Windows
Analysis Report
k8JAXb3Lhs.exe
Overview
General Information
Sample name: | k8JAXb3Lhs.exerenamed because original name is a hash value |
Original sample name: | eead7a529f768cd0a74a639ff806357c.exe |
Analysis ID: | 1523398 |
MD5: | eead7a529f768cd0a74a639ff806357c |
SHA1: | 5fea9c1f649f81dfca7f19af1cabc8aab2b01829 |
SHA256: | 2c84b412d0ab9a058d88e5b34e0921c06da1ba11703ef71c124050406dad1844 |
Tags: | exeStealcuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- k8JAXb3Lhs.exe (PID: 6644 cmdline:
"C:\Users\ user\Deskt op\k8JAXb3 Lhs.exe" MD5: EEAD7A529F768CD0A74A639FF806357C) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- sfjujsr (PID: 2128 cmdline:
C:\Users\u ser\AppDat a\Roaming\ sfjujsr MD5: EEAD7A529F768CD0A74A639FF806357C)
- sfjujsr (PID: 3452 cmdline:
C:\Users\u ser\AppDat a\Roaming\ sfjujsr MD5: EEAD7A529F768CD0A74A639FF806357C)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://nwgrus.ru/tmp/index.php", "http://tech-servers.in.net/tmp/index.php", "http://unicea.ws/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-01T15:17:23.620395+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49736 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:24.752008+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49737 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:25.914811+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49738 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:27.029533+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49739 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:28.206437+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49740 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:29.341890+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:30.500449+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49742 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:31.641582+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49743 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:33.261390+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49744 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:34.418617+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49745 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:35.545596+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:36.688527+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49747 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:37.858454+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49748 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:38.979866+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49749 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:40.096823+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49750 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:41.358376+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:42.684467+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:43.812303+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49753 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:45.121736+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49754 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:46.345239+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49755 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:47.480934+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49756 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:48.777574+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49757 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:49.901493+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49758 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:50.981956+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49759 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:52.350953+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49760 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:53.596376+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49761 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:18:59.724566+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49763 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:06.035186+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49764 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:11.806618+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49765 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:18.036708+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49766 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:23.665761+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49767 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:30.039822+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49768 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:35.601803+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49769 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:42.320909+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49770 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:47.791066+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49771 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:56.389866+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49772 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:02.025493+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49773 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:07.324998+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49774 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:13.530972+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49775 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:19.524009+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49776 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:25.648095+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49777 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:31.521429+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49778 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:36.199335+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49779 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:41.110917+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49780 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:47.770977+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49781 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:54.025223+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49782 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:59.510649+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49783 | 187.131.253.169 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_00403277 | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 4_2_00401514 | |
Source: | Code function: | 4_2_00402F97 | |
Source: | Code function: | 4_2_00401542 | |
Source: | Code function: | 4_2_00403247 | |
Source: | Code function: | 4_2_00401549 | |
Source: | Code function: | 4_2_0040324F | |
Source: | Code function: | 4_2_00403256 | |
Source: | Code function: | 4_2_00401557 | |
Source: | Code function: | 4_2_0040326C | |
Source: | Code function: | 4_2_00403277 | |
Source: | Code function: | 4_2_004014FE | |
Source: | Code function: | 4_2_00403290 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_0286F737 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_025F1550 | |
Source: | Code function: | 0_2_02873192 | |
Source: | Code function: | 0_2_0287156A | |
Source: | Code function: | 0_2_02872031 | |
Source: | Code function: | 4_2_004014E9 | |
Source: | Code function: | 4_2_004032AB | |
Source: | Code function: | 4_2_02711550 | |
Source: | Code function: | 4_2_02752B32 | |
Source: | Code function: | 4_2_027519D1 | |
Source: | Code function: | 4_2_02750F0A |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_025F092B | |
Source: | Code function: | 0_2_025F0D90 | |
Source: | Code function: | 0_2_0286F014 | |
Source: | Code function: | 4_2_0271092B | |
Source: | Code function: | 4_2_02710D90 | |
Source: | Code function: | 4_2_0274E9B4 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 7_2_00406F4A |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | Data from Local System | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 411 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 12 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 113 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 13 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1310247 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1310247 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
nwgrus.ru | 78.89.199.216 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
187.131.253.169 | unknown | Mexico | 8151 | UninetSAdeCVMX | true | |
78.89.199.216 | nwgrus.ru | Kuwait | 29357 | WATANIYATELECOM-ASKW | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1523398 |
Start date and time: | 2024-10-01 15:16:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | k8JAXb3Lhs.exerenamed because original name is a hash value |
Original Sample Name: | eead7a529f768cd0a74a639ff806357c.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@3/2@6/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 20.190.159.68, 20.190.159.0, 40.126.31.69, 20.190.159.64, 40.126.31.67, 20.190.159.71, 20.190.159.23, 40.126.31.73
- Excluded domains from analysis (whitelisted): prdv4a.aadg.msidentity.com, ocsp.digicert.com, slscr.update.microsoft.com, login.live.com, www.tm.v4.a.prd.aadg.akadns.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, www.tm.lg.prod.aadmsa.trafficmanager.net
- Execution Graph export aborted for target sfjujsr, PID 3452 because there are no executed function
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: k8JAXb3Lhs.exe
Time | Type | Description |
---|---|---|
09:17:19 | API Interceptor | |
14:17:20 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
78.89.199.216 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, AsyncRAT, Go Injector, LummaC Stealer, SmokeLoader, VenomRAT | Browse |
| ||
Get hash | malicious | Djvu | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | LummaC, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Mars Stealer, PureLog Stealer, RedLine, SmokeLoader, Stealc | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
nwgrus.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UninetSAdeCVMX | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Phorpiex | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
WATANIYATELECOM-ASKW | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, AsyncRAT, Go Injector, LummaC Stealer, SmokeLoader, VenomRAT | Browse |
| ||
Get hash | malicious | Djvu | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, SmokeLoader | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 369664 |
Entropy (8bit): | 6.992143639446749 |
Encrypted: | false |
SSDEEP: | 6144:o1JYtwjCacpD0fbtNorAJoKURDOT42P12YO5LqxuGG8eskEGtwc:Ui2jCacpofbtNRJoSHbkGVGtw |
MD5: | EEAD7A529F768CD0A74A639FF806357C |
SHA1: | 5FEA9C1F649F81DFCA7F19AF1CABC8AAB2B01829 |
SHA-256: | 2C84B412D0AB9A058D88E5B34E0921C06DA1BA11703EF71C124050406DAD1844 |
SHA-512: | DD28FB4DCBBA20B72E7FB36C2D947A99A8DFFE76D52460D52143992AA98BF0C7EE41CFA9E59FB7D0A7CA3C598B0924254E9764168F5F8031F3BB920F60D562E5 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 6.992143639446749 |
TrID: |
|
File name: | k8JAXb3Lhs.exe |
File size: | 369'664 bytes |
MD5: | eead7a529f768cd0a74a639ff806357c |
SHA1: | 5fea9c1f649f81dfca7f19af1cabc8aab2b01829 |
SHA256: | 2c84b412d0ab9a058d88e5b34e0921c06da1ba11703ef71c124050406dad1844 |
SHA512: | dd28fb4dcbba20b72e7fb36c2d947a99a8dffe76d52460d52143992aa98bf0c7ee41cfa9e59fb7d0a7ca3c598b0924254e9764168f5f8031f3bb920f60d562e5 |
SSDEEP: | 6144:o1JYtwjCacpD0fbtNorAJoKURDOT42P12YO5LqxuGG8eskEGtwc:Ui2jCacpofbtNRJoSHbkGVGtw |
TLSH: | 32748E0353F13C56EB264A32CE2EC6E8761EF561AE1B377A32186A1F14F09B1C663715 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Z"TQ;L.Q;L.Q;L.>M..p;L.>M..w;L.>M..2;L.XC..V;L.Q;M..;L.>M..P;L.>M..P;L.>M..P;L.RichQ;L.................PE..L.....3d........... |
Icon Hash: | 512545415559510d |
Entrypoint: | 0x403749 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6433F7E2 [Mon Apr 10 11:49:54 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | ff383ac4deafd0aa2c692d1185588d4b |
Instruction |
---|
call 00007F32B0836241h |
jmp 00007F32B08328CEh |
push dword ptr [00444FFCh] |
call dword ptr [0040E118h] |
test eax, eax |
je 00007F32B0832A44h |
call eax |
push 00000019h |
call 00007F32B08358DEh |
push 00000001h |
push 00000000h |
call 00007F32B08335DCh |
add esp, 0Ch |
jmp 00007F32B08335A1h |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 20h |
mov eax, dword ptr [ebp+08h] |
push esi |
push edi |
push 00000008h |
pop ecx |
mov esi, 0040E3D8h |
lea edi, dword ptr [ebp-20h] |
rep movsd |
mov dword ptr [ebp-08h], eax |
mov eax, dword ptr [ebp+0Ch] |
pop edi |
mov dword ptr [ebp-04h], eax |
pop esi |
test eax, eax |
je 00007F32B0832A4Eh |
test byte ptr [eax], 00000008h |
je 00007F32B0832A49h |
mov dword ptr [ebp-0Ch], 01994000h |
lea eax, dword ptr [ebp-0Ch] |
push eax |
push dword ptr [ebp-10h] |
push dword ptr [ebp-1Ch] |
push dword ptr [ebp-20h] |
call dword ptr [0040E148h] |
leave |
retn 0008h |
mov edi, edi |
push ebp |
mov ebp, esp |
push ecx |
push ebx |
mov eax, dword ptr [ebp+0Ch] |
add eax, 0Ch |
mov dword ptr [ebp-04h], eax |
mov ebx, dword ptr fs:[00000000h] |
mov eax, dword ptr [ebx] |
mov dword ptr fs:[00000000h], eax |
mov eax, dword ptr [ebp+08h] |
mov ebx, dword ptr [ebp+0Ch] |
mov ebp, dword ptr [ebp-04h] |
mov esp, dword ptr [ebx-04h] |
jmp eax |
pop ebx |
leave |
retn 0008h |
pop eax |
pop ecx |
xchg dword ptr [esp], eax |
jmp eax |
pop eax |
pop ecx |
xchg dword ptr [esp], eax |
jmp eax |
pop eax |
pop ecx |
xchg dword ptr [esp], eax |
jmp eax |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3e4f0 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x205a000 | 0x164a0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x3e540 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x3dbc0 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0xe000 | 0x1d0 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0xcbc4 | 0xcc00 | 94972da1bb4ddcc10d81f17166d186cd | False | 0.6090303308823529 | data | 6.759932634611489 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0xe000 | 0x30f8e | 0x31000 | a7160c40f4b2a83dcb49729dcb3251fe | False | 0.9356365593112245 | data | 7.862669112386082 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x3f000 | 0x201a268 | 0x5e00 | b93d1710981d59197efeabe69c67207d | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x205a000 | 0x164a0 | 0x16600 | b1ce196108c965bda8576c5bc2bb9aa3 | False | 0.38988303072625696 | data | 4.436973677856284 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0x206c988 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.4375 | ||
RT_CURSOR | 0x206cab8 | 0xb0 | Device independent bitmap graphic, 16 x 32 x 1, image size 0 | 0.44886363636363635 | ||
RT_CURSOR | 0x206cb90 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.27238805970149255 | ||
RT_CURSOR | 0x206da38 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | 0.375 | ||
RT_CURSOR | 0x206e2e0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | 0.5057803468208093 | ||
RT_ICON | 0x205a7e0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | India | 0.3686034115138593 |
RT_ICON | 0x205a7e0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | Sri Lanka | 0.3686034115138593 |
RT_ICON | 0x205b688 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | India | 0.45577617328519854 |
RT_ICON | 0x205b688 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | Sri Lanka | 0.45577617328519854 |
RT_ICON | 0x205bf30 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | India | 0.45622119815668205 |
RT_ICON | 0x205bf30 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | Sri Lanka | 0.45622119815668205 |
RT_ICON | 0x205c5f8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.45809248554913296 |
RT_ICON | 0x205c5f8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.45809248554913296 |
RT_ICON | 0x205cb60 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.2676348547717842 |
RT_ICON | 0x205cb60 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.2676348547717842 |
RT_ICON | 0x205f108 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.30605065666041276 |
RT_ICON | 0x205f108 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.30605065666041276 |
RT_ICON | 0x20601b0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.350177304964539 |
RT_ICON | 0x20601b0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.350177304964539 |
RT_ICON | 0x2060680 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | India | 0.56636460554371 |
RT_ICON | 0x2060680 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | Sri Lanka | 0.56636460554371 |
RT_ICON | 0x2061528 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | India | 0.5437725631768953 |
RT_ICON | 0x2061528 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | Sri Lanka | 0.5437725631768953 |
RT_ICON | 0x2061dd0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.6141618497109826 |
RT_ICON | 0x2061dd0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.6141618497109826 |
RT_ICON | 0x2062338 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.46307053941908716 |
RT_ICON | 0x2062338 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.46307053941908716 |
RT_ICON | 0x20648e0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.4871013133208255 |
RT_ICON | 0x20648e0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.4871013133208255 |
RT_ICON | 0x2065988 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | India | 0.4954918032786885 |
RT_ICON | 0x2065988 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | Sri Lanka | 0.4954918032786885 |
RT_ICON | 0x2066310 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.450354609929078 |
RT_ICON | 0x2066310 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.450354609929078 |
RT_ICON | 0x20667e0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | India | 0.4914712153518124 |
RT_ICON | 0x20667e0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | Sri Lanka | 0.4914712153518124 |
RT_ICON | 0x2067688 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | India | 0.46705776173285196 |
RT_ICON | 0x2067688 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | Sri Lanka | 0.46705776173285196 |
RT_ICON | 0x2067f30 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.4320809248554913 |
RT_ICON | 0x2067f30 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.4320809248554913 |
RT_ICON | 0x2068498 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.27593360995850624 |
RT_ICON | 0x2068498 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.27593360995850624 |
RT_ICON | 0x206aa40 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.28775797373358347 |
RT_ICON | 0x206aa40 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.28775797373358347 |
RT_ICON | 0x206bae8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | India | 0.30450819672131146 |
RT_ICON | 0x206bae8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | Sri Lanka | 0.30450819672131146 |
RT_ICON | 0x206c470 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.32890070921985815 |
RT_ICON | 0x206c470 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.32890070921985815 |
RT_STRING | 0x206ead8 | 0x796 | data | Tamil | India | 0.4129763130792997 |
RT_STRING | 0x206ead8 | 0x796 | data | Tamil | Sri Lanka | 0.4129763130792997 |
RT_STRING | 0x206f270 | 0x550 | data | Tamil | India | 0.44485294117647056 |
RT_STRING | 0x206f270 | 0x550 | data | Tamil | Sri Lanka | 0.44485294117647056 |
RT_STRING | 0x206f7c0 | 0x328 | data | Tamil | India | 0.4628712871287129 |
RT_STRING | 0x206f7c0 | 0x328 | data | Tamil | Sri Lanka | 0.4628712871287129 |
RT_STRING | 0x206fae8 | 0x6a0 | data | Tamil | India | 0.4257075471698113 |
RT_STRING | 0x206fae8 | 0x6a0 | data | Tamil | Sri Lanka | 0.4257075471698113 |
RT_STRING | 0x2070188 | 0x312 | data | Tamil | India | 0.4631043256997455 |
RT_STRING | 0x2070188 | 0x312 | data | Tamil | Sri Lanka | 0.4631043256997455 |
RT_ACCELERATOR | 0x206c940 | 0x48 | data | Tamil | India | 0.8472222222222222 |
RT_ACCELERATOR | 0x206c940 | 0x48 | data | Tamil | Sri Lanka | 0.8472222222222222 |
RT_GROUP_CURSOR | 0x206cb68 | 0x22 | data | 1.0588235294117647 | ||
RT_GROUP_CURSOR | 0x206e848 | 0x30 | data | 0.9375 | ||
RT_GROUP_ICON | 0x2066778 | 0x68 | data | Tamil | India | 0.7019230769230769 |
RT_GROUP_ICON | 0x2066778 | 0x68 | data | Tamil | Sri Lanka | 0.7019230769230769 |
RT_GROUP_ICON | 0x2060618 | 0x68 | data | Tamil | India | 0.6826923076923077 |
RT_GROUP_ICON | 0x2060618 | 0x68 | data | Tamil | Sri Lanka | 0.6826923076923077 |
RT_GROUP_ICON | 0x206c8d8 | 0x68 | data | Tamil | India | 0.7211538461538461 |
RT_GROUP_ICON | 0x206c8d8 | 0x68 | data | Tamil | Sri Lanka | 0.7211538461538461 |
RT_VERSION | 0x206e878 | 0x25c | data | 0.5413907284768212 |
DLL | Import |
---|---|
KERNEL32.dll | LocalCompact, InterlockedIncrement, GetCurrentProcess, GetLogicalDriveStringsW, CreateJobObjectW, InterlockedCompareExchange, SetVolumeMountPointW, GetTimeFormatA, _lcreat, GetModuleHandleW, SetFileTime, ClearCommBreak, GetConsoleAliasExesW, CreateActCtxW, LoadLibraryW, CopyFileW, _hread, GetCalendarInfoW, CreateEventA, GetFileAttributesW, VerifyVersionInfoA, GetModuleFileNameW, GetEnvironmentVariableA, GetTempPathW, InterlockedExchange, GlobalUnfix, GetStdHandle, GetLastError, GetProcAddress, CreateNamedPipeA, CommConfigDialogA, EnumSystemCodePagesW, SetComputerNameA, GlobalFree, GetTempFileNameA, LoadLibraryA, UnhandledExceptionFilter, InterlockedExchangeAdd, LocalAlloc, CreateHardLinkW, GetNumberFormatW, OpenEventA, QueryDosDeviceW, FoldStringA, SetEnvironmentVariableA, EnumDateFormatsA, GetCurrentDirectoryA, GetShortPathNameW, SetCalendarInfoA, SetProcessShutdownParameters, SetFileShortNameA, GetDiskFreeSpaceExA, GetVersionExA, ReadConsoleInputW, DebugBreak, SetFileAttributesW, LCMapStringW, GetLocaleInfoA, TlsGetValue, SetFilePointer, EnumCalendarInfoA, GetComputerNameA, InterlockedDecrement, EncodePointer, DecodePointer, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapFree, HeapReAlloc, ExitProcess, GetCommandLineW, HeapSetInformation, GetStartupInfoW, RaiseException, RtlUnwind, HeapAlloc, WideCharToMultiByte, MultiByteToWideChar, GetCPInfo, IsProcessorFeaturePresent, HeapCreate, InitializeCriticalSectionAndSpinCount, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, WriteFile, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, HeapSize, GetACP, GetOEMCP, IsValidCodePage, GetStringTypeW |
GDI32.dll | GetCharWidthI, GetBkMode, CreateDCW, GetCharWidth32A, GetCharABCWidthsI |
WINHTTP.dll | WinHttpCloseHandle |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Tamil | India | |
Tamil | Sri Lanka |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-01T15:17:23.620395+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49736 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:24.752008+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49737 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:25.914811+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49738 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:27.029533+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49739 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:28.206437+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49740 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:29.341890+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49741 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:30.500449+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49742 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:31.641582+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49743 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:33.261390+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49744 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:34.418617+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49745 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:35.545596+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49746 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:36.688527+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49747 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:37.858454+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49748 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:38.979866+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49749 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:40.096823+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49750 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:41.358376+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49751 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:42.684467+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49752 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:43.812303+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49753 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:45.121736+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49754 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:46.345239+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49755 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:47.480934+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49756 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:48.777574+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49757 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:49.901493+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49758 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:50.981956+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49759 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:52.350953+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49760 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:17:53.596376+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49761 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:18:59.724566+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49763 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:06.035186+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49764 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:11.806618+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49765 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:18.036708+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49766 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:23.665761+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49767 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:30.039822+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49768 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:35.601803+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49769 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:42.320909+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49770 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:47.791066+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49771 | 78.89.199.216 | 80 | TCP |
2024-10-01T15:19:56.389866+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49772 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:02.025493+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49773 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:07.324998+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49774 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:13.530972+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49775 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:19.524009+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49776 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:25.648095+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49777 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:31.521429+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49778 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:36.199335+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49779 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:41.110917+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49780 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:47.770977+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49781 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:54.025223+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49782 | 187.131.253.169 | 80 | TCP |
2024-10-01T15:20:59.510649+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49783 | 187.131.253.169 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 1, 2024 15:17:22.445229053 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:22.451527119 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:22.451591969 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:22.451747894 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:22.451772928 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:22.456839085 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:22.456938028 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:23.620310068 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:23.620345116 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:23.620394945 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:23.622291088 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:23.625282049 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:23.628797054 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:23.631429911 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:23.631508112 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:23.632148027 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:23.632172108 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:23.638276100 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:23.638286114 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:24.751142979 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:24.751873016 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:24.752007961 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:24.752744913 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:24.756525993 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:24.757467031 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:24.761313915 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:24.764297009 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:24.764417887 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:24.764436007 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:24.769299030 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:24.769310951 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:25.914532900 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:25.914743900 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:25.914810896 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:25.914952040 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:25.917706013 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:25.919837952 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:25.922595978 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:25.922660112 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:25.922745943 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:25.922774076 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:25.927726030 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:25.927736044 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:27.029357910 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:27.029464960 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:27.029532909 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:27.029649973 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:27.032167912 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:27.034401894 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:27.037061930 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:27.037136078 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:27.037231922 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:27.037246943 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:27.042004108 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:27.042140007 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:28.205945015 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:28.206371069 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:28.206437111 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:28.206469059 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:28.209345102 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:28.211194992 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:28.214118004 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:28.214200974 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:28.214375019 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:28.214417934 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:28.219299078 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:28.219320059 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:29.341069937 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:29.341820002 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:29.341890097 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:29.341963053 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:29.344996929 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:29.346779108 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:29.349792004 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:29.349864006 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:29.350001097 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:29.350030899 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:29.354773998 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:29.354932070 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:30.500327110 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:30.500355959 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:30.500448942 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:30.500621080 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:30.502921104 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:30.505605936 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:30.507860899 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:30.507916927 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:30.508013010 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:30.508030891 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:30.512811899 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:30.513195992 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:31.641361952 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:31.641386986 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:31.641582012 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:31.658416033 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:31.663273096 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:31.778784990 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:31.783729076 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:31.783812046 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:31.786107063 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:31.786122084 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:31.790925026 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:31.790946960 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.261308908 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.261320114 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.261329889 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.261368990 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.261389971 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:33.261410952 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:33.261590004 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:33.264512062 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:33.266448975 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.269424915 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.269500017 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:33.269844055 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:33.269926071 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:33.274668932 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:33.274729013 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:34.418441057 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:34.418560028 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:34.418617010 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:34.418803930 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:34.422225952 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:34.423909903 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:34.427135944 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:34.427232981 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:34.427390099 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:34.427407026 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:34.432135105 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:34.432323933 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:35.545464039 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:35.545540094 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:35.545595884 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:35.545723915 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:35.548285961 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:35.551460028 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:35.553772926 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:35.553854942 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:35.553958893 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:35.553971052 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:35.558896065 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:35.559071064 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:36.688323021 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:36.688472033 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:36.688527107 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:36.688553095 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:36.691919088 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:36.693517923 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:36.696840048 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:36.696912050 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:36.697046995 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:36.697081089 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:36.701819897 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:36.702012062 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:37.858297110 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:37.858382940 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:37.858453989 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:37.858622074 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:37.863507986 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:37.865519047 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:37.870429039 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:37.870507956 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:37.871206045 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:37.871223927 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:37.876038074 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:37.876373053 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:38.979603052 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:38.979806900 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:38.979866028 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:38.979918957 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:38.983025074 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:38.984728098 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:38.987787962 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:38.987854004 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:38.987994909 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:38.988075972 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:38.992887974 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:38.992897987 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:40.096661091 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:40.096705914 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:40.096822977 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:40.097040892 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:40.099662066 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:40.101785898 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:40.104496002 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:40.104585886 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:40.104718924 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:40.104804993 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:40.109496117 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:40.109678984 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:41.358256102 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:41.358282089 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:41.358376026 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:41.366945028 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:41.371722937 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:41.417382002 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:41.422343016 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:41.422415018 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:41.422532082 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:41.422544956 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:41.427268028 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:41.427480936 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:42.684295893 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:42.684406042 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:42.684416056 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:42.684467077 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:42.684706926 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:42.687062025 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:42.689654112 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:42.692214966 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:42.692286968 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:42.692390919 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:42.692410946 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:42.697213888 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:42.697525024 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:43.812161922 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:43.812191963 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:43.812303066 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:43.820204973 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:43.825107098 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:43.888565063 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:43.893436909 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:43.893548965 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:43.896550894 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:43.896550894 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:43.901350975 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:43.901473045 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:45.121233940 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:45.121669054 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:45.121736050 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:45.121788979 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:45.124097109 CEST | 49755 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:45.126543045 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:45.128951073 CEST | 80 | 49755 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:45.129025936 CEST | 49755 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:45.129367113 CEST | 49755 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:45.129425049 CEST | 49755 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:45.134155035 CEST | 80 | 49755 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:45.134823084 CEST | 80 | 49755 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:46.344868898 CEST | 80 | 49755 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:46.345072985 CEST | 80 | 49755 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:46.345238924 CEST | 49755 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:46.345238924 CEST | 49755 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:46.347575903 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:46.350127935 CEST | 80 | 49755 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:46.352461100 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:46.352650881 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:46.352650881 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:46.352679968 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:46.357676029 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:46.357688904 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:47.480715036 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:47.480879068 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:47.480933905 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:47.480973959 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:47.483319044 CEST | 49757 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:47.485948086 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:47.488255978 CEST | 80 | 49757 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:47.488336086 CEST | 49757 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:47.488466978 CEST | 49757 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:47.488495111 CEST | 49757 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:47.493324041 CEST | 80 | 49757 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:47.493349075 CEST | 80 | 49757 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:48.777230024 CEST | 80 | 49757 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:48.777518988 CEST | 80 | 49757 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:48.777574062 CEST | 49757 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:48.777616024 CEST | 49757 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:48.780261040 CEST | 49758 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:48.782406092 CEST | 80 | 49757 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:48.785130978 CEST | 80 | 49758 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:48.785193920 CEST | 49758 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:48.785304070 CEST | 49758 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:48.785329103 CEST | 49758 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:48.790330887 CEST | 80 | 49758 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:48.790409088 CEST | 80 | 49758 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:49.901345015 CEST | 80 | 49758 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:49.901447058 CEST | 80 | 49758 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:49.901493073 CEST | 49758 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:49.901624918 CEST | 49758 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:49.904613018 CEST | 49759 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:49.906589985 CEST | 80 | 49758 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:49.909699917 CEST | 80 | 49759 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:49.909775972 CEST | 49759 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:49.909883022 CEST | 49759 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:49.909920931 CEST | 49759 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:49.915008068 CEST | 80 | 49759 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:49.915020943 CEST | 80 | 49759 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:50.981254101 CEST | 80 | 49759 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:50.981889009 CEST | 80 | 49759 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:50.981956005 CEST | 49759 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:50.987478971 CEST | 49759 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:50.992578983 CEST | 49760 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:50.992608070 CEST | 80 | 49759 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:50.997589111 CEST | 80 | 49760 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:50.997786999 CEST | 49760 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:50.997971058 CEST | 49760 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:50.998014927 CEST | 49760 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:51.004055023 CEST | 80 | 49760 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:51.004077911 CEST | 80 | 49760 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:52.350409031 CEST | 80 | 49760 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:52.350739956 CEST | 80 | 49760 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:52.350953102 CEST | 49760 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:52.350953102 CEST | 49760 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:52.355844975 CEST | 80 | 49760 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:52.359483004 CEST | 49761 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:52.366018057 CEST | 80 | 49761 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:52.366118908 CEST | 49761 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:52.366202116 CEST | 49761 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:52.366219044 CEST | 49761 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:52.371038914 CEST | 80 | 49761 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:52.371251106 CEST | 80 | 49761 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:53.596154928 CEST | 80 | 49761 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:53.596175909 CEST | 80 | 49761 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:53.596198082 CEST | 80 | 49761 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:17:53.596375942 CEST | 49761 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:53.596375942 CEST | 49761 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:53.596487045 CEST | 49761 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:17:53.601316929 CEST | 80 | 49761 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:18:58.629405975 CEST | 49763 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:18:58.635195017 CEST | 80 | 49763 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:18:58.635305882 CEST | 49763 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:18:58.635438919 CEST | 49763 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:18:58.635438919 CEST | 49763 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:18:58.641263962 CEST | 80 | 49763 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:18:58.641503096 CEST | 80 | 49763 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:18:59.724081039 CEST | 80 | 49763 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:18:59.724400997 CEST | 80 | 49763 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:18:59.724565983 CEST | 49763 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:18:59.779752016 CEST | 49763 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:18:59.784720898 CEST | 80 | 49763 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:04.967317104 CEST | 49764 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:04.972249031 CEST | 80 | 49764 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:04.972321033 CEST | 49764 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:04.972449064 CEST | 49764 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:04.972641945 CEST | 49764 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:04.977195978 CEST | 80 | 49764 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:04.977406025 CEST | 80 | 49764 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:06.035068989 CEST | 80 | 49764 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:06.035087109 CEST | 80 | 49764 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:06.035186052 CEST | 49764 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:06.035440922 CEST | 49764 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:06.041214943 CEST | 80 | 49764 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:10.689902067 CEST | 49765 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:10.695034981 CEST | 80 | 49765 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:10.695131063 CEST | 49765 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:10.695298910 CEST | 49765 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:10.695326090 CEST | 49765 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:10.700165987 CEST | 80 | 49765 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:10.700203896 CEST | 80 | 49765 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:11.806364059 CEST | 80 | 49765 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:11.806560040 CEST | 80 | 49765 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:11.806617975 CEST | 49765 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:11.806667089 CEST | 49765 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:11.811470032 CEST | 80 | 49765 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:16.791208982 CEST | 49766 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:16.951153994 CEST | 80 | 49766 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:16.951252937 CEST | 49766 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:16.951466084 CEST | 49766 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:16.951493979 CEST | 49766 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:16.956299067 CEST | 80 | 49766 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:16.956341982 CEST | 80 | 49766 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:18.036545992 CEST | 80 | 49766 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:18.036652088 CEST | 80 | 49766 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:18.036708117 CEST | 49766 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:18.037094116 CEST | 49766 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:18.041821003 CEST | 80 | 49766 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:22.185187101 CEST | 49767 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:22.190233946 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:22.190331936 CEST | 49767 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:22.190469027 CEST | 49767 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:22.190493107 CEST | 49767 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:22.195411921 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:22.195444107 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:23.665653944 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:23.665702105 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:23.665713072 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:23.665740013 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:23.665760994 CEST | 49767 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:23.665800095 CEST | 49767 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:23.665956974 CEST | 49767 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:23.671545029 CEST | 80 | 49767 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:28.838094950 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:28.939483881 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:28.939600945 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:28.939738989 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:28.939748049 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:28.944602013 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:28.944713116 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:30.039554119 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:30.039614916 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:30.039822102 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:30.039942026 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:30.044997931 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:34.498941898 CEST | 49769 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:34.503876925 CEST | 80 | 49769 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:34.503994942 CEST | 49769 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:34.504096031 CEST | 49769 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:34.504173040 CEST | 49769 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:34.508874893 CEST | 80 | 49769 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:34.509087086 CEST | 80 | 49769 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:35.601290941 CEST | 80 | 49769 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:35.601697922 CEST | 80 | 49769 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:35.601803064 CEST | 49769 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:35.602581978 CEST | 49769 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:35.607872963 CEST | 80 | 49769 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:41.185395956 CEST | 49770 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:41.190818071 CEST | 80 | 49770 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:41.190916061 CEST | 49770 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:41.191082954 CEST | 49770 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:41.191118002 CEST | 49770 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:41.196511984 CEST | 80 | 49770 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:41.196542025 CEST | 80 | 49770 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:42.320750952 CEST | 80 | 49770 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:42.320799112 CEST | 80 | 49770 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:42.320909023 CEST | 49770 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:42.321075916 CEST | 49770 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:42.325965881 CEST | 80 | 49770 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:46.690525055 CEST | 49771 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:46.695473909 CEST | 80 | 49771 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:46.695559025 CEST | 49771 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:46.695696115 CEST | 49771 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:46.695724010 CEST | 49771 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:46.700422049 CEST | 80 | 49771 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:46.700459003 CEST | 80 | 49771 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:47.790616989 CEST | 80 | 49771 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:47.790965080 CEST | 80 | 49771 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:47.791065931 CEST | 49771 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:47.791096926 CEST | 49771 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 1, 2024 15:19:47.803268909 CEST | 80 | 49771 | 78.89.199.216 | 192.168.2.4 |
Oct 1, 2024 15:19:55.285552979 CEST | 49772 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:19:55.290549040 CEST | 80 | 49772 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:19:55.290637016 CEST | 49772 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:19:55.290777922 CEST | 49772 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:19:55.290815115 CEST | 49772 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:19:55.295609951 CEST | 80 | 49772 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:19:55.295857906 CEST | 80 | 49772 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:19:56.389751911 CEST | 80 | 49772 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:19:56.389815092 CEST | 80 | 49772 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:19:56.389825106 CEST | 80 | 49772 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:19:56.389866114 CEST | 49772 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:19:56.389914036 CEST | 49772 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:19:56.390023947 CEST | 49772 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:19:56.396209002 CEST | 80 | 49772 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:01.055428028 CEST | 49773 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:01.061125040 CEST | 80 | 49773 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:01.061896086 CEST | 49773 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:01.062087059 CEST | 49773 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:01.062105894 CEST | 49773 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:01.068075895 CEST | 80 | 49773 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:01.068578005 CEST | 80 | 49773 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:02.020612955 CEST | 80 | 49773 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:02.025424004 CEST | 80 | 49773 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:02.025492907 CEST | 49773 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:02.025544882 CEST | 49773 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:02.032139063 CEST | 80 | 49773 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:06.357049942 CEST | 49774 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:06.362009048 CEST | 80 | 49774 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:06.362175941 CEST | 49774 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:06.362241030 CEST | 49774 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:06.362256050 CEST | 49774 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:06.367302895 CEST | 80 | 49774 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:06.367356062 CEST | 80 | 49774 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:07.324738026 CEST | 80 | 49774 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:07.324940920 CEST | 80 | 49774 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:07.324997902 CEST | 49774 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:07.325037956 CEST | 49774 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:07.329893112 CEST | 80 | 49774 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:12.385631084 CEST | 49775 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:12.457861900 CEST | 80 | 49775 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:12.457947016 CEST | 49775 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:12.458080053 CEST | 49775 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:12.458101034 CEST | 49775 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:12.463021994 CEST | 80 | 49775 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:12.463639975 CEST | 80 | 49775 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:13.530782938 CEST | 80 | 49775 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:13.530905962 CEST | 80 | 49775 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:13.530915976 CEST | 80 | 49775 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:13.530972004 CEST | 49775 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:13.531141996 CEST | 49775 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:13.535896063 CEST | 80 | 49775 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:17.892683983 CEST | 49776 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:17.967000961 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:17.967088938 CEST | 49776 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:17.967247009 CEST | 49776 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:17.967266083 CEST | 49776 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:17.972001076 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:17.972141981 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:19.523677111 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:19.523699045 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:19.523709059 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:19.523772001 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:19.524008989 CEST | 49776 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:19.524116039 CEST | 49776 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:19.524116039 CEST | 49776 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:19.528892040 CEST | 80 | 49776 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:24.676763058 CEST | 49777 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:24.681968927 CEST | 80 | 49777 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:24.682076931 CEST | 49777 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:24.682240009 CEST | 49777 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:24.682265997 CEST | 49777 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:24.687267065 CEST | 80 | 49777 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:24.687525988 CEST | 80 | 49777 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:25.647753954 CEST | 80 | 49777 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:25.648049116 CEST | 80 | 49777 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:25.648094893 CEST | 49777 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:25.650413036 CEST | 49777 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:25.655793905 CEST | 80 | 49777 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:30.552651882 CEST | 49778 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:30.557573080 CEST | 80 | 49778 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:30.557800055 CEST | 49778 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:30.557919025 CEST | 49778 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:30.557948112 CEST | 49778 