 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304119110 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304135084 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304143906 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304152966 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304161072 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304172039 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304183006 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304192066 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304202080 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304210901 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304229975 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304235935 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304250002 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304259062 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304267883 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304280043 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304286957 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304301023 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304306030 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304327011 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304332018 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304332018 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304344893 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304357052 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304363012 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304378033 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304384947 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304400921 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304404020 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304421902 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304439068 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304439068 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304459095 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304462910 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304477930 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304497004 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304501057 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304501057 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304516077 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304533958 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304547071 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304553986 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304567099 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304579020 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304579973 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304579973 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304591894 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304610968 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304630041 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304646015 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304647923 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304646015 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304661989 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304680109 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304680109 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304698944 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304707050 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304718971 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304728985 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304738045 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304759026 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304771900 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304776907 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304790974 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304809093 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304830074 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304847956 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304864883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304867029 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304864883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304864883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304864883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304864883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304884911 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304903030 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304904938 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304924011 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304928064 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304944038 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304960012 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304961920 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304980040 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.304995060 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.304997921 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305016041 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305035114 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305035114 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305053949 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305073023 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305073023 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305092096 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305109024 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305109024 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305128098 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305140018 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305146933 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305166006 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305167913 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305186033 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305200100 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305203915 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305222034 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305241108 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.305255890 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305265903 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305284023 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.305404902 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325445890 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325495005 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325520992 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325546026 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325570107 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325597048 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325615883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325615883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325622082 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325647116 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325666904 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325666904 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325671911 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325687885 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325695992 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325711966 