Windows
Analysis Report
QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
Overview
General Information
Sample name: | QUOTATION_SEPQTRA071244#U00faPDF.scr.exerenamed because original name is a hash value |
Original sample name: | QUOTATION_SEPQTRA071244PDF.scr.exe |
Analysis ID: | 1519261 |
MD5: | 631691dca7abc573a0cc911b2ddca40e |
SHA1: | 0ddc497bb233cda946e320378cde5e5cc507eb72 |
SHA256: | 922ff7b2589cfa1d6a8dcd706bc294be4d4cb4d9baf02df5717d121097ab1859 |
Tags: | exescruser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- QUOTATION_SEPQTRA071244#U00faPDF.scr.exe (PID: 6044 cmdline:
"C:\Users\ user\Deskt op\QUOTATI ON_SEPQTRA 071244#U00 faPDF.scr. exe" MD5: 631691DCA7ABC573A0CC911B2DDCA40E) - aspnet_compiler.exe (PID: 5792 cmdline:
"C:\Window s\Microsof t.NET\Fram ework64\v4 .0.30319\a spnet_comp iler.exe" MD5: DF5419B32657D2896514B6A1D041FE08) - conhost.exe (PID: 3700 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
404 Keylogger, Snake Keylogger | Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram. | No Attribution |
{"Exfil Mode": "SMTP", "Username": "rep3send@aoqiinflatables.com", "Password": "Zg^!Zy[?IKrs99@soltan", "Host": "gator3220.hostgator.com", "Port": "587", "Version": "5.1"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Donutloader_f40e3759 | unknown | unknown |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
Windows_Trojan_SnakeKeylogger_af3faa65 | unknown | unknown |
| |
MAL_Envrial_Jan18_1 | Detects Encrial credential stealer malware | Florian Roth |
| |
Click to see the 18 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
Windows_Trojan_SnakeKeylogger_af3faa65 | unknown | unknown |
| |
MAL_Envrial_Jan18_1 | Detects Encrial credential stealer malware | Florian Roth |
| |
Click to see the 22 entries |
System Summary |
---|
Source: | Author: frack113: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-26T09:23:21.173991+0200 | 2022640 | 1 | A Network Trojan was detected | 188.114.97.3 | 443 | 192.168.2.6 | 49713 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-26T09:23:21.173991+0200 | 2017962 | 1 | A Network Trojan was detected | 188.114.97.3 | 443 | 192.168.2.6 | 49713 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-26T09:24:09.511667+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.6 | 49723 | 188.114.96.3 | 443 | TCP |
2024-09-26T09:24:12.846196+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.6 | 49730 | 188.114.96.3 | 443 | TCP |
2024-09-26T09:24:14.010726+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.6 | 49732 | 188.114.96.3 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-26T09:24:08.120101+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.6 | 49721 | 193.122.130.0 | 80 | TCP |
2024-09-26T09:24:08.916988+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.6 | 49721 | 193.122.130.0 | 80 | TCP |
2024-09-26T09:24:10.088998+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.6 | 49724 | 193.122.130.0 | 80 | TCP |
2024-09-26T09:24:11.182593+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.6 | 49727 | 193.122.130.0 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Location Tracking |
---|
Source: | DNS query: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 5_2_00007FFD348599AC | |
Source: | Code function: | 5_2_00007FFD348584EC | |
Source: | Code function: | 5_2_00007FFD3485A141 | |
Source: | Code function: | 5_2_00007FFD34858A1C | |
Source: | Code function: | 5_2_00007FFD34856E1F | |
Source: | Code function: | 5_2_00007FFD34858946 | |
Source: | Code function: | 5_2_00007FFD34858946 | |
Source: | Code function: | 5_2_00007FFD3485720A | |
Source: | Code function: | 5_2_00007FFD3485720A |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FFD34795DDF | |
Source: | Code function: | 0_2_00007FFD34951540 | |
Source: | Code function: | 0_2_00007FFD349504CA | |
Source: | Code function: | 0_2_00007FFD34958F08 | |
Source: | Code function: | 0_2_00007FFD34954829 | |
Source: | Code function: | 0_2_00007FFD349504F8 | |
Source: | Code function: | 0_2_00007FFD349605D4 | |
Source: | Code function: | 0_2_00007FFD34960415 | |
Source: | Code function: | 5_2_0000022934032F78 | |
Source: | Code function: | 5_2_0000022934032B9C | |
Source: | Code function: | 5_2_0000022934036654 | |
Source: | Code function: | 5_2_0000022934033E5C | |
Source: | Code function: | 5_2_00000229340333A8 | |
Source: | Code function: | 5_2_0000022934031CC0 |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: | ||
Source: | Suspicious method names: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_00007FFD34795CF9 | |
Source: | Code function: | 0_2_00007FFD3479816A | |
Source: | Code function: | 0_2_00007FFD347950F9 | |
Source: | Code function: | 0_2_00007FFD348B2E52 | |
Source: | Code function: | 0_2_00007FFD3495420B | |
Source: | Code function: | 5_2_0000022934010172 | |
Source: | Code function: | 5_2_00007FFD3485816A |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Thread created: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Windows Management Instrumentation | 1 Scheduled Task/Job | 211 Process Injection | 1 Disable or Modify Tools | 1 OS Credential Dumping | 1 Query Registry | Remote Services | 1 Email Collection | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 DLL Side-Loading | 1 Scheduled Task/Job | 41 Virtualization/Sandbox Evasion | LSASS Memory | 111 Security Software Discovery | Remote Desktop Protocol | 11 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 211 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | 1 Data from Local System | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 41 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Software Packing | Cached Domain Credentials | 1 System Network Configuration Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 33 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Win64.Trojan.Mardom | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s24.filetransfer.io | 188.114.97.3 | true | true | unknown | |
filetransfer.io | 188.114.97.3 | true | true | unknown | |
reallyfreegeoip.org | 188.114.96.3 | true | true | unknown | |
checkip.dyndns.com | 193.122.130.0 | true | false | unknown | |
checkip.dyndns.org | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false |
| unknown | |
true |
| unknown | |
true |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
188.114.97.3 | s24.filetransfer.io | European Union | 13335 | CLOUDFLARENETUS | true | |
188.114.96.3 | reallyfreegeoip.org | European Union | 13335 | CLOUDFLARENETUS | true | |
193.122.130.0 | checkip.dyndns.com | United States | 31898 | ORACLE-BMC-31898US | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1519261 |
Start date and time: | 2024-09-26 09:22:23 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | QUOTATION_SEPQTRA071244#U00faPDF.scr.exerenamed because original name is a hash value |
Original Sample Name: | QUOTATION_SEPQTRA071244PDF.scr.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@4/0@4/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: QUOTATION_SEPQTRA071244#U00faPDF.scr.exe
Time | Type | Description |
---|---|---|
03:23:16 | API Interceptor | |
03:24:07 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
188.114.97.3 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
188.114.96.3 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s24.filetransfer.io | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
reallyfreegeoip.org | Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
checkip.dyndns.com | Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
filetransfer.io | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
ORACLE-BMC-31898US | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 2.725066233885776 |
TrID: |
|
File name: | QUOTATION_SEPQTRA071244#U00faPDF.scr.exe |
File size: | 361'472 bytes |
MD5: | 631691dca7abc573a0cc911b2ddca40e |
SHA1: | 0ddc497bb233cda946e320378cde5e5cc507eb72 |
SHA256: | 922ff7b2589cfa1d6a8dcd706bc294be4d4cb4d9baf02df5717d121097ab1859 |
SHA512: | 4a94910b35a95038ba787095970ee32281011021f3cd33066bc8b350c2b1824e1f67a303492fbaae41e9872e75667325e3a4b8d759dce3a79105a00a09782dd9 |
SSDEEP: | 768:BiHqbOcbd5LGOcccCM8AMx9m24IeGFfRhQg2ZzEjss2VSg1I1cn0sspAgpq8hLy8:oHqbbJGwrThRhQ7qPpqOLy0uyL+fS |
TLSH: | 9B743F1976B49132ED04CB7428F29E11C2E7EE5D2BE1921E25C8B66D1B326FD8F035C6 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.........."......f............... ....@...... ....................................`...@......@............... ..... |
Icon Hash: | 0e3333b0bbb3b035 |
Entrypoint: | 0x400000 |
Entrypoint Section: | |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66F3BCB4 [Wed Sep 25 07:33:08 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: |
Instruction |
---|
dec ebp |
pop edx |
nop |
add byte ptr [ebx], al |
add byte ptr [eax], al |
add byte ptr [eax+eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xa000 | 0x51aaa | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2000 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x6494 | 0x6600 | 2d608fbb5362c6929620a3cf71b7e840 | False | 0.45036764705882354 | data | 5.532781563761647 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xa000 | 0x51aaa | 0x51c00 | c3f73acd94c48cdff4272b119e3ddd99 | False | 0.07137268253058104 | data | 2.3514408487511735 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xa370 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | 0.7601351351351351 | ||
RT_ICON | 0xa498 | 0x368 | Device independent bitmap graphic, 16 x 32 x 24, image size 832 | 0.7155963302752294 | ||
RT_ICON | 0xa800 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | 0.6826241134751773 | ||
RT_ICON | 0xac68 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 640 | 0.5389784946236559 | ||
RT_ICON | 0xaf50 | 0xca8 | Device independent bitmap graphic, 32 x 64 x 24, image size 3200 | 0.470679012345679 | ||
RT_ICON | 0xbbf8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | 0.4378517823639775 | ||
RT_ICON | 0xcca0 | 0x668 | Device independent bitmap graphic, 48 x 96 x 4, image size 1536 | 0.36402439024390243 | ||
RT_ICON | 0xd308 | 0x1ca8 | Device independent bitmap graphic, 48 x 96 x 24, image size 7296 | 0.33110687022900764 | ||
RT_ICON | 0xefb0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.30881742738589213 | ||
RT_ICON | 0x11558 | 0xa68 | Device independent bitmap graphic, 64 x 128 x 4, image size 2560 | 0.2924174174174174 | ||
RT_ICON | 0x11fc0 | 0x3228 | Device independent bitmap graphic, 64 x 128 x 24, image size 12800 | 0.26580996884735203 | ||
RT_ICON | 0x151e8 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 0 | 0.24244213509683515 | ||
RT_ICON | 0x19410 | 0x42028 | Device independent bitmap graphic, 256 x 512 x 32, image size 0 | 0.014139568600763382 | ||
RT_GROUP_ICON | 0x5b438 | 0xbc | data | 0.5797872340425532 | ||
RT_VERSION | 0x5b4f4 | 0x3ca | data | 0.4144329896907217 | ||
RT_MANIFEST | 0x5b8c0 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-26T09:23:21.173991+0200 | 2017962 | ET MALWARE PE EXE or DLL Windows file download disguised as ASCII | 1 | 188.114.97.3 | 443 | 192.168.2.6 | 49713 | TCP |
2024-09-26T09:23:21.173991+0200 | 2022640 | ET MALWARE PE EXE or DLL Windows file download Text M2 | 1 | 188.114.97.3 | 443 | 192.168.2.6 | 49713 | TCP |
2024-09-26T09:24:08.120101+0200 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.6 | 49721 | 193.122.130.0 | 80 | TCP |
2024-09-26T09:24:08.916988+0200 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.6 | 49721 | 193.122.130.0 | 80 | TCP |
2024-09-26T09:24:09.511667+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.6 | 49723 | 188.114.96.3 | 443 | TCP |