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:30.562913895 CEST | 80 | 49778 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:30.563182116 CEST | 80 | 49778 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:31.521358967 CEST | 80 | 49778 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:31.521388054 CEST | 80 | 49778 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:31.521429062 CEST | 49778 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:31.521555901 CEST | 49778 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:31.526273012 CEST | 80 | 49778 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:35.179691076 CEST | 49779 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:35.217693090 CEST | 80 | 49779 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:35.217789888 CEST | 49779 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:35.217917919 CEST | 49779 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:35.217932940 CEST | 49779 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:35.222702026 CEST | 80 | 49779 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:35.222883940 CEST | 80 | 49779 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:36.199208021 CEST | 80 | 49779 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:36.199249029 CEST | 80 | 49779 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:36.199335098 CEST | 49779 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:36.199521065 CEST | 49779 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:36.204262018 CEST | 80 | 49779 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:40.140780926 CEST | 49780 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:40.145731926 CEST | 80 | 49780 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:40.145817041 CEST | 49780 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:40.145922899 CEST | 49780 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:40.145936966 CEST | 49780 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:40.150835991 CEST | 80 | 49780 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:40.150845051 CEST | 80 | 49780 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:41.110836983 CEST | 80 | 49780 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:41.110863924 CEST | 80 | 49780 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:41.110917091 CEST | 49780 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:41.111092091 CEST | 49780 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:41.115873098 CEST | 80 | 49780 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:46.084177017 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:46.089056969 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:46.089241028 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:46.089329004 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:46.089354038 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:46.094125986 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:46.094484091 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:47.770889997 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:47.770909071 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:47.770917892 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:47.770977020 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:47.771024942 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:47.771155119 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:47.771214008 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:47.771256924 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:47.771483898 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:47.771524906 CEST | 49781 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:47.775875092 CEST | 80 | 49781 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:52.899945974 CEST | 49782 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:52.904849052 CEST | 80 | 49782 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:52.904911041 CEST | 49782 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:52.905045986 CEST | 49782 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:52.905060053 CEST | 49782 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:52.909779072 CEST | 80 | 49782 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:52.909982920 CEST | 80 | 49782 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:54.025105953 CEST | 80 | 49782 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:54.025141954 CEST | 80 | 49782 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:54.025167942 CEST | 80 | 49782 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:54.025223017 CEST | 49782 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:54.025264978 CEST | 49782 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:54.025444984 CEST | 49782 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:54.030210018 CEST | 80 | 49782 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:58.529503107 CEST | 49783 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:58.534431934 CEST | 80 | 49783 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:58.534496069 CEST | 49783 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:58.534616947 CEST | 49783 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:58.534627914 CEST | 49783 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:58.539578915 CEST | 80 | 49783 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:58.539886951 CEST | 80 | 49783 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:59.510467052 CEST | 80 | 49783 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:59.510586977 CEST | 80 | 49783 | 187.131.253.169 | 192.168.2.4 |
Oct 1, 2024 15:20:59.510648966 CEST | 49783 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:59.510708094 CEST | 49783 | 80 | 192.168.2.4 | 187.131.253.169 |
Oct 1, 2024 15:20:59.515568972 CEST | 80 | 49783 | 187.131.253.169 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 1, 2024 15:17:20.132869005 CEST | 58725 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 15:17:21.118122101 CEST | 58725 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 15:17:22.214936018 CEST | 58725 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 15:17:22.421433926 CEST | 53 | 58725 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 15:17:22.422081947 CEST | 53 | 58725 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 15:17:22.422563076 CEST | 53 | 58725 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 15:19:52.888026953 CEST | 58021 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 15:19:53.883910894 CEST | 58021 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 15:19:54.899472952 CEST | 58021 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 15:19:55.284605980 CEST | 53 | 58021 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 15:19:55.284629107 CEST | 53 | 58021 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 15:19:55.287265062 CEST | 53 | 58021 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 1, 2024 15:17:20.132869005 CEST | 192.168.2.4 | 1.1.1.1 | 0x63e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 15:17:21.118122101 CEST | 192.168.2.4 | 1.1.1.1 | 0x63e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 15:17:22.214936018 CEST | 192.168.2.4 | 1.1.1.1 | 0x63e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 15:19:52.888026953 CEST | 192.168.2.4 | 1.1.1.1 | 0x8010 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 15:19:53.883910894 CEST | 192.168.2.4 | 1.1.1.1 | 0x8010 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 15:19:54.899472952 CEST | 192.168.2.4 | 1.1.1.1 | 0x8010 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 179.52.87.163 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 187.131.253.169 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.421433926 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 179.52.87.163 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 187.131.253.169 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422081947 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 179.52.87.163 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 187.131.253.169 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:17:22.422563076 CEST | 1.1.1.1 | 192.168.2.4 | 0x63e | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 187.131.253.169 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 179.52.87.163 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284605980 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 187.131.253.169 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 179.52.87.163 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.284629107 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 187.131.253.169 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 179.52.87.163 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 15:19:55.287265062 CEST | 1.1.1.1 | 192.168.2.4 | 0x8010 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:22.451747894 CEST | 282 | OUT | |
Oct 1, 2024 15:17:22.451772928 CEST | 216 | OUT | |
Oct 1, 2024 15:17:23.620310068 CEST | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49737 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:23.632148027 CEST | 283 | OUT | |
Oct 1, 2024 15:17:23.632172108 CEST | 345 | OUT | |
Oct 1, 2024 15:17:24.751142979 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49738 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:24.764417887 CEST | 282 | OUT | |
Oct 1, 2024 15:17:24.764436007 CEST | 348 | OUT | |
Oct 1, 2024 15:17:25.914532900 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49739 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:25.922745943 CEST | 281 | OUT | |
Oct 1, 2024 15:17:25.922774076 CEST | 150 | OUT | |
Oct 1, 2024 15:17:27.029357910 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49740 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:27.037231922 CEST | 278 | OUT | |
Oct 1, 2024 15:17:27.037246943 CEST | 148 | OUT | |
Oct 1, 2024 15:17:28.205945015 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49741 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:28.214375019 CEST | 282 | OUT | |
Oct 1, 2024 15:17:28.214417934 CEST | 277 | OUT | |
Oct 1, 2024 15:17:29.341069937 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49742 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:29.350001097 CEST | 281 | OUT | |
Oct 1, 2024 15:17:29.350030899 CEST | 170 | OUT | |
Oct 1, 2024 15:17:30.500327110 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49743 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:30.508013010 CEST | 279 | OUT | |
Oct 1, 2024 15:17:30.508030891 CEST | 126 | OUT | |
Oct 1, 2024 15:17:31.641361952 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49744 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:31.786107063 CEST | 282 | OUT | |
Oct 1, 2024 15:17:31.786122084 CEST | 326 | OUT | |
Oct 1, 2024 15:17:33.261308908 CEST | 484 | IN | |
Oct 1, 2024 15:17:33.261368990 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49745 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:33.269844055 CEST | 283 | OUT | |