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325722933 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325733900 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325752974 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325762987 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325779915 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325779915 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325807095 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325823069 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325831890 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325841904 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325861931 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325881004 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325887918 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325900078 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325913906 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325926065 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325937986 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325943947 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325963020 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325973988 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.325988054 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.325993061 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326011896 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326028109 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326040983 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326045990 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326066017 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326081038 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326092005 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326098919 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326116085 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326128960 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326141119 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326148033 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326167107 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326174021 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326190948 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326195955 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326215982 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326231003 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326240063 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326276064 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326278925 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326278925 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326301098 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326301098 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326327085 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326334000 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326350927 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326350927 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326375961 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326384068 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326401949 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326404095 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326427937 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326455116 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326455116 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326474905 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326491117 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326498985 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326523066 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326539993 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326546907 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326562881 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326570988 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326589108 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326596022 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326610088 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326620102 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326634884 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326643944 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326653004 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326668978 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326683044 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326694012 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326700926 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326719046 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326725960 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326744080 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326757908 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326773882 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326788902 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326817036 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326821089 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326847076 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326852083 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326870918 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326896906 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326921940 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326925039 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326948881 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326955080 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.326973915 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.326997995 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327023029 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327023029 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327048063 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327050924 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327071905 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327097893 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327119112 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327122927 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327146053 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327156067 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327171087 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327195883 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327195883 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327220917 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327246904 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327269077 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327270985 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327296019 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327301979 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327321053 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327346087 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327370882 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327375889 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327394962 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327397108 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327419996 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327445030 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327469110 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327470064 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327492952 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327497959 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327517986 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327541113 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327541113 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327565908 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327589035 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327614069 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327616930 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327639103 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327646971 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327663898 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327688932 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327713966 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327713966 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327738047 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327742100 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327761889 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327786922 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327811003 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327812910 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327836990 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327848911 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327861071 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327886105 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327888966 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327909946 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327933073 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327955961 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327958107 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.327980995 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.327986002 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328007936 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328032970 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328058004 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328057051 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328083038 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328090906 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328107119 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328130960 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328155041 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328156948 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328180075 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328183889 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328203917 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328228951 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328253031 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328263044 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328277111 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328289986 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328301907 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328325987 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328350067 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328355074 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328375101 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328397989 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328397989 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328423023 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328445911 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328455925 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328469992 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328478098 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328495026 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328517914 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328541994 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328550100 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328566074 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328573942 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328588963 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328614950 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328638077 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328646898 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328661919 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328666925 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328685999 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328708887 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328732967 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328742981 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328757048 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328769922 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328780890 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328805923 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328830004 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328850031 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328850031 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328855038 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328880072 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328903913 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328927994 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328939915 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328952074 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.328958988 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.328975916 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329000950 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329011917 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329025030 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329050064 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329072952 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329073906 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329098940 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329123974 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329133034 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329148054 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329171896 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329180956 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329195976 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329210043 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329220057 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329246044 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329268932 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329272032 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329292059 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329317093 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329325914 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329340935 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329363108 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329365969 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329390049 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329411983 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.329422951 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.329447985 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.331135035 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.388566971 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:23.409837961 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:23.485009909 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:24.356857061 CEST | 49767 | 80 | 192.168.2.2 | 18.66.97.76 |