2024-09-26T09:24:10.088998+0200 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.6 | 49724 | 193.122.130.0 | 80 | TCP |
2024-09-26T09:24:11.182593+0200 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.6 | 49727 | 193.122.130.0 | 80 | TCP |
2024-09-26T09:24:12.846196+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.6 | 49730 | 188.114.96.3 | 443 | TCP |
2024-09-26T09:24:14.010726+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.6 | 49732 | 188.114.96.3 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 26, 2024 09:23:17.136116028 CEST | 49710 | 80 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:17.141160011 CEST | 80 | 49710 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:17.141263962 CEST | 49710 | 80 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:17.143163919 CEST | 49710 | 80 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:17.148108006 CEST | 80 | 49710 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:17.800228119 CEST | 80 | 49710 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:17.812596083 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:17.812648058 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:17.812725067 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:17.854473114 CEST | 49710 | 80 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:17.885476112 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:17.885513067 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:18.359325886 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:18.359457016 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:18.391016960 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:18.391052008 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:18.391554117 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:18.432624102 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:19.048492908 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:19.091403008 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:19.806668043 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:19.806792021 CEST | 443 | 49711 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:19.806848049 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:19.825942993 CEST | 49711 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:19.838089943 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:19.838139057 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:19.838207006 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:19.838618994 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:19.838630915 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:20.336760044 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:20.336935043 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:20.339198112 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:20.339206934 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:20.339565039 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:20.340924978 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:20.387394905 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.079103947 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.079245090 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.079313040 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.079339027 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.079443932 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.079492092 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.079503059 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.079611063 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.079658031 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.079668045 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.080205917 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.080261946 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.080269098 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.083601952 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.083674908 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.083677053 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.083702087 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.083741903 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.171190977 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171288967 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171329021 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171351910 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.171381950 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171436071 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.171444893 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171499014 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171531916 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.171540022 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171586990 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.171622992 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.171627998 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.172277927 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.172310114 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.172323942 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.172329903 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.172363997 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.172386885 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.172451019 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.172493935 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.172498941 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.173167944 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.173203945 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.173213005 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.173227072 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.173261881 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.173268080 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.174021959 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.174060106 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.174067974 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.174084902 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.174119949 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.174124956 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.174144030 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.174180031 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.263642073 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.263746977 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.263787985 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.263797045 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.263819933 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.263854980 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.263855934 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.263865948 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.263906002 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.263915062 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.263994932 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.264703035 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.264750004 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.264760017 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.264771938 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.264811039 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.265161991 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.265217066 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.265284061 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.265336990 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.266063929 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.266124964 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.266189098 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.266237974 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.266310930 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.266360998 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.267080069 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.267115116 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.267144918 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.267157078 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.267173052 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.267884016 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.267935038 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.267946959 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.267987967 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.268007040 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.268054962 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.304238081 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.304364920 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.356247902 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.356367111 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.356383085 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.356400967 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.356446981 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.356494904 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.356537104 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.356591940 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.356632948 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.356969118 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.357023954 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.357063055 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.357110977 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.357187986 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.357234955 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.357484102 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.357537031 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.357677937 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.357728958 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.357852936 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.357902050 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.357942104 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.357991934 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.358459949 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.358510971 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.358562946 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.358612061 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.358764887 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.358815908 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.358846903 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.358896971 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.359442949 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.359523058 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.359605074 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.359653950 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.359736919 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.359787941 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.359814882 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.359863997 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.360394001 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.360446930 