Windows
Analysis Report
K80v6DHFHE.exe
Overview
General Information
Sample name: | K80v6DHFHE.exerenamed because original name is a hash value |
Original sample name: | 278df1e655d9d27b659468ea21758d17.exe |
Analysis ID: | 1532605 |
MD5: | 278df1e655d9d27b659468ea21758d17 |
SHA1: | 51d59cbc9e28708086517ea33ff07a9b2cfb3fcf |
SHA256: | 2b727f4b529097748b5c49720bb42da02efb7758bf6870acfd4404c24b60840b |
Tags: | exeStealcuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- K80v6DHFHE.exe (PID: 5544 cmdline:
"C:\Users\ user\Deskt op\K80v6DH FHE.exe" MD5: 278DF1E655D9D27B659468EA21758D17) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- wafguag (PID: 6100 cmdline:
C:\Users\u ser\AppDat a\Roaming\ wafguag MD5: 278DF1E655D9D27B659468EA21758D17)
- wafguag (PID: 2936 cmdline:
C:\Users\u ser\AppDat a\Roaming\ wafguag MD5: 278DF1E655D9D27B659468EA21758D17)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://nwgrus.ru/tmp/index.php", "http://tech-servers.in.net/tmp/index.php", "http://unicea.ws/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-13T18:27:45.303931+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64968 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:46.963293+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64969 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:47.919755+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64970 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:48.894639+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64971 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:49.898590+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64972 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:50.854819+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64973 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:51.827443+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64974 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:52.778261+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64975 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:53.738201+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64976 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:54.709329+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64977 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:55.664115+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64978 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:56.624121+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64979 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:57.590520+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64981 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:58.543210+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64987 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:59.558359+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64993 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:00.521490+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 64999 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:01.500523+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65005 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:02.470685+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65016 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:03.627242+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65022 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:04.593154+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65028 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:05.564245+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65034 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:06.520404+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65046 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:07.527668+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65052 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:08.550643+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65058 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:09.504054+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65064 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:10.465258+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65070 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:11.447931+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65080 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:12.404007+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65082 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:13.361965+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65092 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:14.318728+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65099 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:15.828924+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65105 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:16.790815+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65115 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:17.753342+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65122 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:18.775757+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65128 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:19.728904+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65134 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:20.704701+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65140 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:26.607711+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65270 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:28.771259+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65271 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:30.033311+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65272 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:31.548788+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65273 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:32.705945+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65274 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:38.370062+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65275 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:43.415784+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65276 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:48.487284+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65277 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:53.628328+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65278 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:59.682273+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65279 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:30:06.086268+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65280 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:30:12.261434+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65281 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:30:21.478641+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65282 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:27.201694+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65283 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:33.413089+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65284 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:39.987751+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65285 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:45.633160+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65286 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:52.041561+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65287 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:57.539699+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65288 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:31:04.509515+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65289 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:31:10.096614+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 65290 | 190.156.239.49 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_00403277 | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 5_2_00401514 | |
Source: | Code function: | 5_2_00402F97 | |
Source: | Code function: | 5_2_00401542 | |
Source: | Code function: | 5_2_00403247 | |
Source: | Code function: | 5_2_00401549 | |
Source: | Code function: | 5_2_0040324F | |
Source: | Code function: | 5_2_00403256 | |
Source: | Code function: | 5_2_00401557 | |
Source: | Code function: | 5_2_0040326C | |
Source: | Code function: | 5_2_00403277 | |
Source: | Code function: | 5_2_004032C7 | |
Source: | Code function: | 5_2_004014FE | |
Source: | Code function: | 5_2_00403290 |
Source: | Code function: | 0_2_00415530 | |
Source: | Code function: | 5_2_00415530 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_02B8016D |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_02B83BC8 | |
Source: | Code function: | 0_2_02B81FA0 | |
Source: | Code function: | 0_2_02B82A67 | |
Source: | Code function: | 0_2_02C71550 | |
Source: | Code function: | 5_2_004014E9 | |
Source: | Code function: | 5_2_004032AB | |
Source: | Code function: | 5_2_02C81550 | |
Source: | Code function: | 5_2_02E020FF | |
Source: | Code function: | 5_2_02E03260 | |
Source: | Code function: | 5_2_02E01638 | |
Source: | Code function: | 5_2_02E0739A |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_02B7FA4A | |
Source: | Code function: | 0_2_02C70D90 | |
Source: | Code function: | 0_2_02C7092B | |
Source: | Code function: | 5_2_02C80D90 | |
Source: | Code function: | 5_2_02C8092B | |
Source: | Code function: | 5_2_02DFF0E2 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00415530 | |
Source: | Code function: | 5_2_00415530 |
Source: | Code function: | 7_2_00404E64 |
Source: | Code function: | 0_2_00415530 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 511 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 12 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | 113 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Software Packing | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 114 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Win32.Trojan.CrypterX | ||
41% | Virustotal | Browse | ||
100% | Avira | HEUR/AGEN.1312571 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1312571 | ||
100% | Joe Sandbox ML | |||
39% | ReversingLabs | Win32.Trojan.CrypterX | ||
41% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
17% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
2% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
nwgrus.ru | 148.230.249.9 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
190.156.239.49 | unknown | Colombia | 10620 | TelmexColombiaSACO | true | |
148.230.249.9 | nwgrus.ru | Mexico | 3549 | LVLT-3549US | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1532605 |
Start date and time: | 2024-10-13 18:26:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | K80v6DHFHE.exerenamed because original name is a hash value |
Original Sample Name: | 278df1e655d9d27b659468ea21758d17.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@3/2@6/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target wafguag, PID 2936 because there are no executed function
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
12:27:29 | API Interceptor | |
17:27:41 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
190.156.239.49 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
148.230.249.9 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Babuk, Clipboard Hijacker, Djvu, Glupteba, LummaC Stealer, Mars Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
nwgrus.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TelmexColombiaSACO | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
LVLT-3549US | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294400 |
Entropy (8bit): | 5.5821574905838105 |
Encrypted: | false |
SSDEEP: | 3072:iBILhZ6F7bBPQYK3+9L4xwafTdJ5+CyxF9DavCEkXFUCIqzpZAqa8i:iBI87b4SL4qw8/43kXFVIqzpZAqaR |
MD5: | 278DF1E655D9D27B659468EA21758D17 |
SHA1: | 51D59CBC9E28708086517EA33FF07A9B2CFB3FCF |
SHA-256: | 2B727F4B529097748B5C49720BB42DA02EFB7758BF6870ACFD4404C24B60840B |
SHA-512: | C7E6F1325D88EFB57AA123B52D4B4276024C267980F0C72D2F3F058E568A781AFB14207DDE6FC84B98BF308518D2B92304DA6939D8A2056D79E11089CDD8DEC7 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.5821574905838105 |
TrID: |
|
File name: | K80v6DHFHE.exe |
File size: | 294'400 bytes |
MD5: | 278df1e655d9d27b659468ea21758d17 |
SHA1: | 51d59cbc9e28708086517ea33ff07a9b2cfb3fcf |
SHA256: | 2b727f4b529097748b5c49720bb42da02efb7758bf6870acfd4404c24b60840b |
SHA512: | c7e6f1325d88efb57aa123b52d4b4276024c267980f0c72d2f3f058e568a781afb14207dde6fc84b98bf308518d2b92304da6939d8a2056d79e11089cdd8dec7 |
SSDEEP: | 3072:iBILhZ6F7bBPQYK3+9L4xwafTdJ5+CyxF9DavCEkXFUCIqzpZAqa8i:iBI87b4SL4qw8/43kXFVIqzpZAqaR |
TLSH: | 0B54D78252E12C07EFB64B328E39D5D4A62EFD525E7572EEA1047E0F14BB1B1E113B12 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:..K~...~...~...`.x.e...`.i.n...`...4...Y...y...~.......`.v.....`.h.....`.m.....Rich~...........PE..L......d.................J. |
Icon Hash: | 738733b18b838bec |
Entrypoint: | 0x4018e4 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6492C0AC [Wed Jun 21 09:19:40 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | f9644889fc4743405befff91cfd6f312 |
Instruction |
---|
call 00007F03308E1550h |
jmp 00007F03308DDE4Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [0041A3D0h], eax |
mov dword ptr [0041A3CCh], ecx |
mov dword ptr [0041A3C8h], edx |
mov dword ptr [0041A3C4h], ebx |
mov dword ptr [0041A3C0h], esi |
mov dword ptr [0041A3BCh], edi |
mov word ptr [0041A3E8h], ss |
mov word ptr [0041A3DCh], cs |
mov word ptr [0041A3B8h], ds |
mov word ptr [0041A3B4h], es |
mov word ptr [0041A3B0h], fs |
mov word ptr [0041A3ACh], gs |
pushfd |
pop dword ptr [0041A3E0h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [0041A3D4h], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [0041A3D8h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [0041A3E4h], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [0041A320h], 00010001h |
mov eax, dword ptr [0041A3D8h] |
mov dword ptr [0041A2D4h], eax |
mov dword ptr [0041A2C8h], C0000409h |
mov dword ptr [0041A2CCh], 00000001h |
mov eax, dword ptr [00419008h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [0041900Ch] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000F0h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x17734 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x2721000 | 0x29810 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x16000 | 0x190 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x1496f | 0x14a00 | 017412b3a78f0e77be68b00d88053d64 | False | 0.8211292613636364 | data | 7.534628882954891 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x16000 | 0x2062 | 0x2200 | 160cce12c5b12d62944f68724786d475 | False | 0.36328125 | data | 5.445425145565832 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x19000 | 0x26fff7c | 0x1400 | 8da7d0568b68a86023cfd4ba13def4fa | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.dazit | 0x2719000 | 0x4400 | 0x3800 | b211778b80f6d441b6cf61ada776fc6d | False | 0.0025809151785714285 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.xepegi | 0x271e000 | 0x2800 | 0x2800 | 1276481102f218c981e0324180bafd9f | False | 0.00322265625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x2721000 | 0x29810 | 0x29a00 | c7a219fd936649e9e6564e7104748d02 | False | 0.3730058183183183 | data | 4.758448918209474 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
AFX_DIALOG_LAYOUT | 0x273f0a8 | 0x2 | data | 5.0 | ||
RT_CURSOR | 0x273f0b0 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.4276315789473684 | ||
RT_CURSOR | 0x273f1f8 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x273f328 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_CURSOR | 0x27418f8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.31023454157782515 | ||
RT_CURSOR | 0x27427b8 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x27428e8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_ICON | 0x2721e00 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.5674307036247335 |
RT_ICON | 0x2722ca8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.6376353790613718 |
RT_ICON | 0x2723550 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.6849078341013825 |
RT_ICON | 0x2723c18 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.7456647398843931 |
RT_ICON | 0x2724180 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | Turkish | Turkey | 0.512863070539419 |
RT_ICON | 0x2726728 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | Turkish | Turkey | 0.6137429643527205 |
RT_ICON | 0x27277d0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | Turkish | Turkey | 0.6163934426229508 |
RT_ICON | 0x2728158 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | Turkish | Turkey | 0.7553191489361702 |
RT_ICON | 0x2728638 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.3347547974413646 |
RT_ICON | 0x27294e0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5221119133574007 |
RT_ICON | 0x2729d88 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.5846774193548387 |
RT_ICON | 0x272a450 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6307803468208093 |
RT_ICON | 0x272a9b8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.42686721991701243 |
RT_ICON | 0x272cf60 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.5061475409836066 |
RT_ICON | 0x272d8e8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.5079787234042553 |
RT_ICON | 0x272ddb8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.3350213219616205 |
RT_ICON | 0x272ec60 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.388086642599278 |
RT_ICON | 0x272f508 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.39285714285714285 |
RT_ICON | 0x272fbd0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.40534682080924855 |
RT_ICON | 0x2730138 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Turkish | Turkey | 0.21950207468879668 |
RT_ICON | 0x27326e0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Turkish | Turkey | 0.2474202626641651 |
RT_ICON | 0x2733788 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Turkish | Turkey | 0.2815573770491803 |
RT_ICON | 0x2734110 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Turkish | Turkey | 0.31117021276595747 |
RT_ICON | 0x27345f0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.39285714285714285 |
RT_ICON | 0x2735498 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5537003610108303 |
RT_ICON | 0x2735d40 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.6226958525345622 |
RT_ICON | 0x2736408 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6372832369942196 |
RT_ICON | 0x2736970 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.425422138836773 |
RT_ICON | 0x2737a18 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.4209016393442623 |
RT_ICON | 0x27383a0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.46187943262411346 |
RT_ICON | 0x2738870 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.279317697228145 |
RT_ICON | 0x2739718 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.3664259927797834 |
RT_ICON | 0x2739fc0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.3773041474654378 |
RT_ICON | 0x273a688 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.3764450867052023 |
RT_ICON | 0x273abf0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.2587136929460581 |
RT_ICON | 0x273d198 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.27345215759849906 |
RT_ICON | 0x273e240 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.28852459016393445 |
RT_ICON | 0x273ebc8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.32180851063829785 |
RT_STRING | 0x2745070 | 0xaa | data | 0.5588235294117647 | ||
RT_STRING | 0x2745120 | 0x600 | data | 0.4361979166666667 | ||
RT_STRING | 0x2745720 | 0x460 | data | 0.45 | ||
RT_STRING | 0x2745b80 | 0x64a | data | 0.4360248447204969 | ||
RT_STRING | 0x27461d0 | 0x7b8 | data | 0.4185222672064777 | ||
RT_STRING | 0x2746988 | 0x6d0 | data | 0.4294724770642202 | ||
RT_STRING | 0x2747058 | 0x76c | data | 0.42526315789473684 | ||
RT_STRING | 0x27477c8 | 0x606 | data | 0.4455252918287938 | ||
RT_STRING | 0x2747dd0 | 0x7c2 | data | 0.42245720040281975 | ||
RT_STRING | 0x2748598 | 0x810 | data | 0.42102713178294576 | ||
RT_STRING | 0x2748da8 | 0x584 | data | 0.4461756373937677 | ||
RT_STRING | 0x2749330 | 0x74c | data | 0.4234475374732334 | ||
RT_STRING | 0x2749a80 | 0x710 | data | 0.4303097345132743 | ||
RT_STRING | 0x274a190 | 0x5f6 | data | 0.4325032765399738 | ||
RT_STRING | 0x274a788 | 0x88 | data | 0.625 | ||
RT_GROUP_CURSOR | 0x273f1e0 | 0x14 | data | 1.15 | ||
RT_GROUP_CURSOR | 0x27418d0 | 0x22 | data | 1.088235294117647 | ||
RT_GROUP_CURSOR | 0x27427a0 | 0x14 | data | 1.25 | ||
RT_GROUP_CURSOR | 0x2744e90 | 0x22 | data | 1.088235294117647 | ||
RT_GROUP_ICON | 0x272dd50 | 0x68 | data | Turkish | Turkey | 0.7019230769230769 |
RT_GROUP_ICON | 0x2734578 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x273f030 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x27285c0 | 0x76 | data | Turkish | Turkey | 0.6610169491525424 |
RT_GROUP_ICON | 0x2738808 | 0x68 | data | Turkish | Turkey | 0.7211538461538461 |
RT_VERSION | 0x2744eb8 | 0x1b4 | data | 0.5871559633027523 |
DLL | Import |
---|---|
KERNEL32.dll | OpenJobObjectA, ReadConsoleA, InterlockedDecrement, GlobalSize, SetDefaultCommConfigW, QueryDosDeviceA, InterlockedCompareExchange, GetComputerNameW, SetEvent, GetNumaAvailableMemoryNode, FreeEnvironmentStringsA, GetModuleHandleW, GetConsoleAliasesLengthA, FormatMessageA, SetCommState, GetLocaleInfoW, GetConsoleWindow, ReadConsoleOutputW, GetVersionExW, GetStringTypeExW, HeapDestroy, GetFileAttributesA, DeleteVolumeMountPointA, SetConsoleMode, GetFileAttributesW, GetBinaryTypeA, DisconnectNamedPipe, LCMapStringA, GetLastError, GetProcAddress, MoveFileW, SetStdHandle, GetNumaHighestNodeNumber, LoadLibraryA, LocalAlloc, WritePrivateProfileStringA, GetModuleFileNameA, BuildCommDCBA, FatalAppExitA, GetShortPathNameW, SetCalendarInfoA, FindAtomW, SearchPathW, GetConsoleAliasExesLengthA, GetTimeFormatW, PulseEvent, HeapAlloc, MultiByteToWideChar, Sleep, ExitProcess, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapFree, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, WriteFile, GetStdHandle, GetCPInfo, InterlockedIncrement, GetACP, GetOEMCP, IsValidCodePage, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, InitializeCriticalSectionAndSpinCount, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, HeapSize |
GDI32.dll | GetBoundsRect |
ADVAPI32.dll | ClearEventLogW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkish | Turkey |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-13T18:27:45.303931+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64968 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:46.963293+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64969 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:47.919755+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64970 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:48.894639+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64971 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:49.898590+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64972 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:50.854819+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64973 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:51.827443+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64974 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:52.778261+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64975 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:53.738201+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64976 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:54.709329+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64977 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:55.664115+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64978 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:56.624121+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64979 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:57.590520+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64981 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:58.543210+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64987 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:27:59.558359+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64993 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:00.521490+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 64999 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:01.500523+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65005 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:02.470685+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65016 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:03.627242+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65022 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:04.593154+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65028 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:05.564245+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65034 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:06.520404+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65046 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:07.527668+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65052 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:08.550643+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65058 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:09.504054+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65064 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:10.465258+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65070 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:11.447931+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65080 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:12.404007+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65082 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:13.361965+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65092 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:14.318728+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65099 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:15.828924+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65105 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:16.790815+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65115 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:17.753342+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65122 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:18.775757+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65128 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:19.728904+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65134 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:28:20.704701+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65140 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:26.607711+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65270 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:28.771259+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65271 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:30.033311+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65272 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:31.548788+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65273 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:32.705945+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65274 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:38.370062+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65275 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:43.415784+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65276 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:48.487284+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65277 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:53.628328+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65278 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:29:59.682273+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65279 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:30:06.086268+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65280 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:30:12.261434+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65281 | 148.230.249.9 | 80 | TCP |