Apr 4, 2023 12:04:24.376267910 CEST | 80 | 49767 | 18.66.97.76 | 192.168.2.2 |
Apr 4, 2023 12:04:24.376506090 CEST | 49767 | 80 | 192.168.2.2 | 18.66.97.76 |
Apr 4, 2023 12:04:24.376872063 CEST | 49767 | 80 | 192.168.2.2 | 18.66.97.76 |
Apr 4, 2023 12:04:24.396193981 CEST | 80 | 49767 | 18.66.97.76 | 192.168.2.2 |
Apr 4, 2023 12:04:24.699210882 CEST | 80 | 49767 | 18.66.97.76 | 192.168.2.2 |
Apr 4, 2023 12:04:24.886862993 CEST | 49767 | 80 | 192.168.2.2 | 18.66.97.76 |
Apr 4, 2023 12:04:25.319278002 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:25.381963015 CEST | 49767 | 80 | 192.168.2.2 | 18.66.97.76 |
Apr 4, 2023 12:04:25.385734081 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:25.401580095 CEST | 80 | 49767 | 18.66.97.76 | 192.168.2.2 |
Apr 4, 2023 12:04:25.401674032 CEST | 49767 | 80 | 192.168.2.2 | 18.66.97.76 |
Apr 4, 2023 12:04:30.785984993 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:30.786096096 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:30.787208080 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:30.807398081 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:35.393817902 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:35.393925905 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:35.585401058 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:35.605710030 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:40.810178041 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:40.830701113 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:42.842650890 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:42.863183975 CEST | 6568 | 49762 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:42.863302946 CEST | 49762 | 6568 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:45.606287956 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:45.626717091 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:04:55.629388094 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:04:55.649883032 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Apr 4, 2023 12:05:05.652264118 CEST | 49766 | 80 | 192.168.2.2 | 208.115.231.206 |
Apr 4, 2023 12:05:05.672836065 CEST | 80 | 49766 | 208.115.231.206 | 192.168.2.2 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 4, 2023 12:02:57.130357981 CEST | 50130 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:02:57.148536921 CEST | 53 | 50130 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:02:57.370429993 CEST | 56712 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:02:57.388158083 CEST | 53 | 56712 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:02:58.624797106 CEST | 61978 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:02:58.643343925 CEST | 53 | 61978 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:02:58.831864119 CEST | 54981 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:02:58.850370884 CEST | 53 | 54981 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:02:59.136430979 CEST | 63431 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:02:59.155142069 CEST | 53 | 63431 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:03:00.179441929 CEST | 49524 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:03:00.201225996 CEST | 53 | 49524 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:04:17.194188118 CEST | 64488 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:04:17.212552071 CEST | 53 | 64488 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:04:20.894210100 CEST | 56501 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:04:20.912245035 CEST | 53 | 56501 | 1.1.1.1 | 192.168.2.2 |
Apr 4, 2023 12:04:24.329638958 CEST | 60668 | 53 | 192.168.2.2 | 1.1.1.1 |
Apr 4, 2023 12:04:24.351682901 CEST | 53 | 60668 | 1.1.1.1 | 192.168.2.2 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 4, 2023 12:02:57.130357981 CEST | 192.168.2.2 | 1.1.1.1 | 0x16b1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:02:57.370429993 CEST | 192.168.2.2 | 1.1.1.1 | 0xe580 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:02:58.624797106 CEST | 192.168.2.2 | 1.1.1.1 | 0x9cf6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:02:58.831864119 CEST | 192.168.2.2 | 1.1.1.1 | 0xa0ff | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:02:59.136430979 CEST | 192.168.2.2 | 1.1.1.1 | 0xf9fa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:03:00.179441929 CEST | 192.168.2.2 | 1.1.1.1 | 0xc9ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:04:17.194188118 CEST | 192.168.2.2 | 1.1.1.1 | 0x9074 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:04:20.894210100 CEST | 192.168.2.2 | 1.1.1.1 | 0x11b4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 4, 2023 12:04:24.329638958 CEST | 192.168.2.2 | 1.1.1.1 | 0x9892 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 4, 2023 12:02:57.148536921 CEST | 1.1.1.1 | 192.168.2.2 | 0x16b1 | No error (0) | 185.229.191.41 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:02:57.388158083 CEST | 1.1.1.1 | 192.168.2.2 | 0xe580 | No error (0) | 185.229.191.39 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:02:58.643343925 CEST | 1.1.1.1 | 192.168.2.2 | 0x9cf6 | No error (0) | 208.115.231.206 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:02:58.850370884 CEST | 1.1.1.1 | 192.168.2.2 | 0xa0ff | No error (0) | 208.115.231.206 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:02:59.155142069 CEST | 1.1.1.1 | 192.168.2.2 | 0xf9fa | No error (0) | 208.115.231.206 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:03:00.201225996 CEST | 1.1.1.1 | 192.168.2.2 | 0xc9ac | No error (0) | d1atxff5avezsq.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 4, 2023 12:03:00.201225996 CEST | 1.1.1.1 | 192.168.2.2 | 0xc9ac | No error (0) | 18.66.97.18 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:03:00.201225996 CEST | 1.1.1.1 | 192.168.2.2 | 0xc9ac | No error (0) | 18.66.97.76 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:03:00.201225996 CEST | 1.1.1.1 | 192.168.2.2 | 0xc9ac | No error (0) | 18.66.97.48 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:03:00.201225996 CEST | 1.1.1.1 | 192.168.2.2 | 0xc9ac | No error (0) | 18.66.97.82 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:04:17.212552071 CEST | 1.1.1.1 | 192.168.2.2 | 0x9074 | No error (0) | 208.115.231.206 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:04:20.912245035 CEST | 1.1.1.1 | 192.168.2.2 | 0x11b4 | No error (0) | 208.115.231.206 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:04:24.351682901 CEST | 1.1.1.1 | 192.168.2.2 | 0x9892 | No error (0) | d1atxff5avezsq.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 4, 2023 12:04:24.351682901 CEST | 1.1.1.1 | 192.168.2.2 | 0x9892 | No error (0) | 18.66.97.82 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:04:24.351682901 CEST | 1.1.1.1 | 192.168.2.2 | 0x9892 | No error (0) | 18.66.97.18 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:04:24.351682901 CEST | 1.1.1.1 | 192.168.2.2 | 0x9892 | No error (0) | 18.66.97.48 | A (IP address) | IN (0x0001) | false | ||
Apr 4, 2023 12:04:24.351682901 CEST | 1.1.1.1 | 192.168.2.2 | 0x9892 | No error (0) | 18.66.97.76 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.2 | 49759 | 185.229.191.39 | 80 | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Apr 4, 2023 12:02:58.416994095 CEST | 50 | OUT | |
Apr 4, 2023 12:02:58.444766998 CEST | 50 | IN | |
Apr 4, 2023 12:02:58.444880962 CEST | 51 | IN | |
Apr 4, 2023 12:02:58.444991112 CEST | 52 | IN | |
Apr 4, 2023 12:02:58.445065022 CEST | 52 | IN | |
Apr 4, 2023 12:02:58.445163965 CEST | 53 | IN | |
Apr 4, 2023 12:02:58.457070112 CEST | 54 | OUT | |
Apr 4, 2023 12:02:58.483083963 CEST | 54 | IN | |
Apr 4, 2023 12:02:58.483335972 CEST | 54 | IN | |
Apr 4, 2023 12:02:58.485265017 CEST | 54 | OUT | |
Apr 4, 2023 12:02:58.510272026 CEST | 55 | IN | |
Apr 4, 2023 12:02:58.510365963 CEST | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.2 | 49761 | 208.115.231.206 | 80 | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Apr 4, 2023 12:02:58.878720045 CEST | 61 | OUT | |
Apr 4, 2023 12:02:58.901032925 CEST | 62 | IN | |
Apr 4, 2023 12:02:58.901078939 CEST | 63 | IN | |
Apr 4, 2023 12:02:58.901114941 CEST | 63 | IN | |
Apr 4, 2023 12:02:58.913158894 CEST | 65 | OUT | |
Apr 4, 2023 12:02:58.934092999 CEST | 65 | IN | |
Apr 4, 2023 12:02:58.934165001 CEST | 65 | IN | |
Apr 4, 2023 12:02:58.935614109 CEST | 65 | OUT | |
Apr 4, 2023 12:02:59.014251947 CEST | 65 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.2 | 49763 | 18.66.97.82 | 80 | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Apr 4, 2023 12:03:00.226269960 CEST | 491 | OUT | |
Apr 4, 2023 12:03:00.548162937 CEST | 492 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.2 | 49766 | 208.115.231.206 | 80 | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Apr 4, 2023 12:04:20.937870026 CEST | 504 | OUT | |
Apr 4, 2023 12:04:20.961000919 CEST | 505 | IN | |
Apr 4, 2023 12:04:20.961062908 CEST | 507 | IN | |
Apr 4, 2023 12:04:20.961102009 CEST | 507 | IN | |
Apr 4, 2023 12:04:20.973886967 CEST | 508 | OUT | |
Apr 4, 2023 12:04:20.995853901 CEST | 508 | IN | |
Apr 4, 2023 12:04:20.995915890 CEST | 508 | IN | |
Apr 4, 2023 12:04:20.996993065 CEST | 508 | OUT | |
Apr 4, 2023 12:04:21.236733913 CEST | 509 | IN | |
Apr 4, 2023 12:04:21.301178932 CEST | 509 | OUT | |
Apr 4, 2023 12:04:21.390070915 CEST | 509 | IN | |
Apr 4, 2023 12:04:21.390876055 CEST | 509 | OUT | |
Apr 4, 2023 12:04:21.515947104 CEST | 509 | IN | |
Apr 4, 2023 12:04:23.059037924 CEST | 510 | OUT | |
Apr 4, 2023 12:04:23.098850012 CEST | 510 | IN | |
Apr 4, 2023 12:04:23.100040913 CEST | 510 | OUT | |
Apr 4, 2023 12:04:23.149909973 CEST | 510 | IN | |
Apr 4, 2023 12:04:23.151277065 CEST | 510 | OUT | |
Apr 4, 2023 12:04:23.174325943 CEST | 511 | OUT | |
Apr 4, 2023 12:04:23.199976921 CEST | 511 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
4 | 192.168.2.2 | 49767 | 18.66.97.76 | 80 | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Apr 4, 2023 12:04:24.376872063 CEST | 927 | OUT | |
Apr 4, 2023 12:04:24.699210882 CEST | 928 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 12:02:47 |
Start date: | 04/04/2023 |
Path: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6e0000 |
File size: | 3853384 bytes |
MD5 hash: | 2621B754576047A6E94ACBF1DD4FE0EF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 2 |
Start time: | 12:02:51 |
Start date: | 04/04/2023 |
Path: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6e0000 |
File size: | 3853384 bytes |
MD5 hash: | 2621B754576047A6E94ACBF1DD4FE0EF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 3 |
Start time: | 12:02:51 |
Start date: | 04/04/2023 |
Path: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6e0000 |
File size: | 3853384 bytes |
MD5 hash: | 2621B754576047A6E94ACBF1DD4FE0EF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 4 |
Start time: | 12:02:57 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f63c0000 |
File size: | 53744 bytes |
MD5 hash: | 9520A99E77D6196D0D09833146424113 |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Target ID: | 5 |
Start time: | 12:02:57 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f63c0000 |
File size: | 53744 bytes |
MD5 hash: | 9520A99E77D6196D0D09833146424113 |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Target ID: | 6 |
Start time: | 12:02:57 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\SgrmBroker.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6476d0000 |
File size: | 263904 bytes |
MD5 hash: | C51AA0BB954EA45E85572E6CC29BA6F4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Target ID: | 7 |
Start time: | 12:02:57 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f63c0000 |
File size: | 53744 bytes |
MD5 hash: | 9520A99E77D6196D0D09833146424113 |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Target ID: | 8 |
Start time: | 12:04:10 |
Start date: | 04/04/2023 |
Path: | C:\Users\user\Desktop\92f25a21-b9c1-4aee-af3e-cacf098605e9.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6e0000 |
File size: | 3853384 bytes |
MD5 hash: | 2621B754576047A6E94ACBF1DD4FE0EF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Target ID: | 9 |
Start time: | 12:04:13 |
Start date: | 04/04/2023 |
Path: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x580000 |
File size: | 3853384 bytes |
MD5 hash: | 2621B754576047A6E94ACBF1DD4FE0EF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Target ID: | 10 |
Start time: | 12:04:14 |
Start date: | 04/04/2023 |
Path: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x580000 |
File size: | 3853384 bytes |
MD5 hash: | 2621B754576047A6E94ACBF1DD4FE0EF |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Target ID: | 11 |
Start time: | 12:04:15 |
Start date: | 04/04/2023 |
Path: | C:\Windows\SysWOW64\expand.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd60000 |
File size: | 53248 bytes |
MD5 hash: | 8C2235852F8C2659EB6CA4A0C6B3B3F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Target ID: | 12 |
Start time: | 12:04:15 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff69a190000 |
File size: | 885760 bytes |
MD5 hash: | C5E9B1D1103EDCEA2E408E9497A5A88F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Target ID: | 13 |
Start time: | 12:04:17 |
Start date: | 04/04/2023 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x910000 |
File size: | 61952 bytes |
MD5 hash: | D0432468FA4B7F66166C430E1334DBDA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Target ID: | 14 |
Start time: | 12:04:17 |
Start date: | 04/04/2023 |
Path: | C:\Program Files (x86)\AnyDesk\AnyDesk.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x580000 |
File size: | 3853384 bytes |
MD5 hash: | 2621B754576047A6E94ACBF1DD4FE0EF |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Target ID: | 15 |
Start time: | 12:04:22 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f63c0000 |
File size: | 53744 bytes |
MD5 hash: | 9520A99E77D6196D0D09833146424113 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Target ID: | 16 |
Start time: | 12:04:22 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\drvinst.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64ee10000 |
File size: | 173568 bytes |
MD5 hash: | 100997A8B475B1D1B173BE8941DFE1A6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Target ID: | 18 |
Start time: | 12:04:25 |
Start date: | 04/04/2023 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bc550000 |
File size: | 71168 bytes |
MD5 hash: | F68AF942FD7CCC0E7BAB1A2335D2AD26 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Function 0417CF5E Relevance: .9, Instructions: 904COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0417CF5E Relevance: .9, Instructions: 904COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0417DFC9 Relevance: .6, Instructions: 618COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0417DFC9 Relevance: .6, Instructions: 618COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0417DFC9 Relevance: .6, Instructions: 618COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 041580C6 Relevance: .4, Instructions: 370COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |