Windows
Analysis Report
IMG_3322101870451.exe
Overview
General Information
Detection
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- IMG_3322101870451.exe (PID: 8080 cmdline:
"C:\Users\ user\Deskt op\IMG_332 2101870451 .exe" MD5: 8290AB3945CFC9355B5F18D4C4262CEE)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Saudi_Phish_Trojan | Detects a trojan used in Saudi Aramco Phishing | Florian Roth |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Saudi_Phish_Trojan | Detects a trojan used in Saudi Aramco Phishing | Florian Roth |
|
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Code function: | 0_2_01801C0A | |
Source: | Code function: | 0_2_01805A5C | |
Source: | Code function: | 0_2_01802554 | |
Source: | Code function: | 0_2_01801C4C | |
Source: | Code function: | 0_2_01801704 | |
Source: | Code function: | 0_2_01805A96 |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | OS Credential Dumping | 1 Security Software Discovery | Remote Services | 11 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 31 Virtualization/Sandbox Evasion | LSASS Memory | 31 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Software Packing | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 12 System Information Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
55% | ReversingLabs | Win32.Trojan.Jalapeno | ||
100% | Avira | TR/Kryptik.dkuuk | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
6% | Virustotal | Browse |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.167.61.13 | unknown | Turkey | 197328 | INETLTDTR | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1526378 |
Start date and time: | 2024-10-05 14:36:13 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | IMG_3322101870451.exe |
Detection: | MAL |
Classification: | mal88.evad.winEXE@1/0@0/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target IMG_3322101870451.exe, PID 8080 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
08:37:16 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.167.61.13 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
INETLTDTR | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Cobalt Strike, Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RedLine, Snake Keylogger, StormKitty, SugarDump, VIP Keylogger, XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 6.444324190661784 |
TrID: |
|
File name: | IMG_3322101870451.exe |
File size: | 254'328 bytes |
MD5: | 8290ab3945cfc9355b5f18d4c4262cee |
SHA1: | f459dd7cdbc4881d6357c517c2b8026d3da77965 |
SHA256: | 23382ffd9ce9a9b163ed1b6f0ef80242f16c5bc85b0d302fd81b7c4f5cd48acd |
SHA512: | 6504755ec3dc036dea4e901a6812961b96f4e7ab190a7102bb0f48a1f875d6894be946e301f6369697c975ef27bc6dc62d49eee7602c04bae0376a13072bd48b |
SSDEEP: | 3072:zuEbDNm5N/CNnCDDRvLGRrOAOkGt6+duWA/t/SHUebbxCbGgKk12qk/mPYm21KL6:6i05ostvLG0CLbMU8K0PH |
TLSH: | 2E44D7823145DC9AE04329F258EFD56061787D9E8165C60E3783BB2BA5E734334AB78F |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...H <f................................. ........@.. ....................................`................................ |
Icon Hash: | 929296929e9e8e73 |
Entrypoint: | 0x40d6ea |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x663C2048 [Thu May 9 01:00:56 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Signature Valid: | false |
Signature Issuer: | CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US |
Signature Validation Error: | The digital signature of the object did not verify |
Error Number: | -2146869232 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 36083DDD2C0C94D360522774BEDA31E2 |
Thumbprint SHA-1: | B140BCEDA70D6A6C48C4258CC83F4ECCC96845C8 |
Thumbprint SHA-256: | B12E1F90FEB1A204409F736836E7BA7F078E40B3A809A73BAC08AEB658627610 |
Serial: | 06E2870844B5FE917E3498FD2526FBCD |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xd6a0 | 0x4a | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xe000 | 0x2f0d2 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x3ae00 | 0x3378 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x3e000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xb6f0 | 0xb800 | 3a1c970d081c56b2ad69b70a04ff578e | False | 0.5487644361413043 | data | 5.939148641753943 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xe000 | 0x2f0d2 | 0x2f200 | f50624b0c795e794cc04f7694fd461a3 | False | 0.3628564323607427 | data | 6.232542919188173 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x3e000 | 0xc | 0x200 | 279588c3633acfea830b53a9ece43405 | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xe0ac | 0x709e | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9976066597294485 | ||
RT_ICON | 0x1516e | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 67584 | 0.17033893292322252 | ||
RT_ICON | 0x259ba | 0x94a8 | Device independent bitmap graphic, 96 x 192 x 32, image size 38016 | 0.271415808282531 | ||
RT_ICON | 0x2ee86 | 0x5488 | Device independent bitmap graphic, 72 x 144 x 32, image size 21600 | 0.3012014787430684 | ||
RT_ICON | 0x34332 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16896 | 0.28259329239489844 | ||
RT_ICON | 0x3857e | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | 0.38558091286307056 | ||
RT_ICON | 0x3ab4a | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | 0.4598968105065666 | ||
RT_ICON | 0x3bc16 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | 0.5704918032786885 | ||
RT_ICON | 0x3c5c2 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | 0.6631205673758865 | ||
RT_GROUP_ICON | 0x3ca66 | 0x84 | data | 0.7272727272727273 | ||
RT_VERSION | 0x3cb26 | 0x3bc | data | 0.41422594142259417 | ||
RT_MANIFEST | 0x3cf1e | 0x1b4 | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (433), with no line terminators | 0.5642201834862385 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 5, 2024 14:37:17.297852039 CEST | 49709 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:17.302902937 CEST | 80 | 49709 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:37:17.303066015 CEST | 49709 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:17.304004908 CEST | 49709 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:17.309113026 CEST | 80 | 49709 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:37:38.669420004 CEST | 80 | 49709 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:37:38.669645071 CEST | 49709 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:38.678283930 CEST | 49709 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:38.678945065 CEST | 49711 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:38.683295965 CEST | 80 | 49709 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:37:38.684035063 CEST | 80 | 49711 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:37:38.684227943 CEST | 49711 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:38.684227943 CEST | 49711 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:37:38.690646887 CEST | 80 | 49711 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:00.063956022 CEST | 80 | 49711 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:00.064147949 CEST | 49711 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:00.065216064 CEST | 49711 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:00.070405006 CEST | 80 | 49711 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:00.074903965 CEST | 49712 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:00.080720901 CEST | 80 | 49712 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:00.080836058 CEST | 49712 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:00.081015110 CEST | 49712 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:00.087641954 CEST | 80 | 49712 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:21.457211971 CEST | 80 | 49712 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:21.457331896 CEST | 49712 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:21.457895041 CEST | 49712 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:21.458511114 CEST | 49714 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:21.463710070 CEST | 80 | 49712 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:21.464699030 CEST | 80 | 49714 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:21.464771986 CEST | 49714 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:21.464966059 CEST | 49714 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:21.469965935 CEST | 80 | 49714 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:41.837115049 CEST | 49714 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:41.838728905 CEST | 49715 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:41.843528986 CEST | 80 | 49715 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:41.843606949 CEST | 49715 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:41.843748093 CEST | 49715 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:41.848567963 CEST | 80 | 49715 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:41.882137060 CEST | 80 | 49714 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:42.383708954 CEST | 49715 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:42.384614944 CEST | 49716 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:42.389884949 CEST | 80 | 49716 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:42.390002966 CEST | 49716 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:42.390094042 CEST | 49716 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:42.395353079 CEST | 80 | 49716 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:42.430123091 CEST | 80 | 49715 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:42.826488018 CEST | 80 | 49714 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:42.826606035 CEST | 49714 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.446151018 CEST | 49716 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.446845055 CEST | 49717 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.451733112 CEST | 80 | 49717 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:53.451870918 CEST | 49717 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.451989889 CEST | 49717 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.456799984 CEST | 80 | 49717 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:53.494168997 CEST | 80 | 49716 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:53.696815968 CEST | 49717 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.696815968 CEST | 49718 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.701797009 CEST | 80 | 49718 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:53.701896906 CEST | 49718 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.702023029 CEST | 49718 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:38:53.707065105 CEST | 80 | 49718 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:38:53.742161989 CEST | 80 | 49717 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:03.233498096 CEST | 80 | 49715 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:03.233789921 CEST | 49715 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:03.493283987 CEST | 49718 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:03.498692989 CEST | 49719 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:03.503526926 CEST | 80 | 49719 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:03.503645897 CEST | 49719 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:03.504206896 CEST | 49719 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:03.509047031 CEST | 80 | 49719 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:03.542073011 CEST | 80 | 49718 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:03.799901009 CEST | 80 | 49716 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:03.799963951 CEST | 49716 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:08.461833954 CEST | 49719 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:08.463176012 CEST | 49720 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:08.468106031 CEST | 80 | 49720 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:08.468182087 CEST | 49720 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:08.468357086 CEST | 49720 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:08.474239111 CEST | 80 | 49720 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:08.514194012 CEST | 80 | 49719 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:11.165298939 CEST | 49720 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:11.166560888 CEST | 49721 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:11.171545029 CEST | 80 | 49721 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:11.174844027 CEST | 49721 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:11.175188065 CEST | 49721 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:11.180095911 CEST | 80 | 49721 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:11.218251944 CEST | 80 | 49720 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:14.816123009 CEST | 80 | 49717 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:14.816190004 CEST | 49717 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:15.079288006 CEST | 80 | 49718 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:15.079368114 CEST | 49718 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:21.900213003 CEST | 49721 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:21.900213003 CEST | 49722 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:21.905333996 CEST | 80 | 49722 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:21.905775070 CEST | 49722 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:21.905917883 CEST | 49722 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:21.910779953 CEST | 80 | 49722 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:21.946182966 CEST | 80 | 49721 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:22.040668011 CEST | 49722 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:22.040674925 CEST | 49723 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:22.046489000 CEST | 80 | 49723 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:22.046861887 CEST | 49723 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:22.047116041 CEST | 49723 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:22.053077936 CEST | 80 | 49723 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:22.092133999 CEST | 80 | 49722 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:24.859659910 CEST | 80 | 49719 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:24.859733105 CEST | 49719 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:26.759011030 CEST | 49723 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:26.761184931 CEST | 49724 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:26.766104937 CEST | 80 | 49724 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:26.766235113 CEST | 49724 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:26.766469002 CEST | 49724 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:26.771205902 CEST | 80 | 49724 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:26.806129932 CEST | 80 | 49723 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:29.828605890 CEST | 80 | 49720 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:29.828689098 CEST | 49720 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:32.546653986 CEST | 80 | 49721 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:32.547777891 CEST | 49721 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.243207932 CEST | 49724 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.244728088 CEST | 49725 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.249552011 CEST | 80 | 49725 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:33.249773026 CEST | 49725 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.249833107 CEST | 49725 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.254607916 CEST | 80 | 49725 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:33.290035009 CEST | 49725 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.290141106 CEST | 80 | 49724 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:33.290718079 CEST | 49726 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.295475006 CEST | 80 | 49726 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:33.295561075 CEST | 49726 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.295675993 CEST | 49726 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:33.300379992 CEST | 80 | 49726 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:33.338073015 CEST | 80 | 49725 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:35.008892059 CEST | 49726 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.010077953 CEST | 49727 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.014970064 CEST | 80 | 49727 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:35.015043974 CEST | 49727 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.015189886 CEST | 49727 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.020006895 CEST | 80 | 49727 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:35.058176994 CEST | 80 | 49726 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:35.399441957 CEST | 49727 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.400185108 CEST | 49728 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.418884993 CEST | 80 | 49728 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:35.418977976 CEST | 49728 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.419152975 CEST | 49728 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:35.425165892 CEST | 80 | 49728 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:35.458214998 CEST | 80 | 49727 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:36.008904934 CEST | 49728 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.010181904 CEST | 49729 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.015084028 CEST | 80 | 49729 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:36.015758038 CEST | 49729 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.015841961 CEST | 49729 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.020651102 CEST | 80 | 49729 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:36.054125071 CEST | 80 | 49728 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:36.946302891 CEST | 49729 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.947077990 CEST | 49730 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.951953888 CEST | 80 | 49730 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:36.952013969 CEST | 49730 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.952151060 CEST | 49730 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:36.957000971 CEST | 80 | 49730 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:36.994245052 CEST | 80 | 49729 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:37.040431976 CEST | 49730 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:37.041830063 CEST | 49731 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:37.046730995 CEST | 80 | 49731 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:37.046797991 CEST | 49731 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:37.046973944 CEST | 49731 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:37.051891088 CEST | 80 | 49731 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:37.086194992 CEST | 80 | 49730 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:38.836956978 CEST | 49731 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:38.838020086 CEST | 49732 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:38.842822075 CEST | 80 | 49732 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:38.842885971 CEST | 49732 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:38.843039989 CEST | 49732 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:38.847934961 CEST | 80 | 49732 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:38.882231951 CEST | 80 | 49731 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:39.055731058 CEST | 49732 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:39.057466984 CEST | 49733 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:39.062407017 CEST | 80 | 49733 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:39.062469006 CEST | 49733 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:39.062575102 CEST | 49733 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:39.067308903 CEST | 80 | 49733 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:39.102122068 CEST | 80 | 49732 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:43.314244032 CEST | 80 | 49722 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:43.314311028 CEST | 49722 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:43.427329063 CEST | 80 | 49723 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:43.427457094 CEST | 49723 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:43.915100098 CEST | 49733 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:43.915973902 CEST | 49734 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:43.920722961 CEST | 80 | 49734 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:43.920883894 CEST | 49734 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:43.921128035 CEST | 49734 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:43.925879955 CEST | 80 | 49734 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:43.966216087 CEST | 80 | 49733 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:46.821400881 CEST | 49734 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:46.822319984 CEST | 49735 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:46.827873945 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:46.827938080 CEST | 49735 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:46.828227997 CEST | 49735 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:46.835535049 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:46.871234894 CEST | 80 | 49734 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:48.140768051 CEST | 80 | 49724 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:48.140908957 CEST | 49724 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:52.680901051 CEST | 49735 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:52.682863951 CEST | 49736 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:52.687736988 CEST | 80 | 49736 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:52.690963030 CEST | 49736 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:52.694835901 CEST | 49736 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:52.699665070 CEST | 80 | 49736 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:52.726161957 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:53.305772066 CEST | 49736 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:53.306638002 CEST | 49737 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:53.311588049 CEST | 80 | 49737 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:53.311687946 CEST | 49737 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:53.311892033 CEST | 49737 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:53.316751957 CEST | 80 | 49737 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:53.354922056 CEST | 80 | 49736 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:54.641117096 CEST | 80 | 49725 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:54.641881943 CEST | 49725 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:54.642611027 CEST | 80 | 49726 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:54.642683029 CEST | 49726 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:56.511476994 CEST | 80 | 49727 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:56.511580944 CEST | 49727 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:56.801109076 CEST | 80 | 49728 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:56.801229954 CEST | 49728 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:57.395764112 CEST | 80 | 49729 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:57.396831036 CEST | 49729 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:58.328788996 CEST | 80 | 49730 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:58.328936100 CEST | 49730 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:39:58.406816006 CEST | 80 | 49731 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:39:58.406900883 CEST | 49731 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:00.269721031 CEST | 80 | 49732 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:00.270951033 CEST | 49732 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:00.422251940 CEST | 80 | 49733 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:00.422327995 CEST | 49733 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:00.587114096 CEST | 49737 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:00.589857101 CEST | 49738 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:00.594702005 CEST | 80 | 49738 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:00.594793081 CEST | 49738 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:00.594929934 CEST | 49738 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:00.599710941 CEST | 80 | 49738 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:00.634085894 CEST | 80 | 49737 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:05.301620007 CEST | 80 | 49734 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:05.301819086 CEST | 49734 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:08.807569027 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:08.807593107 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:08.807684898 CEST | 49735 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:08.807684898 CEST | 49735 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:08.807763100 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:08.812516928 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:08.812532902 CEST | 49735 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:08.817303896 CEST | 80 | 49735 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:13.805825949 CEST | 49738 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:13.807054996 CEST | 49739 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:13.811992884 CEST | 80 | 49739 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:13.812057972 CEST | 49739 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:13.812184095 CEST | 49739 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:13.817377090 CEST | 80 | 49739 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:13.858182907 CEST | 80 | 49738 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:14.063249111 CEST | 80 | 49736 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:14.065129042 CEST | 49736 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:14.693842888 CEST | 80 | 49737 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:14.693948030 CEST | 49737 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:21.954080105 CEST | 80 | 49738 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:21.954907894 CEST | 49738 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:22.010169983 CEST | 49740 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:22.010289907 CEST | 49739 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:22.015058041 CEST | 80 | 49740 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:22.015410900 CEST | 49740 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:22.015532017 CEST | 49740 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:22.020276070 CEST | 80 | 49740 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:22.058126926 CEST | 80 | 49739 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:35.192137003 CEST | 80 | 49739 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:35.192184925 CEST | 49739 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:43.428574085 CEST | 80 | 49740 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:43.428657055 CEST | 49740 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:43.429476976 CEST | 49740 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:43.430634975 CEST | 49741 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:43.434362888 CEST | 80 | 49740 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:43.435527086 CEST | 80 | 49741 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:43.435611963 CEST | 49741 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:43.435986996 CEST | 49741 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:43.440790892 CEST | 80 | 49741 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:53.462213993 CEST | 49741 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:53.463259935 CEST | 49742 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:53.468148947 CEST | 80 | 49742 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:53.468226910 CEST | 49742 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:53.468368053 CEST | 49742 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:53.473231077 CEST | 80 | 49742 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:53.510170937 CEST | 80 | 49741 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:54.838046074 CEST | 49743 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:54.838066101 CEST | 49742 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:54.842948914 CEST | 80 | 49743 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:54.843151093 CEST | 49743 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:54.843425035 CEST | 49743 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:54.848257065 CEST | 80 | 49743 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:54.886169910 CEST | 80 | 49742 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:55.321584940 CEST | 49743 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:55.322510958 CEST | 49744 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:55.327377081 CEST | 80 | 49744 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:55.327459097 CEST | 49744 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:55.327585936 CEST | 49744 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:55.332391024 CEST | 80 | 49744 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:55.370213985 CEST | 80 | 49743 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:59.821717978 CEST | 49744 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:59.822807074 CEST | 49745 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:59.827630043 CEST | 80 | 49745 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:59.827694893 CEST | 49745 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:59.827903032 CEST | 49745 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:40:59.832624912 CEST | 80 | 49745 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:40:59.876142979 CEST | 80 | 49744 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:00.040386915 CEST | 49745 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:00.043204069 CEST | 49746 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:00.048158884 CEST | 80 | 49746 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:00.051306009 CEST | 49746 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:00.051561117 CEST | 49746 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:00.056466103 CEST | 80 | 49746 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:00.087359905 CEST | 80 | 49745 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:03.196584940 CEST | 49746 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:03.197675943 CEST | 49747 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:03.203718901 CEST | 80 | 49747 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:03.203794003 CEST | 49747 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:03.204015970 CEST | 49747 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:03.209480047 CEST | 80 | 49747 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:03.242098093 CEST | 80 | 49746 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:04.829632998 CEST | 80 | 49741 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:04.829854965 CEST | 49741 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:06.774708033 CEST | 49747 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:06.775453091 CEST | 49748 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:06.780663967 CEST | 80 | 49748 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:06.782845020 CEST | 49748 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:06.783065081 CEST | 49748 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:06.790354013 CEST | 80 | 49748 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:06.822889090 CEST | 80 | 49747 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:12.916960001 CEST | 49748 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:12.919059038 CEST | 49749 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:12.926146984 CEST | 80 | 49749 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:12.927201986 CEST | 49749 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:12.927422047 CEST | 49749 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:12.935648918 CEST | 80 | 49749 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:12.966082096 CEST | 80 | 49748 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:14.829931021 CEST | 80 | 49742 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:14.830029011 CEST | 49742 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:16.224311113 CEST | 80 | 49743 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:16.224540949 CEST | 49743 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:16.690071106 CEST | 80 | 49744 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:16.690290928 CEST | 49744 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:17.493505001 CEST | 49749 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:17.494364023 CEST | 49750 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:17.499212980 CEST | 80 | 49750 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:17.499280930 CEST | 49750 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:17.499458075 CEST | 49750 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:17.504297972 CEST | 80 | 49750 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:17.542198896 CEST | 80 | 49749 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:20.354146957 CEST | 49751 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:20.354150057 CEST | 49750 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:20.359076023 CEST | 80 | 49751 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:20.359348059 CEST | 49751 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:20.359536886 CEST | 49751 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:20.364293098 CEST | 80 | 49751 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:20.406156063 CEST | 80 | 49750 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:21.226818085 CEST | 80 | 49745 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:21.226876020 CEST | 49745 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:21.408334970 CEST | 80 | 49746 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:21.408521891 CEST | 49746 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:22.784735918 CEST | 49751 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:22.785234928 CEST | 49752 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:22.790059090 CEST | 80 | 49752 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:22.790132999 CEST | 49752 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:22.790214062 CEST | 49752 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:22.794979095 CEST | 80 | 49752 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:22.830137968 CEST | 80 | 49751 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:24.564575911 CEST | 80 | 49747 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:24.564654112 CEST | 49747 | 80 | 192.168.2.10 | 185.167.61.13 |
Oct 5, 2024 14:41:28.174010992 CEST | 80 | 49748 | 185.167.61.13 | 192.168.2.10 |
Oct 5, 2024 14:41:28.174120903 CEST | 49748 | 80 | 192.168.2.10 | 185.167.61.13 |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.10 | 49709 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:37:17.304004908 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.10 | 49711 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:37:38.684227943 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.10 | 49712 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:38:00.081015110 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.10 | 49714 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:38:21.464966059 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.10 | 49715 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:38:41.843748093 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.10 | 49716 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:38:42.390094042 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.10 | 49717 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:38:53.451989889 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.10 | 49718 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:38:53.702023029 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.10 | 49719 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:03.504206896 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.10 | 49720 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:08.468357086 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.10 | 49721 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:11.175188065 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.10 | 49722 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:21.905917883 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.10 | 49723 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:22.047116041 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.10 | 49724 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:26.766469002 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.10 | 49725 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:33.249833107 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.10 | 49726 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:33.295675993 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.10 | 49727 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:35.015189886 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.10 | 49728 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:35.419152975 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.10 | 49729 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:36.015841961 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.10 | 49730 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:36.952151060 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.10 | 49731 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:37.046973944 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.10 | 49732 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:38.843039989 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.10 | 49733 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:39.062575102 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.10 | 49734 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:43.921128035 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.10 | 49735 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:46.828227997 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.10 | 49736 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:52.694835901 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.10 | 49737 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:39:53.311892033 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.10 | 49738 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:00.594929934 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.10 | 49739 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:13.812184095 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.10 | 49740 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:22.015532017 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.10 | 49741 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:43.435986996 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.10 | 49742 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:53.468368053 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.10 | 49743 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:54.843425035 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.10 | 49744 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:55.327585936 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.10 | 49745 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:40:59.827903032 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.10 | 49746 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:41:00.051561117 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.10 | 49747 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:41:03.204015970 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.10 | 49748 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:41:06.783065081 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.10 | 49749 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:41:12.927422047 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.10 | 49750 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:41:17.499458075 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.10 | 49751 | 185.167.61.13 | 80 | 8080 | C:\Users\user\Desktop\IMG_3322101870451.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:41:20.359536886 CEST | 78 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
41 | 192.168.2.10 | 49752 | 185.167.61.13 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 5, 2024 14:41:22.790214062 CEST | 78 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 08:37:15 |
Start date: | 05/10/2024 |
Path: | C:\Users\user\Desktop\IMG_3322101870451.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xf20000 |
File size: | 254'328 bytes |
MD5 hash: | 8290AB3945CFC9355B5F18D4C4262CEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Function 01801C0A Relevance: .6, Instructions: 590COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01801C4C Relevance: .4, Instructions: 353COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01805A5C Relevance: .2, Instructions: 209COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01805A96 Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0180752D Relevance: .5, Instructions: 493COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01802DAC Relevance: .4, Instructions: 373COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01804D51 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018039E0 Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800A90 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0180354A Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01807858 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01802C10 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800D46 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0145D654 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018009E0 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01801AAE Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01802C00 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0145D64F Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01803CAF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800D14 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01803CDC Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0145D005 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0145D01D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800C46 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800A08 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800A81 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01805670 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018036BE Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800991 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018016DB Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018009A0 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01805680 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800C26 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800860 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800C38 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018056C0 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0180083A Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01802D9B Relevance: .0, Instructions: 10COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01800848 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01802554 Relevance: .4, Instructions: 377COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01801704 Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|