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.360548019 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.360599041 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.360861063 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.360913038 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.360955954 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.361002922 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.361232042 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.361284018 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.396846056 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.397016048 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.448419094 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.448530912 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.448559046 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.448575974 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.448589087 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.448616028 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.449002981 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449012041 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449032068 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449059963 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.449067116 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449100018 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.449120998 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.449398041 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449436903 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449441910 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.449450016 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449515104 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.449898005 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.449920893 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.450006008 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.450006008 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.450011015 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.450500965 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.450527906 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.450624943 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.450632095 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.450639963 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.454030991 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.454056025 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.454086065 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.454092979 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.454138041 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.454515934 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.454535007 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.454575062 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.454580069 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.454607010 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.455195904 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.455218077 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.455245018 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.455250025 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.455285072 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.495124102 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.541013956 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.541042089 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.541266918 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.541300058 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.541351080 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.541515112 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.541534901 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.541590929 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.541601896 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.541623116 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.541630983 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.542011023 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.542028904 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.542068005 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.542083025 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.542105913 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.542120934 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.542640924 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.542658091 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.542700052 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.542716026 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.542753935 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.542771101 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.543313026 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.543333054 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.543421030 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.543421984 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.543438911 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.543477058 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.543992043 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544020891 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544050932 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544064999 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544085979 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544101000 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544279099 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544297934 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544323921 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544332981 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544353962 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544372082 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544858932 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544879913 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544917107 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544928074 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.544945955 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.544992924 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.550194025 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.633671045 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.633699894 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.633752108 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.633781910 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.633804083 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.633824110 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.634011030 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.634031057 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.634057045 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.634063959 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.634087086 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.634102106 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.634605885 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.634624004 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.634655952 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.634671926 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.634687901 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.634707928 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.635231018 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.635258913 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.635281086 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.635298014 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.635315895 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.635335922 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.635804892 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.635823965 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.635852098 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.635862112 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.635885000 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.635895967 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.636420012 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.636440039 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.636496067 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.636511087 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.636552095 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.636728048 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.636735916 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.636745930 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.636778116 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.636784077 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.636806011 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.636822939 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.637022972 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.637458086 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.637478113 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.637506008 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.637520075 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.637535095 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.637548923 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.726072073 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.726094961 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.726206064 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.726224899 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.726267099 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.726574898 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.726598024 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.726629972 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.726634979 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.726674080 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.726674080 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.727195024 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.727215052 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.727257967 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.727262974 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.727303982 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.727703094 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.727724075 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.727761030 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.727766037 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.727790117 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.727808952 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.728068113 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.728085995 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.728127003 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.728132010 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.728159904 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.728174925 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.728801966 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.728826046 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.728853941 