Windows
Analysis Report
is it legal to kill a peacock in california 93889.js
Overview
General Information
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6664 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\is it legal to kill a pea cock in ca lifornia 9 3889.js" MD5: A47CBE969EA935BDD3AB568BB126BC80)
- wscript.exe (PID: 4724 cmdline:
C:\Windows \system32\ wscript.EX E BALANC~1 .JS MD5: A47CBE969EA935BDD3AB568BB126BC80) - cscript.exe (PID: 6768 cmdline:
"C:\Window s\System32 \cscript.e xe" "BALAN C~1.JS" MD5: 24590BF74BBBBFD7D7AC070F4E3C44FD) - conhost.exe (PID: 6488 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5952 cmdline:
powershell MD5: 04029E121A0CFA5991749937DD22A1D9)
- wscript.exe (PID: 2072 cmdline:
C:\Windows \system32\ wscript.EX E BALANC~1 .JS MD5: A47CBE969EA935BDD3AB568BB126BC80) - cscript.exe (PID: 1888 cmdline:
"C:\Window s\System32 \cscript.e xe" "BALAN C~1.JS" MD5: 24590BF74BBBBFD7D7AC070F4E3C44FD) - conhost.exe (PID: 6020 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5796 cmdline:
powershell MD5: 04029E121A0CFA5991749937DD22A1D9)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GookitLoader | Yara detected GookitLoader | Joe Security | ||
JoeSecurity_GookitLoader | Yara detected GookitLoader | Joe Security | ||
JoeSecurity_GookitLoader | Yara detected GookitLoader | Joe Security | ||
JoeSecurity_GookitLoader | Yara detected GookitLoader | Joe Security |
System Summary |
---|
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: frack113, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Click to jump to signature section
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Software Vulnerabilities |
---|
Source: | Child: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior |
Source: | Process Stats: |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static file information: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Anti Malware Scan Interface: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior | ||
Source: | Window found: | Jump to behavior | ||
Source: | Window found: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 1 Windows Management Instrumentation | 2 Scripting | 11 Process Injection | 1 Masquerading | OS Credential Dumping | 2 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 121 Virtualization/Sandbox Evasion | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | 1 Office Application Startup | 1 DLL Side-Loading | 11 Process Injection | Security Account Manager | 121 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 1 DLL Side-Loading | Login Hook | 1 Obfuscated Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 14 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 12 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ipacrack.com | 188.114.96.3 | true | false | unknown | |
ellinikiaktoploia.net | 104.21.67.130 | true | false | unknown | |
www.shamara.de | 109.237.132.6 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.67.130 | ellinikiaktoploia.net | United States | 13335 | CLOUDFLARENETUS | false | |
109.237.132.6 | www.shamara.de | Germany | 45012 | CLOUDPITDE | false | |
188.114.96.3 | ipacrack.com | European Union | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1500124 |
Start date and time: | 2024-08-27 22:50:03 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 22s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 12 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | is it legal to kill a peacock in california 93889.js |
Detection: | MAL |
Classification: | mal72.troj.expl.evad.winJS@13/9@3/3 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: is it legal to kill a peacock in california 93889.js
Time | Type | Description |
---|---|---|
16:52:05 | API Interceptor | |
22:51:32 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
188.114.96.3 | Get hash | malicious | Lokibot | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Nitol | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Azorult | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Simda Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
CLOUDPITDE | Get hash | malicious | FormBook, PureLog Stealer | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Sality | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | SystemBC | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Blank Grabber, Umbral Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RHADAMANTHYS, XWorm | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 19604 |
Entropy (8bit): | 5.009171660142711 |
Encrypted: | false |
SSDEEP: | 384:Wrib4ZmVoGIpN6KQkj2Fkjh4iUxDhQfdjes+YW+OdBANXp5eYoaYpib47:WLmV3IpNBQkj2Uh4iUxDhEdCs+YW+Od1 |
MD5: | CB7B7AAE0A74AC0D6190B9CFA61C9A20 |
SHA1: | 36B17899ED6FB1CA25DBEAB456003B54AA125FF9 |
SHA-256: | 830DB3443E72BD355AD6EF99987DD20D7793EA406E0F4A78FE2AAE5B9353B122 |
SHA-512: | FC43BE983B3CBB7C3760F526379501A06B90AA1523042DB46F3367A25D335FF7A57FECDFAEAF9CF4BD6BCEBB0306887175286E18EA0F8D1E5DCCEF4BC5365300 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 44131560 |
Entropy (8bit): | 5.660561296891204 |
Encrypted: | false |
SSDEEP: | 3072:vOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtG:X |
MD5: | 04C043B7B5F13C4CF23B63FC7BA1BEA2 |
SHA1: | B846E889513103BEA0CAC649448F0E874453C6E5 |
SHA-256: | 692EFF0C8195A14B5691713E51DB78AF1B1D81C00DD697B960D84B73EC75AA19 |
SHA-512: | 4598F5F9A2CBFE88091B1E34BD2432849AB3E000488E74AA04623876836ECDB39AB6987D07CA23679F82A63778B1AC314FF6DCA26F0FD040422F302A91B9DEB2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 44131560 |
Entropy (8bit): | 5.660561296891204 |
Encrypted: | false |
SSDEEP: | 3072:vOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtOtG:X |
MD5: | 04C043B7B5F13C4CF23B63FC7BA1BEA2 |
SHA1: | B846E889513103BEA0CAC649448F0E874453C6E5 |
SHA-256: | 692EFF0C8195A14B5691713E51DB78AF1B1D81C00DD697B960D84B73EC75AA19 |
SHA-512: | 4598F5F9A2CBFE88091B1E34BD2432849AB3E000488E74AA04623876836ECDB39AB6987D07CA23679F82A63778B1AC314FF6DCA26F0FD040422F302A91B9DEB2 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.596528651735499 |
TrID: | |
File name: | is it legal to kill a peacock in california 93889.js |
File size: | 30'348'243 bytes |
MD5: | 42ffe54cde30c6d3babb008f491597ad |
SHA1: | 7bdbe6b90df3e48cadbd494f0d2ff24fc32b287d |
SHA256: | 5bf0940ddb8bc56d5322f879b64c0565f66a3ed6bf4dbdadc3e5f01236e08e52 |
SHA512: | 71effe8015dbfffb087845974dd2425e1b856dd728a6324fd4b1f9c085d3cb90c435a9cc63da0c479bdf87903d1fd0f1a3afe29a1582445f1682db702b60821c |
SSDEEP: | 49152:57BkzjCxbgqHlp4qhuN08khlGhxz4YzYBmMI+8WQm3L3/uMcGCgD3qug5FgZcE47:q |
TLSH: | 1767A20DAEF71091A923317C8FAF640AB6748017190ADD143D8DA3945FA953867FEFE8 |
File Content Preview: | ./*.* Licensed to the Apache Software Foundation (ASF) under one.* or more contributor license agreements. See the NOTICE file.* distributed with this work for additional information.* regarding copyright ownership. The ASF licenses this file.* to you u |
Icon Hash: | 68d69b8bb6aa9a86 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 27, 2024 22:52:09.552805901 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:09.552865028 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:09.553004026 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:09.559386015 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:09.559431076 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:10.908011913 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:10.908087969 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:10.910036087 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:10.910058022 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:10.910300016 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:10.964732885 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.047399998 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.047442913 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.529377937 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.529827118 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.529834986 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.529860020 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.529931068 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.529962063 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.529978991 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.589821100 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.619856119 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.619864941 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.619962931 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.620188951 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.620704889 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.620711088 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.620743990 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.620773077 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.620815039 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.622210026 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.622216940 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.622282028 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.622294903 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.622692108 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.622747898 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.622756004 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.623420000 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.623470068 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.623478889 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.623547077 CEST | 443 | 49713 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:11.625495911 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:11.627140045 CEST | 49713 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:24.509208918 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:24.509283066 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:24.509392023 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:24.512437105 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:24.512464046 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.169967890 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.170051098 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.171559095 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.171575069 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.171782970 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.179776907 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.179815054 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.528572083 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.529320002 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.529406071 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.529432058 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.574148893 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.621386051 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.621416092 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.621540070 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.621562958 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.622162104 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.622227907 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.622241974 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.623126984 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.623186111 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.623194933 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.623997927 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.624047995 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.624058008 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.667982101 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.713485956 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.713493109 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.713557959 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.713572025 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.713610888 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.714117050 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.714128971 CEST | 443 | 49715 | 109.237.132.6 | 192.168.2.5 |
Aug 27, 2024 22:52:25.714143991 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:25.714171886 CEST | 49715 | 443 | 192.168.2.5 | 109.237.132.6 |
Aug 27, 2024 22:52:32.122667074 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.122704029 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.122771978 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.123261929 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.123274088 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.608465910 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.608578920 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.611356020 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.611366987 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.611861944 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.618410110 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.618479967 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.722779036 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.722882986 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.722922087 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.722964048 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.723053932 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.723066092 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.723386049 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.723433018 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.723438978 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.723581076 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.723619938 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.723628044 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.723633051 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.723674059 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.723952055 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.727680922 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.727770090 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.727776051 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.777283907 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.810926914 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.811007023 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.811065912 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.811077118 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.811158895 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:32.811212063 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:32.811475992 CEST | 49716 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:46.084669113 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:46.084697962 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:46.084775925 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:46.085036039 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:46.085046053 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:46.555624962 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:46.555702925 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:46.557492018 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:46.557497978 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:46.557729006 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:46.558933020 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:46.558958054 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.613795996 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.613836050 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.613861084 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.613888025 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.613917112 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.613943100 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.613957882 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.614166975 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.614192963 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.614217997 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.614217997 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.614227057 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.614275932 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.614751101 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.614797115 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.614873886 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.667897940 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.667905092 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.702364922 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.702395916 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.702445984 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.702452898 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.702524900 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.702899933 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.702950954 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.702974081 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.702996969 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703021049 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.703025103 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703033924 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703061104 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.703068018 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.703069925 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703079939 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703114986 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.703119993 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703828096 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703851938 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703880072 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.703883886 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.703972101 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.704121113 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.704176903 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.704659939 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.704710007 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.704715014 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.704798937 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.704838037 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.704843044 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.704883099 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.705061913 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.705662966 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.705751896 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.705790043 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.705795050 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.707056046 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.790591955 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.790822029 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.790853977 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.790879965 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.790905952 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.790913105 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.790941954 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.791388988 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.791560888 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.791567087 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.791728020 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.791754961 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.791788101 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.791793108 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.791838884 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.792617083 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.792670965 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.792675972 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.793024063 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.793076992 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.793081999 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.793479919 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.793529987 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.793534994 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.794425964 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.794452906 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.794486046 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.794495106 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.794506073 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.795334101 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.795366049 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.795392036 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.795393944 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.795399904 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.795433998 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.795466900 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.796255112 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.796320915 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.796839952 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.796876907 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.796905041 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.796909094 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.796917915 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.796956062 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.879048109 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.879164934 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.879225969 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.879290104 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.879849911 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.879908085 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.880546093 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.880578041 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.880605936 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.880609989 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.880650997 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.881289005 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.881344080 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.881346941 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.881573915 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.882040024 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.882078886 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.882114887 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.882119894 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.882148027 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.882164955 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.882934093 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.882989883 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.883733034 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.883765936 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.883794069 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.883796930 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.883827925 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.884562969 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.884591103 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.884620905 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.884624958 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.884649992 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.885427952 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.885484934 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.885488987 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.885559082 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.886095047 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.886137962 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.886163950 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.886167049 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.886178017 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.886204958 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.886228085 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.887044907 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.887079000 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.887108088 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.887115002 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.887125969 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.888003111 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.888036013 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.888094902 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.888098955 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.888130903 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.888927937 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.888967991 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.888978004 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.888981104 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.889015913 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.889909983 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.889949083 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.889971018 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.889975071 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.889981985 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.889988899 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.890019894 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.890022993 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.890080929 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.967792988 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.967938900 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.969300032 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.969315052 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.969463110 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.969474077 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.969564915 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.970711946 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.970731020 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.970794916 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.970799923 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.972642899 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.972661018 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.972702026 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.972707033 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.972733974 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.972759962 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.974590063 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.974605083 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.974656105 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.974659920 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.974684000 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.974709988 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.975455999 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.975470066 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.975517988 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.975523949 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.975548983 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.975577116 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.977210045 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.977226973 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.977279902 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.977287054 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.977308989 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.977332115 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.978152037 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.978168964 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.978233099 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.978238106 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:47.978274107 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:47.978293896 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.062200069 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.062221050 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.062268019 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.062326908 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.062340975 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.062367916 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.063199043 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.063216925 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.063273907 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.063281059 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.065104008 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.065115929 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.065162897 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.065169096 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.065192938 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.066087961 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.066103935 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.066143036 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.066148043 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.066174030 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.067998886 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.068037033 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.068061113 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.068064928 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.068094015 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.068996906 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.069013119 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.069057941 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.069062948 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.069092035 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.069816113 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.069828033 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.069878101 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.069884062 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.071681976 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.071693897 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.071738958 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.071743965 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.071763992 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.121077061 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.144804955 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.144823074 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.145037889 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.145055056 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.145097971 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.146379948 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.146394968 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.146450996 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.146456957 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.146493912 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.146927118 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.146965981 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.147006035 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.147010088 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.147034883 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.148698092 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.148710012 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.148742914 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.148758888 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.148770094 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.148811102 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.150460958 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.150475025 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.150527000 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.150532961 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.150569916 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.151443005 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.151456118 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.151494980 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.151499987 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.151525021 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.151544094 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.152214050 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.152226925 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.152291059 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.152295113 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.152333021 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.153969049 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.153984070 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.154040098 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.154046059 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.154092073 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.233318090 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.233339071 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.233422041 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.233428001 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.233455896 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.233473063 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.234265089 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.234282970 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.234364033 