Oct 1, 2024 15:17:33.269926071 CEST | 196 | OUT | |
Oct 1, 2024 15:17:34.418441057 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49746 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:34.427390099 CEST | 278 | OUT | |
Oct 1, 2024 15:17:34.427407026 CEST | 205 | OUT | |
Oct 1, 2024 15:17:35.545464039 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49747 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:35.553958893 CEST | 281 | OUT | |
Oct 1, 2024 15:17:35.553971052 CEST | 205 | OUT | |
Oct 1, 2024 15:17:36.688323021 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49748 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:36.697046995 CEST | 279 | OUT | |
Oct 1, 2024 15:17:36.697081089 CEST | 168 | OUT | |
Oct 1, 2024 15:17:37.858297110 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49749 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:37.871206045 CEST | 278 | OUT | |
Oct 1, 2024 15:17:37.871223927 CEST | 149 | OUT | |
Oct 1, 2024 15:17:38.979603052 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49750 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:38.987994909 CEST | 282 | OUT | |
Oct 1, 2024 15:17:38.988075972 CEST | 319 | OUT | |
Oct 1, 2024 15:17:40.096661091 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49751 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:40.104718924 CEST | 282 | OUT | |
Oct 1, 2024 15:17:40.104804993 CEST | 271 | OUT | |
Oct 1, 2024 15:17:41.358256102 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49752 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:41.422532082 CEST | 279 | OUT | |
Oct 1, 2024 15:17:41.422544956 CEST | 261 | OUT | |
Oct 1, 2024 15:17:42.684295893 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49753 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:42.692390919 CEST | 281 | OUT | |
Oct 1, 2024 15:17:42.692410946 CEST | 323 | OUT | |
Oct 1, 2024 15:17:43.812161922 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49754 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:43.896550894 CEST | 280 | OUT | |
Oct 1, 2024 15:17:43.896550894 CEST | 127 | OUT | |
Oct 1, 2024 15:17:45.121233940 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49755 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:45.129367113 CEST | 278 | OUT | |
Oct 1, 2024 15:17:45.129425049 CEST | 147 | OUT | |
Oct 1, 2024 15:17:46.344868898 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49756 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:46.352650881 CEST | 282 | OUT | |
Oct 1, 2024 15:17:46.352679968 CEST | 276 | OUT | |
Oct 1, 2024 15:17:47.480715036 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49757 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:47.488466978 CEST | 281 | OUT | |
Oct 1, 2024 15:17:47.488495111 CEST | 362 | OUT | |
Oct 1, 2024 15:17:48.777230024 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49758 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:48.785304070 CEST | 280 | OUT | |
Oct 1, 2024 15:17:48.785329103 CEST | 336 | OUT | |
Oct 1, 2024 15:17:49.901345015 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49759 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:49.909883022 CEST | 280 | OUT | |
Oct 1, 2024 15:17:49.909920931 CEST | 171 | OUT | |
Oct 1, 2024 15:17:50.981254101 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49760 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:50.997971058 CEST | 278 | OUT | |
Oct 1, 2024 15:17:50.998014927 CEST | 237 | OUT | |
Oct 1, 2024 15:17:52.350409031 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49761 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:17:52.366202116 CEST | 278 | OUT | |
Oct 1, 2024 15:17:52.366219044 CEST | 318 | OUT | |
Oct 1, 2024 15:17:53.596154928 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49763 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:18:58.635438919 CEST | 279 | OUT | |
Oct 1, 2024 15:18:58.635438919 CEST | 240 | OUT | |
Oct 1, 2024 15:18:59.724081039 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49764 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:04.972449064 CEST | 280 | OUT | |
Oct 1, 2024 15:19:04.972641945 CEST | 126 | OUT | |
Oct 1, 2024 15:19:06.035068989 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49765 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:10.695298910 CEST | 281 | OUT | |
Oct 1, 2024 15:19:10.695326090 CEST | 200 | OUT | |
Oct 1, 2024 15:19:11.806364059 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49766 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:16.951466084 CEST | 280 | OUT | |
Oct 1, 2024 15:19:16.951493979 CEST | 349 | OUT | |
Oct 1, 2024 15:19:18.036545992 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49767 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:22.190469027 CEST | 280 | OUT | |
Oct 1, 2024 15:19:22.190493107 CEST | 287 | OUT | |
Oct 1, 2024 15:19:23.665653944 CEST | 151 | IN | |
Oct 1, 2024 15:19:23.665740013 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49768 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:28.939738989 CEST | 279 | OUT | |
Oct 1, 2024 15:19:28.939748049 CEST | 151 | OUT | |
Oct 1, 2024 15:19:30.039554119 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49769 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:34.504096031 CEST | 283 | OUT | |
Oct 1, 2024 15:19:34.504173040 CEST | 139 | OUT | |
Oct 1, 2024 15:19:35.601290941 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49770 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:41.191082954 CEST | 280 | OUT | |
Oct 1, 2024 15:19:41.191118002 CEST | 331 | OUT | |
Oct 1, 2024 15:19:42.320750952 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49771 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:46.695696115 CEST | 278 | OUT | |
Oct 1, 2024 15:19:46.695724010 CEST | 316 | OUT | |
Oct 1, 2024 15:19:47.790616989 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49772 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:19:55.290777922 CEST | 282 | OUT | |
Oct 1, 2024 15:19:55.290815115 CEST | 160 | OUT | |
Oct 1, 2024 15:19:56.389751911 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 49773 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:01.062087059 CEST | 282 | OUT | |
Oct 1, 2024 15:20:01.062105894 CEST | 326 | OUT | |
Oct 1, 2024 15:20:02.020612955 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 49774 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:06.362241030 CEST | 282 | OUT | |
Oct 1, 2024 15:20:06.362256050 CEST | 355 | OUT | |
Oct 1, 2024 15:20:07.324738026 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 49775 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:12.458080053 CEST | 282 | OUT | |
Oct 1, 2024 15:20:12.458101034 CEST | 224 | OUT | |
Oct 1, 2024 15:20:13.530782938 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 49776 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:17.967247009 CEST | 279 | OUT | |
Oct 1, 2024 15:20:17.967266083 CEST | 183 | OUT | |
Oct 1, 2024 15:20:19.523677111 CEST | 151 | IN | |
Oct 1, 2024 15:20:19.523772001 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 49777 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:24.682240009 CEST | 279 | OUT | |
Oct 1, 2024 15:20:24.682265997 CEST | 238 | OUT | |
Oct 1, 2024 15:20:25.647753954 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 49778 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:30.557919025 CEST | 278 | OUT | |
Oct 1, 2024 15:20:30.557948112 CEST | 155 | OUT | |
Oct 1, 2024 15:20:31.521358967 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 49779 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:35.217917919 CEST | 282 | OUT | |
Oct 1, 2024 15:20:35.217932940 CEST | 192 | OUT | |
Oct 1, 2024 15:20:36.199208021 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 49780 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:40.145922899 CEST | 279 | OUT | |
Oct 1, 2024 15:20:40.145936966 CEST | 187 | OUT | |
Oct 1, 2024 15:20:41.110836983 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 49781 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:46.089329004 CEST | 278 | OUT | |
Oct 1, 2024 15:20:46.089354038 CEST | 187 | OUT | |
Oct 1, 2024 15:20:47.770889997 CEST | 151 | IN | |
Oct 1, 2024 15:20:47.771214008 CEST | 151 | IN | |
Oct 1, 2024 15:20:47.771483898 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 49782 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:52.905045986 CEST | 278 | OUT | |
Oct 1, 2024 15:20:52.905060053 CEST | 222 | OUT | |
Oct 1, 2024 15:20:54.025105953 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 49783 | 187.131.253.169 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 15:20:58.534616947 CEST | 280 | OUT | |
Oct 1, 2024 15:20:58.534627914 CEST | 174 | OUT | |
Oct 1, 2024 15:20:59.510467052 CEST | 151 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:16:55 |
Start date: | 01/10/2024 |
Path: | C:\Users\user\Desktop\k8JAXb3Lhs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 369'664 bytes |
MD5 hash: | EEAD7A529F768CD0A74A639FF806357C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 09:17:01 |
Start date: | 01/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 4 |
Start time: | 09:17:20 |
Start date: | 01/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sfjujsr |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 369'664 bytes |
MD5 hash: | EEAD7A529F768CD0A74A639FF806357C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 09:20:01 |
Start date: | 01/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sfjujsr |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 369'664 bytes |
MD5 hash: | EEAD7A529F768CD0A74A639FF806357C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 8.6% |
Dynamic/Decrypted Code Coverage: | 42.6% |
Signature Coverage: | 43.4% |
Total number of Nodes: | 122 |
Total number of Limit Nodes: | 4 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0286F737 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 025F003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 025F0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0286F3F6 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025F092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0286F014 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403277 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040324F Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025F0D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403256 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403290 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 8.6% |
Dynamic/Decrypted Code Coverage: | 42.6% |
Signature Coverage: | 0% |
Total number of Nodes: | 122 |
Total number of Limit Nodes: | 4 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0271003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0274F0D7 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02710E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0274ED96 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|