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.728858948 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.728892088 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.728904963 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.729392052 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.729413033 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.729492903 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.729499102 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.729533911 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.729953051 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.729976892 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.730009079 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.730015039 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.730037928 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.730052948 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.819293976 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.819338083 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.819422007 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.819434881 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.819482088 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820055962 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820076942 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820111036 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820116997 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820128918 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820151091 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820375919 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820400000 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820435047 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820439100 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820465088 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820482969 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820837975 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820858002 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820884943 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820889950 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.820915937 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.820934057 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.821315050 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.821336031 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.821372986 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.821377993 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.821408987 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.821417093 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.821969032 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.821996927 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.822042942 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.822047949 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.822056055 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.822081089 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.822211027 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.822235107 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.822269917 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.822273970 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.822299957 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.822318077 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.822947025 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.822971106 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.822998047 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.823004007 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.823029995 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.823044062 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.833308935 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.911160946 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.911211967 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.911253929 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.911266088 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.911288977 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.911315918 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.911640882 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.911667109 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.911695957 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.911703110 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.911725044 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.911740065 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.912194014 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.912214041 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.912242889 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.912247896 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.912273884 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.912292004 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.912810087 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.912827969 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.912900925 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.912906885 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.912947893 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.913285971 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.913306952 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.913341999 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.913347006 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.913373947 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.913388014 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.913866043 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.913889885 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.913922071 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.913925886 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.913953066 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.913966894 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.914400101 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.914429903 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.914455891 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.914460897 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.914484024 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.914508104 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.915035009 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.915055990 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.915083885 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.915087938 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:21.915115118 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.915133953 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:21.918379068 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.003870010 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.003941059 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004089117 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004117966 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004133940 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004162073 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004369020 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004417896 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004447937 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004456043 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004481077 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004498959 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004806995 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004853964 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004863977 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004880905 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.004890919 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.004920959 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.005393028 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.005435944 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.005448103 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.005455971 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.005481005 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.005497932 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.005899906 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.005955935 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.005970955 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.005978107 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.006004095 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.006019115 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.006753922 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.006795883 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.006818056 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.006825924 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.006846905 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.006864071 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.006964922 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.007003069 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.007015944 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.007026911 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.007054090 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.007070065 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.007266045 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.007675886 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.007721901 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.007740974 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.007746935 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.007775068 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.096195936 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.096235037 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.096343994 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.096359968 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.096400023 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.096739054 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.096769094 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.096800089 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.096805096 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.096833944 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.096847057 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.097349882 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.097373962 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.097404957 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.097409964 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.097455025 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.097455025 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.097857952 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.097879887 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.097908020 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.097912073 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.097939968 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.097958088 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.098484993 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.098520041 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.098541021 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.098546028 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.098572969 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.098588943 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.099097013 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.099123955 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.099153996 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.099159956 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.099185944 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.099205017 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.099674940 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.099706888 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.099740028 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.099745035 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.099771023 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.099786997 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.099956989 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.099986076 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.100013018 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.100018024 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.100055933 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.100055933 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.117187977 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.188822031 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.188863039 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.188981056 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.189001083 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.189042091 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.189225912 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.189245939 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.189275980 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.189280987 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.189308882 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.189327955 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.189858913 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.189878941 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.189918041 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.189923048 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.189950943 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.189968109 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.190392017 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.190409899 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.190452099 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.190458059 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.190489054 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.190974951 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.190992117 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.191023111 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.191028118 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.191076994 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.191447020 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.191473961 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.191493988 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.191493988 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.191499949 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.191524982 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.191555023 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.192003965 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.192023039 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.192053080 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.192056894 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.192085028 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.192085981 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.192604065 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.192625999 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.192655087 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.192660093 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.192681074 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.192714930 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.192714930 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.281529903 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.281569004 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.281663895 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.281697989 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.281718016 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.281744003 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.281975031 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.281991959 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.282036066 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.282042027 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.282073975 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.282090902 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.282583952 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.282601118 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.282660007 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.282668114 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.282708883 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.283155918 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.283173084 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.283217907 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.283224106 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.283252954 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.283265114 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.283876896 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.283900976 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.283947945 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.283955097 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.283984900 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.284001112 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.284216881 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.284235001 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.284286976 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.284293890 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.284338951 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.284888029 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.284908056 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.284950972 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.284956932 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.284984112 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.285006046 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.285289049 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.285311937 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.285357952 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.285363913 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.285393953 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.285403967 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.374162912 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.374195099 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.374290943 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.374305964 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.374352932 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.374589920 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.374607086 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.374651909 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.374658108 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.374691010 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.375158072 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.375174046 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.375211000 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.375216961 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.375241041 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.375257015 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.375439882 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.375457048 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.375492096 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.375497103 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.375520945 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.375536919 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.376216888 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.376231909 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.376271963 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.376276970 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.376300097 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.376321077 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.376537085 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.376552105 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.376589060 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.376595020 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.376617908 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.376631975 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.377310991 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.377329111 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.377362967 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.377379894 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.377392054 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.377420902 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.377892971 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.377907991 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.377947092 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.377953053 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.377974987 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.377995968 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.467554092 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.467578888 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.467668056 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.467684984 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.467726946 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.467853069 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.467868090 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.467899084 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.467905045 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.467931986 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.467951059 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.468215942 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.468230963 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.468283892 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.468290091 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.468322992 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.468579054 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.468590975 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.468656063 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.468662024 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.468698025 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.468945980 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.468964100 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469028950 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.469033957 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469069004 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.469512939 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469538927 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469577074 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.469583988 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469597101 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.469615936 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.469871998 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469887018 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469935894 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.469942093 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.469978094 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.470855951 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.470870972 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.470922947 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.470928907 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.470963955 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.559525013 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.559601068 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.559684992 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.559712887 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.559747934 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.559762955 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.559844017 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.559871912 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.559906960 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.559915066 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.559937000 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.559957981 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.560478926 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.560493946 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.560544014 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.560551882 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.560592890 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.560966969 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.560983896 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561028957 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.561034918 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561059952 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.561079979 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.561602116 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561616898 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561655998 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.561662912 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561686993 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.561706066 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.561917067 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561933041 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561969995 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.561975002 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.561999083 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.562016010 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.562711000 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.562732935 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.562767029 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.562772989 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.562798023 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.562813997 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.563299894 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.563318014 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.563357115 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.563363075 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.563411951 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.563411951 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.652157068 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.652187109 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.652400970 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.652420998 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.652471066 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.652599096 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.652616024 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.652676105 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.652683020 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.652695894 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.652731895 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.653105021 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.653124094 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.653178930 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.653187037 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.653209925 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.653233051 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.653732061 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.653747082 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.653795958 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.653804064 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.653841972 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.654323101 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.654359102 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.654401064 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.654407978 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.654436111 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.654459953 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.654928923 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.654944897 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.654994011 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.654999971 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.655014992 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.655046940 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.655421019 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.655437946 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.655494928 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.655503035 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.655545950 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.656053066 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.656068087 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.656121969 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.656130075 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.656176090 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.744834900 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.744890928 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.744951010 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.744965076 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.744992971 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.745009899 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.745126963 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.745193005 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.745198965 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.745242119 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.745292902 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.6 |
Sep 26, 2024 09:23:22.745342016 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:23:22.746695995 CEST | 49713 | 443 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:24:07.496129990 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:07.501146078 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:07.501265049 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:07.501533985 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:07.506416082 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:07.957529068 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:07.962793112 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:07.967720032 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:08.067563057 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:08.103247881 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.103281975 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.104872942 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.109081030 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.109096050 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.120100975 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:08.583930016 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.584002972 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.586654902 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.586666107 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.587068081 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.635740995 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.644130945 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.691406965 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.753200054 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.753437042 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.754168987 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.768476009 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.774626017 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:08.780647993 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:08.875153065 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:08.880737066 CEST | 49723 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.880779028 CEST | 443 | 49723 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.881016016 CEST | 49723 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.881417036 CEST | 49723 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:08.881432056 CEST | 443 | 49723 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:08.916987896 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:09.344171047 CEST | 443 | 49723 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:09.385863066 CEST | 49723 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:09.403892994 CEST | 49723 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:09.403902054 CEST | 443 | 49723 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:09.511673927 CEST | 443 | 49723 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:09.511768103 CEST | 443 | 49723 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:09.511873960 CEST | 49723 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:09.518909931 CEST | 49723 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:09.557792902 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:09.564141989 CEST | 80 | 49721 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:09.565211058 CEST | 49721 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:09.566318989 CEST | 49724 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:09.571927071 CEST | 80 | 49724 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:09.573236942 CEST | 49724 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:09.574687004 CEST | 49724 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:09.579672098 CEST | 80 | 49724 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:09.821667910 CEST | 49710 | 80 | 192.168.2.6 | 188.114.97.3 |