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.234369040 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.234417915 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.234752893 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.234810114 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.236048937 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.236063004 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.236099958 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.236104965 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.236138105 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.236160994 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.236983061 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.236996889 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.237040997 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.237046003 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.237072945 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.237092018 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.237816095 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.237859011 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:48.237904072 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.245414972 CEST | 49717 | 443 | 192.168.2.5 | 104.21.67.130 |
Aug 27, 2024 22:52:48.245426893 CEST | 443 | 49717 | 104.21.67.130 | 192.168.2.5 |
Aug 27, 2024 22:52:53.150310040 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.150341034 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.150435925 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.150696039 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.150707960 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.821275949 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.823420048 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.823442936 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.938793898 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.938863039 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.938885927 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.938909054 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.938926935 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.938930035 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.938941002 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.938950062 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.938977957 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.939071894 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.939481974 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.939528942 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.939537048 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.943528891 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.943551064 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.943581104 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:53.943586111 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:53.943629980 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:54.028927088 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:54.028985023 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:54.029006004 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:54.029040098 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:54.029061079 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:54.029087067 CEST | 443 | 49718 | 188.114.96.3 | 192.168.2.5 |
Aug 27, 2024 22:52:54.029094934 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:54.029128075 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Aug 27, 2024 22:52:54.029556036 CEST | 49718 | 443 | 192.168.2.5 | 188.114.96.3 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 27, 2024 22:52:09.519843102 CEST | 64469 | 53 | 192.168.2.5 | 1.1.1.1 |
Aug 27, 2024 22:52:09.547665119 CEST | 53 | 64469 | 1.1.1.1 | 192.168.2.5 |
Aug 27, 2024 22:52:31.934988976 CEST | 56469 | 53 | 192.168.2.5 | 1.1.1.1 |
Aug 27, 2024 22:52:32.121295929 CEST | 53 | 56469 | 1.1.1.1 | 192.168.2.5 |
Aug 27, 2024 22:52:46.047743082 CEST | 58008 | 53 | 192.168.2.5 | 1.1.1.1 |
Aug 27, 2024 22:52:46.084126949 CEST | 53 | 58008 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 27, 2024 22:52:09.519843102 CEST | 192.168.2.5 | 1.1.1.1 | 0x913b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 27, 2024 22:52:31.934988976 CEST | 192.168.2.5 | 1.1.1.1 | 0x2fa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 27, 2024 22:52:46.047743082 CEST | 192.168.2.5 | 1.1.1.1 | 0x1a98 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 27, 2024 22:52:09.547665119 CEST | 1.1.1.1 | 192.168.2.5 | 0x913b | No error (0) | 109.237.132.6 | A (IP address) | IN (0x0001) | false | ||
Aug 27, 2024 22:52:32.121295929 CEST | 1.1.1.1 | 192.168.2.5 | 0x2fa | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Aug 27, 2024 22:52:32.121295929 CEST | 1.1.1.1 | 192.168.2.5 | 0x2fa | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Aug 27, 2024 22:52:46.084126949 CEST | 1.1.1.1 | 192.168.2.5 | 0x1a98 | No error (0) | 104.21.67.130 | A (IP address) | IN (0x0001) | false | ||
Aug 27, 2024 22:52:46.084126949 CEST | 1.1.1.1 | 192.168.2.5 | 0x1a98 | No error (0) | 172.67.175.162 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49713 | 109.237.132.6 | 443 | 5952 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-27 20:52:11 UTC | 2153 | OUT | |
2024-08-27 20:52:11 UTC | 602 | IN | |
2024-08-27 20:52:11 UTC | 6 | IN | |
2024-08-27 20:52:11 UTC | 7632 | IN | |
2024-08-27 20:52:11 UTC | 112 | IN | |
2024-08-27 20:52:11 UTC | 8192 | IN | |
2024-08-27 20:52:11 UTC | 8192 | IN | |
2024-08-27 20:52:11 UTC | 8192 | IN | |
2024-08-27 20:52:11 UTC | 4816 | IN | |
2024-08-27 20:52:11 UTC | 5025 | IN | |
2024-08-27 20:52:11 UTC | 2 | IN | |
2024-08-27 20:52:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49715 | 109.237.132.6 | 443 | 5796 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-27 20:52:25 UTC | 2149 | OUT | |
2024-08-27 20:52:25 UTC | 602 | IN | |
2024-08-27 20:52:25 UTC | 6 | IN | |
2024-08-27 20:52:25 UTC | 7632 | IN | |
2024-08-27 20:52:25 UTC | 112 | IN | |
2024-08-27 20:52:25 UTC | 8192 | IN | |
2024-08-27 20:52:25 UTC | 8192 | IN | |
2024-08-27 20:52:25 UTC | 8192 | IN | |
2024-08-27 20:52:25 UTC | 4816 | IN | |
2024-08-27 20:52:25 UTC | 5025 | IN | |
2024-08-27 20:52:25 UTC | 2 | IN | |
2024-08-27 20:52:25 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49716 | 188.114.96.3 | 443 | 5952 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-27 20:52:32 UTC | 2147 | OUT | |
2024-08-27 20:52:32 UTC | 1285 | IN | |
2024-08-27 20:52:32 UTC | 731 | IN | |
2024-08-27 20:52:32 UTC | 722 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN | |
2024-08-27 20:52:32 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49717 | 104.21.67.130 | 443 | 5796 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-27 20:52:46 UTC | 2156 | OUT | |
2024-08-27 20:52:47 UTC | 834 | IN | |
2024-08-27 20:52:47 UTC | 535 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN | |
2024-08-27 20:52:47 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49718 | 188.114.96.3 | 443 | 5952 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-27 20:52:53 UTC | 2147 | OUT | |
2024-08-27 20:52:53 UTC | 1285 | IN | |
2024-08-27 20:52:53 UTC | 741 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN | |
2024-08-27 20:52:53 UTC | 1369 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 16:50:48 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7585d0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 16:51:32 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7585d0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 16:51:48 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\cscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6a3200000 |
File size: | 161'280 bytes |
MD5 hash: | 24590BF74BBBBFD7D7AC070F4E3C44FD |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 6 |
Start time: | 16:51:48 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 7 |
Start time: | 16:51:53 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7585d0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 16:52:03 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 16:52:08 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\cscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6a3200000 |
File size: | 161'280 bytes |
MD5 hash: | 24590BF74BBBBFD7D7AC070F4E3C44FD |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 10 |
Start time: | 16:52:08 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 16:52:21 |
Start date: | 27/08/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |