Windows
Analysis Report
FyDBXJE74v.exe
Overview
General Information
Sample name: | FyDBXJE74v.exerenamed because original name is a hash value |
Original sample name: | 497859eed941e073a43e8291908e6494.exe |
Analysis ID: | 1532550 |
MD5: | 497859eed941e073a43e8291908e6494 |
SHA1: | 8136e8e148deeb6c9d18f8300f47e7b3a43b4290 |
SHA256: | 8484619768f32fb9368cc46bc15a16cf99c98e95a2a605068adf5dd71090e0c7 |
Tags: | exeSocks5Systemzuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- FyDBXJE74v.exe (PID: 7524 cmdline:
"C:\Users\ user\Deskt op\FyDBXJE 74v.exe" MD5: 497859EED941E073A43E8291908E6494) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- wsbgrgh (PID: 7956 cmdline:
C:\Users\u ser\AppDat a\Roaming\ wsbgrgh MD5: 497859EED941E073A43E8291908E6494)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://nwgrus.ru/tmp/index.php", "http://tech-servers.in.net/tmp/index.php", "http://unicea.ws/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-13T17:02:34.009237+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49736 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:35.260507+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49737 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:36.675576+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49738 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:37.879607+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49739 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:39.110270+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49740 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:40.315350+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:41.719962+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49742 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:43.127590+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49743 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:44.418920+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49744 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:45.652054+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49745 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:46.866023+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:48.088816+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49747 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:49.324243+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49748 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:50.631889+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49749 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:51.847825+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49750 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:53.053024+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:54.269862+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:55.483123+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49753 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:56.676550+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49754 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:58.136557+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49756 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:59.375455+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49768 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:00.567671+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49774 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:01.795567+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49785 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:03.055928+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49794 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:04.302004+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49802 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:05.654853+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49810 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:06.907800+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49819 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:08.190298+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49828 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:09.445903+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49836 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:10.849624+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49845 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:12.157474+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49856 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:13.543698+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49864 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:14.797727+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49873 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:15.976762+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49882 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:17.244744+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49890 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:18.612428+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49896 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:28.029229+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50038 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:34.140280+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50039 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:39.391353+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50040 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:44.509898+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50041 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:50.069868+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50042 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:55.760104+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50043 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:05:01.475818+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50044 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:05:06.987167+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50045 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:11.639706+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50046 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:16.825285+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50047 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:23.062242+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50048 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:28.723373+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50049 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:34.540144+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50050 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:40.583026+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50051 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:45.894239+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50052 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:50.727891+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50053 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:56.082119+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50054 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:06:01.188741+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50055 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:06:06.774445+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50056 | 109.175.29.39 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_00403277 | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 5_2_00401514 | |
Source: | Code function: | 5_2_00402F97 | |
Source: | Code function: | 5_2_00401542 | |
Source: | Code function: | 5_2_00403247 | |
Source: | Code function: | 5_2_00401549 | |
Source: | Code function: | 5_2_0040324F | |
Source: | Code function: | 5_2_00403256 | |
Source: | Code function: | 5_2_00401557 | |
Source: | Code function: | 5_2_0040326C | |
Source: | Code function: | 5_2_00403277 | |
Source: | Code function: | 5_2_004014FE | |
Source: | Code function: | 5_2_00403290 |
Source: | Code function: | 0_2_00415F50 | |
Source: | Code function: | 5_2_00415F50 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_02CA0A22 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_02BC1550 | |
Source: | Code function: | 0_2_02C9D7E5 | |
Source: | Code function: | 0_2_02CA447D | |
Source: | Code function: | 0_2_02CA331C | |
Source: | Code function: | 0_2_02CA2855 | |
Source: | Code function: | 5_2_004014E9 | |
Source: | Code function: | 5_2_004032AB | |
Source: | Code function: | 5_2_02DE1550 | |
Source: | Code function: | 5_2_02E535B5 | |
Source: | Code function: | 5_2_02E5198D | |
Source: | Code function: | 5_2_02E52454 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_02BC0D90 | |
Source: | Code function: | 0_2_02BC092B | |
Source: | Code function: | 0_2_02CA02FF | |
Source: | Code function: | 5_2_02DE0D90 | |
Source: | Code function: | 5_2_02DE092B | |
Source: | Code function: | 5_2_02E4F437 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00415F50 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 511 Security Software Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 12 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 2 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 3 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 113 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Software Packing | Cached Domain Credentials | 13 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Win32.Ransomware.LockbitCrypt | ||
41% | Virustotal | Browse | ||
100% | Avira | HEUR/AGEN.1312571 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1312571 | ||
100% | Joe Sandbox ML | |||
39% | ReversingLabs | Win32.Ransomware.LockbitCrypt | ||
41% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
17% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
2% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
nwgrus.ru | 78.89.199.216 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
109.175.29.39 | unknown | Bosnia and Herzegowina | 9146 | BIHNETBIHNETAutonomusSystemBA | true | |
78.89.199.216 | nwgrus.ru | Kuwait | 29357 | WATANIYATELECOM-ASKW | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1532550 |
Start date and time: | 2024-10-13 17:01:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | FyDBXJE74v.exerenamed because original name is a hash value |
Original Sample Name: | 497859eed941e073a43e8291908e6494.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@2/2@4/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
11:02:29 | API Interceptor | |
16:02:28 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
109.175.29.39 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | Babuk, Djvu, PrivateLoader | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Glupteba, LummaC Stealer, Mars Stealer, RedLine, SmokeLoader | Browse |
| ||
78.89.199.216 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, AsyncRAT, Go Injector, LummaC Stealer, SmokeLoader, VenomRAT | Browse |
| ||
Get hash | malicious | Djvu | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | LummaC, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Mars Stealer, PureLog Stealer, RedLine, SmokeLoader, Stealc | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
nwgrus.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
WATANIYATELECOM-ASKW | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
BIHNETBIHNETAutonomusSystemBA | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | CryptOne, SmokeLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 296960 |
Entropy (8bit): | 5.617071692398502 |
Encrypted: | false |
SSDEEP: | 3072:ohQBX24upVVQN58sfUAJ5IpCyxF9DavUjZXFUCIqzpZAqa8i:oqFseN58u8/4OXFVIqzpZAqaR |
MD5: | 497859EED941E073A43E8291908E6494 |
SHA1: | 8136E8E148DEEB6C9D18F8300F47E7B3A43B4290 |
SHA-256: | 8484619768F32FB9368CC46BC15A16CF99C98E95A2A605068ADF5DD71090E0C7 |
SHA-512: | 5E5AF6D5D1802AAD3160E8A139134C5CC39D6D3B10AE0ACBE686A1FEF9944D36CBA20081781ABFEAD68F3B6E37DE4182178FA293C16B6994473A6D869C9D7A06 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.617071692398502 |
TrID: |
|
File name: | FyDBXJE74v.exe |
File size: | 296'960 bytes |
MD5: | 497859eed941e073a43e8291908e6494 |
SHA1: | 8136e8e148deeb6c9d18f8300f47e7b3a43b4290 |
SHA256: | 8484619768f32fb9368cc46bc15a16cf99c98e95a2a605068adf5dd71090e0c7 |
SHA512: | 5e5af6d5d1802aad3160e8a139134c5cc39d6d3b10ae0acbe686a1fef9944d36cba20081781abfead68f3b6e37de4182178fa293c16b6994473a6d869c9d7a06 |
SSDEEP: | 3072:ohQBX24upVVQN58sfUAJ5IpCyxF9DavUjZXFUCIqzpZAqa8i:oqFseN58u8/4OXFVIqzpZAqaR |
TLSH: | D754D78252E56C03EFB64B328E39D9D8262EFD724E3572DEB1047A0F147B1A5E513B12 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9..K}...}...}...c.x.f...c.i.m...c...7...Z...z...}.......c.v.|...c.h.|...c.m.|...Rich}...........PE..L...|OXe.................T. |
Icon Hash: | 738733b18b838be4 |
Entrypoint: | 0x4018e4 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x65584F7C [Sat Nov 18 05:45:32 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | 67def8961050d10da5ff74312b7f0aec |
Instruction |
---|
call 00007FD9EC80A790h |
jmp 00007FD9EC80708Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [0041B3D0h], eax |
mov dword ptr [0041B3CCh], ecx |
mov dword ptr [0041B3C8h], edx |
mov dword ptr [0041B3C4h], ebx |
mov dword ptr [0041B3C0h], esi |
mov dword ptr [0041B3BCh], edi |
mov word ptr [0041B3E8h], ss |
mov word ptr [0041B3DCh], cs |
mov word ptr [0041B3B8h], ds |
mov word ptr [0041B3B4h], es |
mov word ptr [0041B3B0h], fs |
mov word ptr [0041B3ACh], gs |
pushfd |
pop dword ptr [0041B3E0h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [0041B3D4h], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [0041B3D8h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [0041B3E4h], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [0041B320h], 00010001h |
mov eax, dword ptr [0041B3D8h] |
mov dword ptr [0041B2D4h], eax |
mov dword ptr [0041B2C8h], C0000409h |
mov dword ptr [0041B2CCh], 00000001h |
mov eax, dword ptr [0041A008h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [0041A00Ch] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000E8h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x18724 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x2722000 | 0x29810 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x17000 | 0x188 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x1536f | 0x15400 | d9f6f2e355da13b0605c446f69f8ab36 | False | 0.8254940257352941 | data | 7.557544545964827 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x17000 | 0x2026 | 0x2200 | 015eea173e4482b2da1d23e4e48ecb46 | False | 0.36144301470588236 | data | 5.426629733611342 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x1a000 | 0x26fff7c | 0x1400 | c0c063eabbb97a813e07a4dc77f29fa1 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.kibojis | 0x271a000 | 0x4400 | 0x3800 | b211778b80f6d441b6cf61ada776fc6d | False | 0.0025809151785714285 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.xeto | 0x271f000 | 0x2800 | 0x2800 | 1276481102f218c981e0324180bafd9f | False | 0.00322265625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x2722000 | 0x29810 | 0x29a00 | ac1373b8d4a9736ee5e17d763fc3f5d3 | False | 0.3729588963963964 | data | 4.765772210605211 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
AFX_DIALOG_LAYOUT | 0x27400a8 | 0x2 | data | 5.0 | ||
RT_CURSOR | 0x27400b0 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.4276315789473684 | ||
RT_CURSOR | 0x27401f8 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x2740328 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_CURSOR | 0x27428f8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.31023454157782515 | ||
RT_CURSOR | 0x27437b8 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x27438e8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_ICON | 0x2722e00 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.5674307036247335 |
RT_ICON | 0x2723ca8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.6376353790613718 |
RT_ICON | 0x2724550 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.6849078341013825 |
RT_ICON | 0x2724c18 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.7456647398843931 |
RT_ICON | 0x2725180 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | Turkish | Turkey | 0.512863070539419 |
RT_ICON | 0x2727728 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | Turkish | Turkey | 0.6137429643527205 |
RT_ICON | 0x27287d0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | Turkish | Turkey | 0.6163934426229508 |
RT_ICON | 0x2729158 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | Turkish | Turkey | 0.7553191489361702 |
RT_ICON | 0x2729638 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.3363539445628998 |
RT_ICON | 0x272a4e0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.523014440433213 |
RT_ICON | 0x272ad88 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.5829493087557603 |
RT_ICON | 0x272b450 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6315028901734104 |
RT_ICON | 0x272b9b8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.42728215767634853 |
RT_ICON | 0x272df60 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.5045081967213115 |
RT_ICON | 0x272e8e8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.5026595744680851 |
RT_ICON | 0x272edb8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.3350213219616205 |
RT_ICON | 0x272fc60 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.388086642599278 |
RT_ICON | 0x2730508 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.39285714285714285 |
RT_ICON | 0x2730bd0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.40534682080924855 |
RT_ICON | 0x2731138 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Turkish | Turkey | 0.21950207468879668 |
RT_ICON | 0x27336e0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Turkish | Turkey | 0.2474202626641651 |
RT_ICON | 0x2734788 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Turkish | Turkey | 0.2815573770491803 |
RT_ICON | 0x2735110 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Turkish | Turkey | 0.31117021276595747 |
RT_ICON | 0x27355f0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.39285714285714285 |
RT_ICON | 0x2736498 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5537003610108303 |
RT_ICON | 0x2736d40 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.6226958525345622 |
RT_ICON | 0x2737408 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6372832369942196 |
RT_ICON | 0x2737970 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.425422138836773 |
RT_ICON | 0x2738a18 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.4209016393442623 |
RT_ICON | 0x27393a0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.46187943262411346 |
RT_ICON | 0x2739870 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.279317697228145 |
RT_ICON | 0x273a718 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.3664259927797834 |
RT_ICON | 0x273afc0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.3773041474654378 |
RT_ICON | 0x273b688 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.3764450867052023 |
RT_ICON | 0x273bbf0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.2587136929460581 |
RT_ICON | 0x273e198 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.27345215759849906 |
RT_ICON | 0x273f240 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.28852459016393445 |
RT_ICON | 0x273fbc8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.32180851063829785 |
RT_STRING | 0x2746070 | 0xaa | data | 0.5588235294117647 | ||
RT_STRING | 0x2746120 | 0x600 | data | 0.4361979166666667 | ||
RT_STRING | 0x2746720 | 0x460 | data | 0.45 | ||
RT_STRING | 0x2746b80 | 0x64a | data | 0.4360248447204969 | ||
RT_STRING | 0x27471d0 | 0x7b8 | data | 0.4185222672064777 | ||
RT_STRING | 0x2747988 | 0x6d0 | data | 0.4294724770642202 | ||
RT_STRING | 0x2748058 | 0x76c | data | 0.42526315789473684 | ||
RT_STRING | 0x27487c8 | 0x606 | data | 0.4455252918287938 | ||
RT_STRING | 0x2748dd0 | 0x7c2 | data | 0.42245720040281975 | ||
RT_STRING | 0x2749598 | 0x810 | data | 0.42102713178294576 | ||
RT_STRING | 0x2749da8 | 0x584 | data | 0.4461756373937677 | ||
RT_STRING | 0x274a330 | 0x74c | data | 0.4234475374732334 | ||
RT_STRING | 0x274aa80 | 0x710 | data | 0.4303097345132743 | ||
RT_STRING | 0x274b190 | 0x5f6 | data | 0.4325032765399738 | ||
RT_STRING | 0x274b788 | 0x88 | data | 0.625 | ||
RT_GROUP_CURSOR | 0x27401e0 | 0x14 | data | 1.15 | ||
RT_GROUP_CURSOR | 0x27428d0 | 0x22 | data | 1.088235294117647 | ||
RT_GROUP_CURSOR | 0x27437a0 | 0x14 | data | 1.25 | ||
RT_GROUP_CURSOR | 0x2745e90 | 0x22 | data | 1.088235294117647 | ||
RT_GROUP_ICON | 0x272ed50 | 0x68 | data | Turkish | Turkey | 0.7019230769230769 |
RT_GROUP_ICON | 0x2735578 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x2740030 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x27295c0 | 0x76 | data | Turkish | Turkey | 0.6610169491525424 |
RT_GROUP_ICON | 0x2739808 | 0x68 | data | Turkish | Turkey | 0.7211538461538461 |
RT_VERSION | 0x2745eb8 | 0x1b4 | data | 0.5871559633027523 |
DLL | Import |
---|---|
KERNEL32.dll | OpenJobObjectA, ReadConsoleA, InterlockedDecrement, GlobalSize, SetDefaultCommConfigW, QueryDosDeviceA, InterlockedCompareExchange, GetComputerNameW, SetEvent, GetNumaAvailableMemoryNode, FreeEnvironmentStringsA, GetModuleHandleW, GetConsoleAliasesLengthA, SetCommState, GetConsoleWindow, ReadConsoleOutputW, GetVersionExW, GetStringTypeExW, HeapDestroy, GetFileAttributesA, GetTimeFormatW, DeleteVolumeMountPointA, GetFileAttributesW, GetBinaryTypeA, DisconnectNamedPipe, LCMapStringA, GetLastError, GetProcAddress, MoveFileW, SetStdHandle, GetNumaHighestNodeNumber, LoadLibraryA, LocalAlloc, WritePrivateProfileStringA, GetModuleFileNameA, BuildCommDCBA, FatalAppExitA, GetShortPathNameW, SetCalendarInfoA, FindAtomW, SearchPathW, GetConsoleAliasExesLengthA, SetConsoleMode, PulseEvent, HeapAlloc, MultiByteToWideChar, Sleep, ExitProcess, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapFree, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, WriteFile, GetStdHandle, GetCPInfo, InterlockedIncrement, GetACP, GetOEMCP, IsValidCodePage, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, InitializeCriticalSectionAndSpinCount, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, HeapSize |
GDI32.dll | GetBoundsRect |
ADVAPI32.dll | ClearEventLogW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkish | Turkey |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-13T17:02:34.009237+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49736 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:35.260507+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49737 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:36.675576+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49738 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:37.879607+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49739 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:39.110270+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49740 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:40.315350+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49741 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:41.719962+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49742 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:43.127590+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49743 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:44.418920+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49744 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:45.652054+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49745 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:46.866023+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49746 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:48.088816+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49747 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:49.324243+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49748 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:50.631889+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49749 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:51.847825+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49750 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:53.053024+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49751 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:54.269862+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49752 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:55.483123+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49753 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:56.676550+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49754 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:58.136557+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49756 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:02:59.375455+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49768 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:00.567671+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49774 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:01.795567+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49785 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:03.055928+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49794 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:04.302004+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49802 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:05.654853+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49810 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:06.907800+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49819 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:08.190298+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49828 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:09.445903+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49836 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:10.849624+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49845 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:12.157474+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49856 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:13.543698+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49864 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:14.797727+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49873 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:15.976762+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49882 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:17.244744+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49890 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:03:18.612428+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49896 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:28.029229+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50038 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:34.140280+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50039 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:39.391353+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50040 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:44.509898+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50041 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:50.069868+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50042 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:04:55.760104+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50043 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:05:01.475818+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50044 | 78.89.199.216 | 80 | TCP |
2024-10-13T17:05:06.987167+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50045 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:11.639706+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50046 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:16.825285+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50047 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:23.062242+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50048 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:28.723373+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50049 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:34.540144+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50050 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:40.583026+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50051 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:45.894239+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50052 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:50.727891+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50053 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:05:56.082119+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50054 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:06:01.188741+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50055 | 109.175.29.39 | 80 | TCP |
2024-10-13T17:06:06.774445+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50056 | 109.175.29.39 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 13, 2024 17:02:32.560286999 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:32.566359997 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:32.566431046 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:32.576184988 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:32.576219082 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:32.581362963 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:32.581377029 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:34.009001017 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:34.009186029 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:34.009237051 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:34.013793945 CEST | 49736 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:34.015855074 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:34.018697023 CEST | 80 | 49736 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:34.020775080 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:34.020849943 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:34.020936966 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:34.020936966 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:34.025847912 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:34.026043892 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:35.259593964 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:35.259953976 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:35.260507107 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:35.260507107 CEST | 49737 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:35.263489008 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:35.266388893 CEST | 80 | 49737 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:35.268676043 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:35.268934011 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:35.269042015 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:35.269079924 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:35.273986101 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:35.274315119 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:36.674861908 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:36.675302982 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:36.675575972 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:36.675885916 CEST | 49738 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:36.680715084 CEST | 80 | 49738 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:36.683495045 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:36.688721895 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:36.688817024 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:36.688941956 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:36.688975096 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:36.694111109 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:36.694417953 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:37.879072905 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:37.879406929 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:37.879606962 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:37.879607916 CEST | 49739 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:37.882751942 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:37.884685993 CEST | 80 | 49739 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:37.887845993 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:37.887921095 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:37.888127089 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:37.888159037 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:37.893713951 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:37.893760920 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:39.110152006 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:39.110207081 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:39.110270023 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:39.110418081 CEST | 49740 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:39.112994909 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:39.115324974 CEST | 80 | 49740 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:39.118015051 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:39.118139982 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:39.118288040 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:39.118324041 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:39.123888016 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:39.124034882 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:40.314954042 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:40.315179110 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:40.315350056 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:40.315351009 CEST | 49741 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:40.318582058 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:40.320806980 CEST | 80 | 49741 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:40.323703051 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:40.323776960 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:40.323925018 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:40.323961020 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:40.329161882 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:40.329277992 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:41.718607903 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:41.719450951 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:41.719961882 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:41.719961882 CEST | 49742 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:41.723174095 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:41.725390911 CEST | 80 | 49742 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:41.728741884 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:41.729180098 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:41.729180098 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:41.729296923 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:41.734564066 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:41.734639883 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:43.127505064 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:43.127526999 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:43.127589941 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:43.127773046 CEST | 49743 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:43.132734060 CEST | 80 | 49743 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:43.186113119 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:43.191576958 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:43.191756964 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:43.191849947 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:43.191849947 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:43.197463036 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:43.197654009 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:44.418507099 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:44.418549061 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:44.418920040 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:44.419318914 CEST | 49744 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:44.422872066 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:44.425367117 CEST | 80 | 49744 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:44.428920984 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:44.429007053 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:44.429153919 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:44.429188013 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:44.434396029 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:44.434411049 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:45.651444912 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:45.651973963 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:45.652054071 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:45.652141094 CEST | 49745 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:45.655184984 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:45.658524990 CEST | 80 | 49745 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:45.661622047 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:45.661698103 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:45.661859989 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:45.661891937 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:45.669509888 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:45.669542074 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:46.864932060 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:46.865941048 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:46.866023064 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:46.866106033 CEST | 49746 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:46.871300936 CEST | 80 | 49746 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:46.873111010 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:46.881781101 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:46.882241964 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:46.882323980 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:46.882323980 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:46.888642073 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:46.888659954 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:48.087645054 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:48.088360071 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:48.088815928 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:48.088815928 CEST | 49747 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:48.092044115 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:48.094264984 CEST | 80 | 49747 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:48.097707033 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:48.098006964 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:48.098006964 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:48.098058939 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:48.104764938 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:48.105384111 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:49.323573112 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:49.323952913 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:49.324243069 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:49.346019030 CEST | 49748 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:49.351309061 CEST | 80 | 49748 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:49.375056982 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:49.380335093 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:49.380414009 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:49.380553007 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:49.380609989 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:49.385657072 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:49.386015892 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:50.630939007 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:50.631422997 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:50.631889105 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:50.631889105 CEST | 49749 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:50.634012938 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:50.637607098 CEST | 80 | 49749 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:50.639192104 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:50.639411926 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:50.639411926 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:50.639473915 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:50.645639896 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:50.645669937 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:51.846788883 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:51.847420931 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:51.847825050 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:51.847825050 CEST | 49750 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:51.850218058 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:51.854507923 CEST | 80 | 49750 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:51.856842995 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:51.857181072 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:51.857182026 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:51.857182026 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:51.862633944 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:51.863471031 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:53.051822901 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:53.052421093 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:53.053024054 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:53.053025007 CEST | 49751 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:53.055464983 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:53.058257103 CEST | 80 | 49751 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:53.060580015 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:53.060666084 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:53.060765028 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:53.060798883 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:53.066361904 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:53.066495895 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:54.269166946 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:54.269788027 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:54.269861937 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:54.269948959 CEST | 49752 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:54.272766113 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:54.274966002 CEST | 80 | 49752 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:54.277679920 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:54.277864933 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:54.277864933 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:54.277901888 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:54.283622980 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:54.283652067 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:55.482976913 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:55.483025074 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:55.483123064 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:55.483405113 CEST | 49753 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:55.485366106 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:55.488517046 CEST | 80 | 49753 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:55.490384102 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:55.490564108 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:55.490760088 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:55.490760088 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:55.496150017 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:55.496180058 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:56.675520897 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:56.676352978 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:56.676549911 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:56.676736116 CEST | 49754 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:56.678881884 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:56.681668997 CEST | 80 | 49754 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:56.683911085 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:56.684150934 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:56.685101032 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:56.685101986 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:56.690201044 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:56.690336943 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:58.136038065 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:58.136357069 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:58.136557102 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:58.136557102 CEST | 49756 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:58.139544010 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:58.141746998 CEST | 80 | 49756 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:58.144614935 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:58.144685030 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:58.144890070 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:58.144921064 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:58.150405884 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:58.150455952 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:59.375215054 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:59.375377893 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:59.375454903 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:59.375540018 CEST | 49768 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:59.380435944 CEST | 49774 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:59.380543947 CEST | 80 | 49768 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:59.385458946 CEST | 80 | 49774 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:59.385545969 CEST | 49774 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:59.385839939 CEST | 49774 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:59.385839939 CEST | 49774 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:02:59.391459942 CEST | 80 | 49774 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:02:59.391557932 CEST | 80 | 49774 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:00.567207098 CEST | 80 | 49774 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:00.567296982 CEST | 80 | 49774 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:00.567671061 CEST | 49774 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:00.567759991 CEST | 49774 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:00.570714951 CEST | 49785 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:00.573648930 CEST | 80 | 49774 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:00.576198101 CEST | 80 | 49785 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:00.580315113 CEST | 49785 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:00.580315113 CEST | 49785 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:00.583970070 CEST | 49785 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:00.586055994 CEST | 80 | 49785 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:00.589783907 CEST | 80 | 49785 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:01.794980049 CEST | 80 | 49785 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:01.795494080 CEST | 80 | 49785 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:01.795567036 CEST | 49785 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:01.795660973 CEST | 49785 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:01.800889015 CEST | 80 | 49785 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:01.815253019 CEST | 49794 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:01.820312023 CEST | 80 | 49794 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:01.820386887 CEST | 49794 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:01.839550972 CEST | 49794 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:01.839601040 CEST | 49794 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:01.844669104 CEST | 80 | 49794 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:01.844700098 CEST | 80 | 49794 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:03.054527998 CEST | 80 | 49794 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:03.055840015 CEST | 80 | 49794 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:03.055927992 CEST | 49794 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:03.056003094 CEST | 49794 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:03.058851957 CEST | 49802 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:03.062767982 CEST | 80 | 49794 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:03.064526081 CEST | 80 | 49802 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:03.064608097 CEST | 49802 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:03.064747095 CEST | 49802 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:03.064793110 CEST | 49802 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:03.070024014 CEST | 80 | 49802 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:03.070051908 CEST | 80 | 49802 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:04.301119089 CEST | 80 | 49802 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:04.301798105 CEST | 80 | 49802 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:04.302004099 CEST | 49802 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:04.302005053 CEST | 49802 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:04.304913998 CEST | 49810 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:04.308376074 CEST | 80 | 49802 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:04.311651945 CEST | 80 | 49810 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:04.311893940 CEST | 49810 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:04.311893940 CEST | 49810 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:04.311893940 CEST | 49810 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:04.317286968 CEST | 80 | 49810 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:04.317437887 CEST | 80 | 49810 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:05.654290915 CEST | 80 | 49810 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:05.654663086 CEST | 80 | 49810 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:05.654853106 CEST | 49810 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:05.655349970 CEST | 49810 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:05.657824993 CEST | 49819 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:05.660471916 CEST | 80 | 49810 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:05.663247108 CEST | 80 | 49819 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:05.663341999 CEST | 49819 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:05.663530111 CEST | 49819 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:05.663530111 CEST | 49819 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:05.668842077 CEST | 80 | 49819 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:05.668947935 CEST | 80 | 49819 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:06.907557964 CEST | 80 | 49819 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:06.907571077 CEST | 80 | 49819 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:06.907799959 CEST | 49819 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:06.907800913 CEST | 49819 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:06.914355040 CEST | 80 | 49819 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:07.007589102 CEST | 49828 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:07.016840935 CEST | 80 | 49828 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:07.017020941 CEST | 49828 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:07.017113924 CEST | 49828 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:07.017113924 CEST | 49828 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:07.025096893 CEST | 80 | 49828 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:07.025106907 CEST | 80 | 49828 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:08.189560890 CEST | 80 | 49828 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:08.190237999 CEST | 80 | 49828 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:08.190298080 CEST | 49828 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:08.190323114 CEST | 49828 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:08.193116903 CEST | 49836 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:08.195164919 CEST | 80 | 49828 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:08.197978020 CEST | 80 | 49836 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:08.198158026 CEST | 49836 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:08.198231936 CEST | 49836 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:08.198271036 CEST | 49836 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:08.203502893 CEST | 80 | 49836 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:08.203511953 CEST | 80 | 49836 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:09.445173025 CEST | 80 | 49836 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:09.445723057 CEST | 80 | 49836 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:09.445903063 CEST | 49836 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:09.445947886 CEST | 49836 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:09.448765993 CEST | 49845 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:09.450809002 CEST | 80 | 49836 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:09.453763962 CEST | 80 | 49845 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:09.453846931 CEST | 49845 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:09.453996897 CEST | 49845 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:09.454029083 CEST | 49845 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:09.459274054 CEST | 80 | 49845 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:09.459302902 CEST | 80 | 49845 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:10.849014997 CEST | 80 | 49845 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:10.849464893 CEST | 80 | 49845 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:10.849623919 CEST | 49845 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:10.849623919 CEST | 49845 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:10.854516029 CEST | 80 | 49845 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:10.908196926 CEST | 49856 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:10.913525105 CEST | 80 | 49856 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:10.913723946 CEST | 49856 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:10.913814068 CEST | 49856 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:10.913814068 CEST | 49856 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:10.919189930 CEST | 80 | 49856 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:10.919346094 CEST | 80 | 49856 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:12.156563044 CEST | 80 | 49856 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:12.157402992 CEST | 80 | 49856 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:12.157474041 CEST | 49856 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:12.157555103 CEST | 49856 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:12.159852982 CEST | 49864 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:12.163930893 CEST | 80 | 49856 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:12.166126013 CEST | 80 | 49864 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:12.166194916 CEST | 49864 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:12.166707039 CEST | 49864 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:12.166743994 CEST | 49864 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:12.173557043 CEST | 80 | 49864 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:12.173567057 CEST | 80 | 49864 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:13.541337967 CEST | 80 | 49864 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:13.543642044 CEST | 80 | 49864 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:13.543698072 CEST | 49864 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:13.543751955 CEST | 49864 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:13.546578884 CEST | 49873 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:13.549077034 CEST | 80 | 49864 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:13.552542925 CEST | 80 | 49873 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:13.552614927 CEST | 49873 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:13.552712917 CEST | 49873 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:13.552731037 CEST | 49873 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:13.558378935 CEST | 80 | 49873 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:13.559869051 CEST | 80 | 49873 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:14.796607971 CEST | 80 | 49873 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:14.797261953 CEST | 80 | 49873 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:14.797727108 CEST | 49873 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:14.797727108 CEST | 49873 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:14.799767017 CEST | 49882 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:14.804766893 CEST | 80 | 49873 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:14.806061983 CEST | 80 | 49882 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:14.806171894 CEST | 49882 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:14.806333065 CEST | 49882 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:14.808027029 CEST | 49882 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:14.813427925 CEST | 80 | 49882 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:14.814769030 CEST | 80 | 49882 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:15.976577044 CEST | 80 | 49882 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:15.976699114 CEST | 80 | 49882 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:15.976762056 CEST | 49882 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:15.976871014 CEST | 49882 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:15.979903936 CEST | 49890 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:15.982258081 CEST | 80 | 49882 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:15.984932899 CEST | 80 | 49890 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:15.985001087 CEST | 49890 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:15.985131979 CEST | 49890 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:15.985166073 CEST | 49890 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:15.991193056 CEST | 80 | 49890 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:15.991204977 CEST | 80 | 49890 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:17.243900061 CEST | 80 | 49890 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:17.244674921 CEST | 80 | 49890 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:17.244744062 CEST | 49890 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:17.244831085 CEST | 49890 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:17.247486115 CEST | 49896 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:17.250129938 CEST | 80 | 49890 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:17.252420902 CEST | 80 | 49896 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:17.252489090 CEST | 49896 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:17.252623081 CEST | 49896 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:17.252645016 CEST | 49896 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:17.258215904 CEST | 80 | 49896 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:17.258349895 CEST | 80 | 49896 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:18.610971928 CEST | 80 | 49896 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:18.612153053 CEST | 80 | 49896 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:03:18.612427950 CEST | 49896 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:18.612427950 CEST | 49896 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:03:18.617937088 CEST | 80 | 49896 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:26.622078896 CEST | 50038 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:26.627234936 CEST | 80 | 50038 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:26.627331972 CEST | 50038 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:26.627563000 CEST | 50038 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:26.627563000 CEST | 50038 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:26.632961988 CEST | 80 | 50038 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:26.633461952 CEST | 80 | 50038 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:28.029043913 CEST | 80 | 50038 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:28.029155016 CEST | 80 | 50038 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:28.029184103 CEST | 80 | 50038 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:28.029228926 CEST | 50038 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:28.029230118 CEST | 50038 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:28.029321909 CEST | 50038 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:28.034533978 CEST | 80 | 50038 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:32.905869007 CEST | 50039 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:32.910968065 CEST | 80 | 50039 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:32.911178112 CEST | 50039 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:32.911271095 CEST | 50039 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:32.911271095 CEST | 50039 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:32.916522980 CEST | 80 | 50039 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:32.916553020 CEST | 80 | 50039 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:34.140043020 CEST | 80 | 50039 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:34.140116930 CEST | 80 | 50039 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:34.140280008 CEST | 50039 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:34.140326977 CEST | 50039 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:34.145302057 CEST | 80 | 50039 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:38.177248001 CEST | 50040 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:38.182682991 CEST | 80 | 50040 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:38.182797909 CEST | 50040 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:38.182934999 CEST | 50040 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:38.182967901 CEST | 50040 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:38.187859058 CEST | 80 | 50040 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:38.187906027 CEST | 80 | 50040 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:39.391208887 CEST | 80 | 50040 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:39.391261101 CEST | 80 | 50040 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:39.391352892 CEST | 50040 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:39.391530037 CEST | 50040 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:39.396564007 CEST | 80 | 50040 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:43.318149090 CEST | 50041 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:43.323273897 CEST | 80 | 50041 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:43.323587894 CEST | 50041 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:43.323587894 CEST | 50041 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:43.326654911 CEST | 50041 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:43.328644991 CEST | 80 | 50041 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:43.331577063 CEST | 80 | 50041 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:44.509438038 CEST | 80 | 50041 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:44.509701014 CEST | 80 | 50041 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:44.509897947 CEST | 50041 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:44.509897947 CEST | 50041 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:44.515180111 CEST | 80 | 50041 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:48.781563044 CEST | 50042 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:48.786787033 CEST | 80 | 50042 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:48.786886930 CEST | 50042 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:48.787045002 CEST | 50042 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:48.787079096 CEST | 50042 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:48.791924953 CEST | 80 | 50042 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:48.792181015 CEST | 80 | 50042 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:50.069689035 CEST | 80 | 50042 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:50.069770098 CEST | 80 | 50042 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:50.069868088 CEST | 50042 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:50.070045948 CEST | 50042 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:50.075010061 CEST | 80 | 50042 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:54.547180891 CEST | 50043 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:54.553078890 CEST | 80 | 50043 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:54.553184986 CEST | 50043 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:54.553349972 CEST | 50043 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:54.553381920 CEST | 50043 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:54.558430910 CEST | 80 | 50043 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:54.558443069 CEST | 80 | 50043 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:55.759946108 CEST | 80 | 50043 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:55.759998083 CEST | 80 | 50043 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:04:55.760103941 CEST | 50043 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:55.760232925 CEST | 50043 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:04:55.765090942 CEST | 80 | 50043 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:05:00.277189970 CEST | 50044 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:05:00.282720089 CEST | 80 | 50044 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:05:00.282829046 CEST | 50044 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:05:00.282948971 CEST | 50044 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:05:00.282968998 CEST | 50044 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:05:00.287978888 CEST | 80 | 50044 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:05:00.288203001 CEST | 80 | 50044 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:05:01.475089073 CEST | 80 | 50044 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:05:01.475759029 CEST | 80 | 50044 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:05:01.475817919 CEST | 50044 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:05:01.478200912 CEST | 50044 | 80 | 192.168.2.4 | 78.89.199.216 |
Oct 13, 2024 17:05:01.483138084 CEST | 80 | 50044 | 78.89.199.216 | 192.168.2.4 |
Oct 13, 2024 17:05:06.191832066 CEST | 50045 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:06.196970940 CEST | 80 | 50045 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:06.197058916 CEST | 50045 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:06.197248936 CEST | 50045 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:06.197290897 CEST | 50045 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:06.202508926 CEST | 80 | 50045 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:06.202537060 CEST | 80 | 50045 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:06.985910892 CEST | 80 | 50045 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:06.986984968 CEST | 80 | 50045 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:06.987166882 CEST | 50045 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:06.988662004 CEST | 50045 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:06.993597031 CEST | 80 | 50045 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:10.835773945 CEST | 50046 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:10.840984106 CEST | 80 | 50046 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:10.841243029 CEST | 50046 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:10.841243029 CEST | 50046 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:10.841335058 CEST | 50046 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:10.846546888 CEST | 80 | 50046 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:10.846924067 CEST | 80 | 50046 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:11.639252901 CEST | 80 | 50046 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:11.639487028 CEST | 80 | 50046 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:11.639705896 CEST | 50046 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:11.647552967 CEST | 50046 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:11.652762890 CEST | 80 | 50046 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:15.984630108 CEST | 50047 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:15.990159035 CEST | 80 | 50047 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:15.990240097 CEST | 50047 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:15.990360975 CEST | 50047 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:15.990394115 CEST | 50047 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:15.995266914 CEST | 80 | 50047 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:15.995516062 CEST | 80 | 50047 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:16.825057983 CEST | 80 | 50047 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:16.825107098 CEST | 80 | 50047 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:16.825134993 CEST | 80 | 50047 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:16.825284958 CEST | 50047 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:16.825285912 CEST | 50047 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:16.825385094 CEST | 50047 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:16.830280066 CEST | 80 | 50047 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:21.862819910 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:21.867942095 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:21.868038893 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:21.868154049 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:21.868169069 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:21.873539925 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:21.873651981 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:23.062016010 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:23.062063932 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:23.062093019 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:23.062119961 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:23.062242031 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:23.062242985 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:23.062242985 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:23.062374115 CEST | 50048 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:23.068356037 CEST | 80 | 50048 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:27.906042099 CEST | 50049 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:27.911626101 CEST | 80 | 50049 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:27.911860943 CEST | 50049 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:27.911989927 CEST | 50049 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:27.911989927 CEST | 50049 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:27.916857958 CEST | 80 | 50049 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:27.916979074 CEST | 80 | 50049 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:28.722807884 CEST | 80 | 50049 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:28.723186970 CEST | 80 | 50049 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:28.723372936 CEST | 50049 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:28.723373890 CEST | 50049 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:28.729046106 CEST | 80 | 50049 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:33.735925913 CEST | 50050 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:33.741894007 CEST | 80 | 50050 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:33.742140055 CEST | 50050 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:33.742224932 CEST | 50050 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:33.742224932 CEST | 50050 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:33.747045994 CEST | 80 | 50050 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:33.747529030 CEST | 80 | 50050 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:34.538161993 CEST | 80 | 50050 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:34.539958000 CEST | 80 | 50050 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:34.540143967 CEST | 50050 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:34.540144920 CEST | 50050 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:34.545373917 CEST | 80 | 50050 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:39.538078070 CEST | 50051 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:39.543400049 CEST | 80 | 50051 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:39.543508053 CEST | 50051 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:39.543642998 CEST | 50051 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:39.543716908 CEST | 50051 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:39.548437119 CEST | 80 | 50051 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:39.548661947 CEST | 80 | 50051 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:40.582794905 CEST | 80 | 50051 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:40.582844019 CEST | 80 | 50051 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:40.582873106 CEST | 80 | 50051 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:40.583025932 CEST | 50051 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:40.583025932 CEST | 50051 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:40.583025932 CEST | 50051 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:40.587959051 CEST | 80 | 50051 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:45.094003916 CEST | 50052 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:45.099169970 CEST | 80 | 50052 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:45.099252939 CEST | 50052 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:45.099385977 CEST | 50052 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:45.099427938 CEST | 50052 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:45.104536057 CEST | 80 | 50052 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:45.104568958 CEST | 80 | 50052 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:45.894088030 CEST | 80 | 50052 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:45.894177914 CEST | 80 | 50052 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:45.894238949 CEST | 50052 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:45.898165941 CEST | 50052 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:45.903048992 CEST | 80 | 50052 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:49.931529999 CEST | 50053 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:49.936806917 CEST | 80 | 50053 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:49.937036037 CEST | 50053 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:49.937036037 CEST | 50053 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:49.937036037 CEST | 50053 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:49.942228079 CEST | 80 | 50053 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:49.942256927 CEST | 80 | 50053 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:50.726022005 CEST | 80 | 50053 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:50.727740049 CEST | 80 | 50053 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:50.727890968 CEST | 50053 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:50.727978945 CEST | 50053 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:50.733088970 CEST | 80 | 50053 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:55.265965939 CEST | 50054 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:55.284661055 CEST | 80 | 50054 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:55.284992933 CEST | 50054 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:55.284992933 CEST | 50054 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:55.284993887 CEST | 50054 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:55.289963961 CEST | 80 | 50054 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:55.290066004 CEST | 80 | 50054 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:56.081058025 CEST | 80 | 50054 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:56.081747055 CEST | 80 | 50054 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:05:56.082118988 CEST | 50054 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:56.082118988 CEST | 50054 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:05:56.087374926 CEST | 80 | 50054 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:00.378408909 CEST | 50055 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:00.384020090 CEST | 80 | 50055 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:00.384150028 CEST | 50055 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:00.384315014 CEST | 50055 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:00.384349108 CEST | 50055 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:00.389223099 CEST | 80 | 50055 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:00.389451981 CEST | 80 | 50055 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:01.187680006 CEST | 80 | 50055 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:01.188643932 CEST | 80 | 50055 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:01.188740969 CEST | 50055 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:01.188834906 CEST | 50055 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:01.193869114 CEST | 80 | 50055 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:05.958173990 CEST | 50056 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:05.963494062 CEST | 80 | 50056 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:05.963730097 CEST | 50056 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:05.963869095 CEST | 50056 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:05.963869095 CEST | 50056 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:05.968836069 CEST | 80 | 50056 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:05.969316959 CEST | 80 | 50056 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:06.773713112 CEST | 80 | 50056 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:06.774359941 CEST | 80 | 50056 | 109.175.29.39 | 192.168.2.4 |
Oct 13, 2024 17:06:06.774445057 CEST | 50056 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:06.774727106 CEST | 50056 | 80 | 192.168.2.4 | 109.175.29.39 |
Oct 13, 2024 17:06:06.779587984 CEST | 80 | 50056 | 109.175.29.39 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 13, 2024 17:02:29.738940001 CEST | 62976 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 17:02:30.743540049 CEST | 62976 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 17:02:31.743417978 CEST | 62976 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 17:02:32.048778057 CEST | 53 | 62976 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 17:02:32.048799038 CEST | 53 | 62976 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 17:02:32.048810959 CEST | 53 | 62976 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 17:05:06.014777899 CEST | 61842 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 17:05:06.190921068 CEST | 53 | 61842 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 13, 2024 17:02:29.738940001 CEST | 192.168.2.4 | 1.1.1.1 | 0x6814 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 17:02:30.743540049 CEST | 192.168.2.4 | 1.1.1.1 | 0x6814 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 17:02:31.743417978 CEST | 192.168.2.4 | 1.1.1.1 | 0x6814 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 17:05:06.014777899 CEST | 192.168.2.4 | 1.1.1.1 | 0xe812 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 190.219.117.240 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 197.164.156.210 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 189.195.132.134 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 201.103.8.135 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 190.98.23.157 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 152.231.127.202 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048778057 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 190.219.117.240 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 197.164.156.210 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 189.195.132.134 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 201.103.8.135 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 190.98.23.157 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 152.231.127.202 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048799038 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 190.219.117.240 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 197.164.156.210 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 189.195.132.134 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 201.103.8.135 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 190.98.23.157 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 152.231.127.202 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:02:32.048810959 CEST | 1.1.1.1 | 192.168.2.4 | 0x6814 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 152.231.127.202 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 190.219.117.240 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 197.164.156.210 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 189.195.132.134 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 201.103.8.135 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 17:05:06.190921068 CEST | 1.1.1.1 | 192.168.2.4 | 0xe812 | No error (0) | 190.98.23.157 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:32.576184988 CEST | 282 | OUT | |
Oct 13, 2024 17:02:32.576219082 CEST | 267 | OUT | |
Oct 13, 2024 17:02:34.009001017 CEST | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49737 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:34.020936966 CEST | 282 | OUT | |
Oct 13, 2024 17:02:34.020936966 CEST | 261 | OUT | |
Oct 13, 2024 17:02:35.259593964 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49738 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:35.269042015 CEST | 283 | OUT | |
Oct 13, 2024 17:02:35.269079924 CEST | 183 | OUT | |
Oct 13, 2024 17:02:36.674861908 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49739 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:36.688941956 CEST | 283 | OUT | |
Oct 13, 2024 17:02:36.688975096 CEST | 282 | OUT | |
Oct 13, 2024 17:02:37.879072905 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49740 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:37.888127089 CEST | 281 | OUT | |
Oct 13, 2024 17:02:37.888159037 CEST | 289 | OUT | |
Oct 13, 2024 17:02:39.110152006 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49741 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:39.118288040 CEST | 279 | OUT | |
Oct 13, 2024 17:02:39.118324041 CEST | 305 | OUT | |
Oct 13, 2024 17:02:40.314954042 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49742 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:40.323925018 CEST | 283 | OUT | |
Oct 13, 2024 17:02:40.323961020 CEST | 218 | OUT | |
Oct 13, 2024 17:02:41.718607903 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49743 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:41.729180098 CEST | 279 | OUT | |
Oct 13, 2024 17:02:41.729296923 CEST | 217 | OUT | |
Oct 13, 2024 17:02:43.127505064 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49744 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:43.191849947 CEST | 278 | OUT | |
Oct 13, 2024 17:02:43.191849947 CEST | 339 | OUT | |
Oct 13, 2024 17:02:44.418507099 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49745 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:44.429153919 CEST | 280 | OUT | |
Oct 13, 2024 17:02:44.429188013 CEST | 266 | OUT | |
Oct 13, 2024 17:02:45.651444912 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49746 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:45.661859989 CEST | 283 | OUT | |
Oct 13, 2024 17:02:45.661891937 CEST | 218 | OUT | |
Oct 13, 2024 17:02:46.864932060 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49747 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:46.882323980 CEST | 279 | OUT | |
Oct 13, 2024 17:02:46.882323980 CEST | 128 | OUT | |
Oct 13, 2024 17:02:48.087645054 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49748 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:48.098006964 CEST | 283 | OUT | |
Oct 13, 2024 17:02:48.098058939 CEST | 262 | OUT | |
Oct 13, 2024 17:02:49.323573112 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49749 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:49.380553007 CEST | 281 | OUT | |
Oct 13, 2024 17:02:49.380609989 CEST | 196 | OUT | |
Oct 13, 2024 17:02:50.630939007 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49750 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:50.639411926 CEST | 280 | OUT | |
Oct 13, 2024 17:02:50.639473915 CEST | 290 | OUT | |
Oct 13, 2024 17:02:51.846788883 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49751 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:51.857182026 CEST | 278 | OUT | |
Oct 13, 2024 17:02:51.857182026 CEST | 202 | OUT | |
Oct 13, 2024 17:02:53.051822901 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49752 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:53.060765028 CEST | 282 | OUT | |
Oct 13, 2024 17:02:53.060798883 CEST | 234 | OUT | |
Oct 13, 2024 17:02:54.269166946 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49753 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:54.277864933 CEST | 279 | OUT | |
Oct 13, 2024 17:02:54.277901888 CEST | 234 | OUT | |
Oct 13, 2024 17:02:55.482976913 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49754 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:55.490760088 CEST | 279 | OUT | |
Oct 13, 2024 17:02:55.490760088 CEST | 173 | OUT | |
Oct 13, 2024 17:02:56.675520897 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49756 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:56.685101032 CEST | 278 | OUT | |
Oct 13, 2024 17:02:56.685101986 CEST | 131 | OUT | |
Oct 13, 2024 17:02:58.136038065 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49768 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:58.144890070 CEST | 278 | OUT | |
Oct 13, 2024 17:02:58.144921064 CEST | 228 | OUT | |
Oct 13, 2024 17:02:59.375215054 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49774 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:02:59.385839939 CEST | 280 | OUT | |
Oct 13, 2024 17:02:59.385839939 CEST | 160 | OUT | |
Oct 13, 2024 17:03:00.567207098 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49785 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:00.580315113 CEST | 279 | OUT | |
Oct 13, 2024 17:03:00.583970070 CEST | 286 | OUT | |
Oct 13, 2024 17:03:01.794980049 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49794 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:01.839550972 CEST | 281 | OUT | |
Oct 13, 2024 17:03:01.839601040 CEST | 316 | OUT | |
Oct 13, 2024 17:03:03.054527998 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49802 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:03.064747095 CEST | 278 | OUT | |
Oct 13, 2024 17:03:03.064793110 CEST | 343 | OUT | |
Oct 13, 2024 17:03:04.301119089 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49810 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:04.311893940 CEST | 278 | OUT | |
Oct 13, 2024 17:03:04.311893940 CEST | 132 | OUT | |
Oct 13, 2024 17:03:05.654290915 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49819 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:05.663530111 CEST | 281 | OUT | |
Oct 13, 2024 17:03:05.663530111 CEST | 247 | OUT | |
Oct 13, 2024 17:03:06.907557964 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49828 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:07.017113924 CEST | 283 | OUT | |
Oct 13, 2024 17:03:07.017113924 CEST | 238 | OUT | |
Oct 13, 2024 17:03:08.189560890 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49836 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:08.198231936 CEST | 278 | OUT | |
Oct 13, 2024 17:03:08.198271036 CEST | 136 | OUT | |
Oct 13, 2024 17:03:09.445173025 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49845 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:09.453996897 CEST | 283 | OUT | |
Oct 13, 2024 17:03:09.454029083 CEST | 190 | OUT | |
Oct 13, 2024 17:03:10.849014997 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49856 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:10.913814068 CEST | 281 | OUT | |
Oct 13, 2024 17:03:10.913814068 CEST | 249 | OUT | |
Oct 13, 2024 17:03:12.156563044 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49864 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:12.166707039 CEST | 282 | OUT | |
Oct 13, 2024 17:03:12.166743994 CEST | 184 | OUT | |
Oct 13, 2024 17:03:13.541337967 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49873 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:13.552712917 CEST | 281 | OUT | |
Oct 13, 2024 17:03:13.552731037 CEST | 136 | OUT | |
Oct 13, 2024 17:03:14.796607971 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49882 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:14.806333065 CEST | 281 | OUT | |
Oct 13, 2024 17:03:14.808027029 CEST | 308 | OUT | |
Oct 13, 2024 17:03:15.976577044 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49890 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:15.985131979 CEST | 279 | OUT | |
Oct 13, 2024 17:03:15.985166073 CEST | 308 | OUT | |
Oct 13, 2024 17:03:17.243900061 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49896 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:03:17.252623081 CEST | 280 | OUT | |
Oct 13, 2024 17:03:17.252645016 CEST | 135 | OUT | |
Oct 13, 2024 17:03:18.610971928 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 50038 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:04:26.627563000 CEST | 283 | OUT | |
Oct 13, 2024 17:04:26.627563000 CEST | 274 | OUT | |
Oct 13, 2024 17:04:28.029043913 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 50039 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:04:32.911271095 CEST | 278 | OUT | |
Oct 13, 2024 17:04:32.911271095 CEST | 156 | OUT | |
Oct 13, 2024 17:04:34.140043020 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 50040 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:04:38.182934999 CEST | 283 | OUT | |
Oct 13, 2024 17:04:38.182967901 CEST | 362 | OUT | |
Oct 13, 2024 17:04:39.391208887 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 50041 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:04:43.323587894 CEST | 279 | OUT | |
Oct 13, 2024 17:04:43.326654911 CEST | 307 | OUT | |
Oct 13, 2024 17:04:44.509438038 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 50042 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:04:48.787045002 CEST | 279 | OUT | |
Oct 13, 2024 17:04:48.787079096 CEST | 215 | OUT | |
Oct 13, 2024 17:04:50.069689035 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 50043 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:04:54.553349972 CEST | 279 | OUT | |
Oct 13, 2024 17:04:54.553381920 CEST | 132 | OUT | |
Oct 13, 2024 17:04:55.759946108 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 50044 | 78.89.199.216 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:00.282948971 CEST | 279 | OUT | |
Oct 13, 2024 17:05:00.282968998 CEST | 298 | OUT | |
Oct 13, 2024 17:05:01.475089073 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 50045 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:06.197248936 CEST | 278 | OUT | |
Oct 13, 2024 17:05:06.197290897 CEST | 214 | OUT | |
Oct 13, 2024 17:05:06.985910892 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 50046 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:10.841243029 CEST | 278 | OUT | |
Oct 13, 2024 17:05:10.841335058 CEST | 323 | OUT | |
Oct 13, 2024 17:05:11.639252901 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 50047 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:15.990360975 CEST | 283 | OUT | |
Oct 13, 2024 17:05:15.990394115 CEST | 140 | OUT | |
Oct 13, 2024 17:05:16.825057983 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 50048 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:21.868154049 CEST | 278 | OUT | |
Oct 13, 2024 17:05:21.868169069 CEST | 200 | OUT | |
Oct 13, 2024 17:05:23.062016010 CEST | 151 | IN | |
Oct 13, 2024 17:05:23.062119961 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 50049 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:27.911989927 CEST | 283 | OUT | |
Oct 13, 2024 17:05:27.911989927 CEST | 353 | OUT | |
Oct 13, 2024 17:05:28.722807884 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 50050 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:33.742224932 CEST | 280 | OUT | |
Oct 13, 2024 17:05:33.742224932 CEST | 164 | OUT | |
Oct 13, 2024 17:05:34.538161993 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 50051 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:39.543642998 CEST | 278 | OUT | |
Oct 13, 2024 17:05:39.543716908 CEST | 249 | OUT | |
Oct 13, 2024 17:05:40.582794905 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 50052 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:45.099385977 CEST | 282 | OUT | |
Oct 13, 2024 17:05:45.099427938 CEST | 119 | OUT | |
Oct 13, 2024 17:05:45.894088030 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 50053 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:49.937036037 CEST | 278 | OUT | |
Oct 13, 2024 17:05:49.937036037 CEST | 169 | OUT | |
Oct 13, 2024 17:05:50.726022005 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.4 | 50054 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:05:55.284992933 CEST | 281 | OUT | |
Oct 13, 2024 17:05:55.284993887 CEST | 146 | OUT | |
Oct 13, 2024 17:05:56.081058025 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.4 | 50055 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:06:00.384315014 CEST | 283 | OUT | |
Oct 13, 2024 17:06:00.384349108 CEST | 128 | OUT | |
Oct 13, 2024 17:06:01.187680006 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.4 | 50056 | 109.175.29.39 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 17:06:05.963869095 CEST | 282 | OUT | |
Oct 13, 2024 17:06:05.963869095 CEST | 301 | OUT | |
Oct 13, 2024 17:06:06.773713112 CEST | 151 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:02:02 |
Start date: | 13/10/2024 |
Path: | C:\Users\user\Desktop\FyDBXJE74v.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 296'960 bytes |
MD5 hash: | 497859EED941E073A43E8291908E6494 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 11:02:11 |
Start date: | 13/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 11:02:28 |
Start date: | 13/10/2024 |
Path: | C:\Users\user\AppData\Roaming\wsbgrgh |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 296'960 bytes |
MD5 hash: | 497859EED941E073A43E8291908E6494 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 9.5% |
Dynamic/Decrypted Code Coverage: | 29.4% |
Signature Coverage: | 44.2% |
Total number of Nodes: | 163 |
Total number of Limit Nodes: | 7 |
Graph
Function 00415F50 Relevance: 45.8, APIs: 24, Strings: 2, Instructions: 288filepipetimeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CA0A22 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02BC003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415BD0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02BC0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CA06E1 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415BA0 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02BC092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02CA02FF Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403277 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040324F Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02BC0D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403256 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403290 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415EC0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.5% |
Dynamic/Decrypted Code Coverage: | 29.4% |
Signature Coverage: | 0% |
Total number of Nodes: | 163 |
Total number of Limit Nodes: | 7 |
Graph
Function 00415F50 Relevance: 45.8, APIs: 24, Strings: 2, Instructions: 288filepipetimeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DE003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415BD0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02E4FB5A Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02DE0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02E4F819 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415BA0 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415EC0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|