Sep 26, 2024 09:24:10.036540985 CEST | 80 | 49724 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:10.037786007 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:10.037826061 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:10.037897110 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:10.038280010 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:10.038289070 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:10.088998079 CEST | 49724 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:10.509722948 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:10.511091948 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:10.511127949 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:10.659065008 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:10.659168005 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:10.659219980 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:10.659629107 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:10.662763119 CEST | 49724 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:10.663999081 CEST | 49727 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:10.667995930 CEST | 80 | 49724 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:10.668049097 CEST | 49724 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:10.668833971 CEST | 80 | 49727 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:10.668891907 CEST | 49727 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:10.668996096 CEST | 49727 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:10.673855066 CEST | 80 | 49727 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:11.135719061 CEST | 80 | 49727 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:11.137037992 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:11.137080908 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:11.137168884 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:11.137394905 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:11.137408972 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:11.182593107 CEST | 49727 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:11.597151041 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:11.598499060 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:11.598516941 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:11.746350050 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:11.746464968 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:11.746575117 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:11.747402906 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:11.751709938 CEST | 49729 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:11.756724119 CEST | 80 | 49729 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:11.756825924 CEST | 49729 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:11.756902933 CEST | 49729 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:11.761727095 CEST | 80 | 49729 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:12.240467072 CEST | 80 | 49729 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:12.241681099 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:12.241727114 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:12.241889000 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:12.242167950 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:12.242183924 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:12.291976929 CEST | 49729 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:12.715090036 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:12.719610929 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:12.719635963 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:12.846224070 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:12.846365929 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:12.846457005 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:12.884553909 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:12.926213980 CEST | 49729 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:12.926837921 CEST | 49731 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:12.932277918 CEST | 80 | 49729 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:12.932351112 CEST | 49729 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:12.932535887 CEST | 80 | 49731 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:12.932635069 CEST | 49731 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:12.936882973 CEST | 49731 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:12.941739082 CEST | 80 | 49731 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:13.423831940 CEST | 80 | 49731 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:13.425425053 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:13.425544977 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:13.425653934 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:13.425940990 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:13.425975084 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:13.479664087 CEST | 49731 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:13.879364967 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:13.881109953 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:13.881192923 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:14.010689974 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:14.010798931 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:14.011059999 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:14.011594057 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:14.015115976 CEST | 49731 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:14.016176939 CEST | 49733 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:14.020369053 CEST | 80 | 49731 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:14.020467043 CEST | 49731 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:14.021069050 CEST | 80 | 49733 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:14.021158934 CEST | 49733 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:14.021230936 CEST | 49733 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:14.027554035 CEST | 80 | 49733 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:14.543195963 CEST | 80 | 49733 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:14.544373035 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:14.544430971 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:14.544508934 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:14.544734955 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:14.544748068 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:14.588974953 CEST | 49733 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:15.026631117 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:15.028023005 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:15.028039932 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:15.155863047 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:15.155987978 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:15.156116962 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:15.156790972 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:15.160166979 CEST | 49733 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:15.161300898 CEST | 49735 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:15.165354013 CEST | 80 | 49733 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:15.165443897 CEST | 49733 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:15.166168928 CEST | 80 | 49735 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:15.166237116 CEST | 49735 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:15.166368008 CEST | 49735 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:15.171145916 CEST | 80 | 49735 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:16.007286072 CEST | 80 | 49735 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:24:16.015923977 CEST | 49736 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:16.015968084 CEST | 443 | 49736 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:16.016048908 CEST | 49736 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:16.016288042 CEST | 49736 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:16.016299963 CEST | 443 | 49736 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:16.057693005 CEST | 49735 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:24:16.500582933 CEST | 443 | 49736 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:16.501952887 CEST | 49736 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:16.501982927 CEST | 443 | 49736 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:16.652475119 CEST | 443 | 49736 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:16.652570963 CEST | 443 | 49736 | 188.114.96.3 | 192.168.2.6 |
Sep 26, 2024 09:24:16.652637005 CEST | 49736 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:24:16.653209925 CEST | 49736 | 443 | 192.168.2.6 | 188.114.96.3 |
Sep 26, 2024 09:25:16.135379076 CEST | 80 | 49727 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:25:16.135516882 CEST | 49727 | 80 | 192.168.2.6 | 193.122.130.0 |
Sep 26, 2024 09:25:21.006797075 CEST | 80 | 49735 | 193.122.130.0 | 192.168.2.6 |
Sep 26, 2024 09:25:21.006966114 CEST | 49735 | 80 | 192.168.2.6 | 193.122.130.0 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 26, 2024 09:23:17.120726109 CEST | 53290 | 53 | 192.168.2.6 | 1.1.1.1 |
Sep 26, 2024 09:23:17.129074097 CEST | 53 | 53290 | 1.1.1.1 | 192.168.2.6 |
Sep 26, 2024 09:23:19.827397108 CEST | 50327 | 53 | 192.168.2.6 | 1.1.1.1 |
Sep 26, 2024 09:23:19.837196112 CEST | 53 | 50327 | 1.1.1.1 | 192.168.2.6 |
Sep 26, 2024 09:24:07.483951092 CEST | 55802 | 53 | 192.168.2.6 | 1.1.1.1 |
Sep 26, 2024 09:24:07.490923882 CEST | 53 | 55802 | 1.1.1.1 | 192.168.2.6 |
Sep 26, 2024 09:24:08.092330933 CEST | 61879 | 53 | 192.168.2.6 | 1.1.1.1 |
Sep 26, 2024 09:24:08.101630926 CEST | 53 | 61879 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 26, 2024 09:23:17.120726109 CEST | 192.168.2.6 | 1.1.1.1 | 0x3f79 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 26, 2024 09:23:19.827397108 CEST | 192.168.2.6 | 1.1.1.1 | 0x4b21 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 26, 2024 09:24:07.483951092 CEST | 192.168.2.6 | 1.1.1.1 | 0x6429 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 26, 2024 09:24:08.092330933 CEST | 192.168.2.6 | 1.1.1.1 | 0xdc4b | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 26, 2024 09:23:17.129074097 CEST | 1.1.1.1 | 192.168.2.6 | 0x3f79 | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:23:17.129074097 CEST | 1.1.1.1 | 192.168.2.6 | 0x3f79 | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:23:19.837196112 CEST | 1.1.1.1 | 192.168.2.6 | 0x4b21 | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:23:19.837196112 CEST | 1.1.1.1 | 192.168.2.6 | 0x4b21 | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:07.490923882 CEST | 1.1.1.1 | 192.168.2.6 | 0x6429 | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:07.490923882 CEST | 1.1.1.1 | 192.168.2.6 | 0x6429 | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:07.490923882 CEST | 1.1.1.1 | 192.168.2.6 | 0x6429 | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:07.490923882 CEST | 1.1.1.1 | 192.168.2.6 | 0x6429 | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:07.490923882 CEST | 1.1.1.1 | 192.168.2.6 | 0x6429 | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:07.490923882 CEST | 1.1.1.1 | 192.168.2.6 | 0x6429 | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:08.101630926 CEST | 1.1.1.1 | 192.168.2.6 | 0xdc4b | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 26, 2024 09:24:08.101630926 CEST | 1.1.1.1 | 192.168.2.6 | 0xdc4b | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49710 | 188.114.97.3 | 80 | 6044 | C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:23:17.143163919 CEST | 95 | OUT | |
Sep 26, 2024 09:23:17.800228119 CEST | 865 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49721 | 193.122.130.0 | 80 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:24:07.501533985 CEST | 151 | OUT | |
Sep 26, 2024 09:24:07.957529068 CEST | 320 | IN | |
Sep 26, 2024 09:24:07.962793112 CEST | 127 | OUT | |
Sep 26, 2024 09:24:08.067563057 CEST | 320 | IN | |
Sep 26, 2024 09:24:08.774626017 CEST | 127 | OUT | |
Sep 26, 2024 09:24:08.875153065 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49724 | 193.122.130.0 | 80 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:24:09.574687004 CEST | 127 | OUT | |
Sep 26, 2024 09:24:10.036540985 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49727 | 193.122.130.0 | 80 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:24:10.668996096 CEST | 127 | OUT | |
Sep 26, 2024 09:24:11.135719061 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49729 | 193.122.130.0 | 80 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:24:11.756902933 CEST | 151 | OUT | |
Sep 26, 2024 09:24:12.240467072 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49731 | 193.122.130.0 | 80 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:24:12.936882973 CEST | 151 | OUT | |
Sep 26, 2024 09:24:13.423831940 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49733 | 193.122.130.0 | 80 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:24:14.021230936 CEST | 151 | OUT | |
Sep 26, 2024 09:24:14.543195963 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49735 | 193.122.130.0 | 80 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 26, 2024 09:24:15.166368008 CEST | 151 | OUT | |
Sep 26, 2024 09:24:16.007286072 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49711 | 188.114.97.3 | 443 | 6044 | C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:23:19 UTC | 95 | OUT | |
2024-09-26 07:23:19 UTC | 1074 | IN | |
2024-09-26 07:23:19 UTC | 134 | IN | |
2024-09-26 07:23:19 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49713 | 188.114.97.3 | 443 | 6044 | C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:23:20 UTC | 98 | OUT | |
2024-09-26 07:23:21 UTC | 1026 | IN | |
2024-09-26 07:23:21 UTC | 343 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN | |
2024-09-26 07:23:21 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49722 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:08 UTC | 84 | OUT | |
2024-09-26 07:24:08 UTC | 704 | IN | |
2024-09-26 07:24:08 UTC | 340 | IN | |
2024-09-26 07:24:08 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49723 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:09 UTC | 60 | OUT | |
2024-09-26 07:24:09 UTC | 680 | IN | |
2024-09-26 07:24:09 UTC | 340 | IN | |
2024-09-26 07:24:09 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49725 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:10 UTC | 84 | OUT | |
2024-09-26 07:24:10 UTC | 672 | IN | |
2024-09-26 07:24:10 UTC | 340 | IN | |
2024-09-26 07:24:10 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49728 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:11 UTC | 84 | OUT | |
2024-09-26 07:24:11 UTC | 680 | IN | |
2024-09-26 07:24:11 UTC | 340 | IN | |
2024-09-26 07:24:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49730 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:12 UTC | 60 | OUT | |
2024-09-26 07:24:12 UTC | 678 | IN | |
2024-09-26 07:24:12 UTC | 340 | IN | |
2024-09-26 07:24:12 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49732 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:13 UTC | 60 | OUT | |
2024-09-26 07:24:14 UTC | 680 | IN | |
2024-09-26 07:24:14 UTC | 340 | IN | |
2024-09-26 07:24:14 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.6 | 49734 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:15 UTC | 84 | OUT | |
2024-09-26 07:24:15 UTC | 672 | IN | |
2024-09-26 07:24:15 UTC | 340 | IN | |
2024-09-26 07:24:15 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.6 | 49736 | 188.114.96.3 | 443 | 5792 | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-26 07:24:16 UTC | 84 | OUT | |
2024-09-26 07:24:16 UTC | 690 | IN | |
2024-09-26 07:24:16 UTC | 340 | IN | |
2024-09-26 07:24:16 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 03:23:15 |
Start date: | 26/09/2024 |
Path: | C:\Users\user\Desktop\QUOTATION_SEPQTRA071244#U00faPDF.scr.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x28acc6c0000 |
File size: | 361'472 bytes |
MD5 hash: | 631691DCA7ABC573A0CC911B2DDCA40E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 03:24:06 |
Start date: | 26/09/2024 |
Path: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x22933f90000 |
File size: | 55'824 bytes |
MD5 hash: | DF5419B32657D2896514B6A1D041FE08 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | moderate |
Has exited: | false |
Target ID: | 6 |
Start time: | 03:24:06 |
Start date: | 26/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Execution Graph
Execution Coverage: | 5.1% |
Dynamic/Decrypted Code Coverage: | 33.3% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34958F08 Relevance: .7, Instructions: 707COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34954829 Relevance: .6, Instructions: 557COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348B200D Relevance: .6, Instructions: 565COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348B1CD3 Relevance: .3, Instructions: 306COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34791E1F Relevance: .3, Instructions: 296COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347937FA Relevance: .3, Instructions: 294COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347947F2 Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347939FA Relevance: .1, Instructions: 144COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347908A1 Relevance: .1, Instructions: 136COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347942D0 Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34791FE2 Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34791FD7 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34794800 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34797D1D Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34793C5D Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34790ACD Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34793ED3 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34790A52 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34797CCD Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34793EE0 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3479B044 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3479E92C Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347984D3 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34797D10 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347940CD Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD347940F0 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34793FE8 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34793F30 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34790890 Relevance: .0, Instructions: 7COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 26.3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 88 |
Total number of Limit Nodes: | 5 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00007FFD3485720A Relevance: 1.2, Instructions: 1165COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34858946 Relevance: 1.1, Instructions: 1114COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348599AC Relevance: .7, Instructions: 658COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34858A1C Relevance: .5, Instructions: 471COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34856E1F Relevance: .2, Instructions: 243COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485A141 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00000229340343B4 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 104libraryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34850862 Relevance: .9, Instructions: 875COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485EA75 Relevance: .5, Instructions: 496COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855631 Relevance: .4, Instructions: 376COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348581F3 Relevance: .4, Instructions: 373COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34854CCF Relevance: .3, Instructions: 342COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348530C8 Relevance: .3, Instructions: 331COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485293D Relevance: .3, Instructions: 306COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34851E72 Relevance: .3, Instructions: 305COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855A09 Relevance: .3, Instructions: 303COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855228 Relevance: .3, Instructions: 252COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34851E90 Relevance: .2, Instructions: 250COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855230 Relevance: .2, Instructions: 239COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855250 Relevance: .2, Instructions: 233COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34850598 Relevance: .2, Instructions: 224COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485A9E5 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855298 Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485EEBA Relevance: .2, Instructions: 186COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855210 Relevance: .2, Instructions: 176COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348552C8 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855D79 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485EE66 Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34850738 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34850740 Relevance: .1, Instructions: 108COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34855C98 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34850748 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34856749 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485ABA4 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34856227 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485AB85 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485AB91 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485AB9B Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3485D4FE Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348551FA Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348530DB Relevance: .0, Instructions: 4COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348584EC Relevance: .4, Instructions: 396COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|