2024-10-13T18:30:21.478641+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65282 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:27.201694+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65283 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:33.413089+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65284 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:39.987751+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65285 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:45.633160+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65286 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:52.041561+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65287 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:30:57.539699+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65288 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:31:04.509515+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65289 | 190.156.239.49 | 80 | TCP |
2024-10-13T18:31:10.096614+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 65290 | 190.156.239.49 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 13, 2024 18:27:44.322470903 CEST | 64968 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:44.327584028 CEST | 80 | 64968 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:44.327867985 CEST | 64968 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:44.338875055 CEST | 64968 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:44.338875055 CEST | 64968 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:44.344046116 CEST | 80 | 64968 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:44.344127893 CEST | 80 | 64968 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:45.302810907 CEST | 80 | 64968 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:45.303859949 CEST | 80 | 64968 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:45.303930998 CEST | 64968 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:45.307379007 CEST | 64968 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:45.312424898 CEST | 80 | 64968 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:45.322740078 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:45.328291893 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:45.328598022 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:45.331068039 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:45.331068039 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:45.335994959 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:45.336071968 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.963160038 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.963207006 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.963236094 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.963268042 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.963293076 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.963293076 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.963397980 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.967463017 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.967504978 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.967544079 CEST | 64969 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.970889091 CEST | 64970 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.972407103 CEST | 80 | 64969 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.976089001 CEST | 80 | 64970 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.976293087 CEST | 64970 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.976579905 CEST | 64970 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.976579905 CEST | 64970 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:46.981838942 CEST | 80 | 64970 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:46.981878042 CEST | 80 | 64970 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:47.918625116 CEST | 80 | 64970 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:47.919682026 CEST | 80 | 64970 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:47.919754982 CEST | 64970 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:47.919815063 CEST | 64970 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:47.922821045 CEST | 64971 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:47.924977064 CEST | 80 | 64970 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:47.927870989 CEST | 80 | 64971 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:47.928205967 CEST | 64971 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:47.928205967 CEST | 64971 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:47.929371119 CEST | 64971 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:47.933600903 CEST | 80 | 64971 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:47.934279919 CEST | 80 | 64971 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:48.893680096 CEST | 80 | 64971 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:48.894534111 CEST | 80 | 64971 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:48.894639015 CEST | 64971 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:48.896545887 CEST | 64971 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:48.901724100 CEST | 80 | 64971 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:48.927881956 CEST | 64972 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:48.932904959 CEST | 80 | 64972 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:48.933026075 CEST | 64972 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:48.933195114 CEST | 64972 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:48.933260918 CEST | 64972 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:48.938105106 CEST | 80 | 64972 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:48.938158989 CEST | 80 | 64972 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:49.898473024 CEST | 80 | 64972 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:49.898525000 CEST | 80 | 64972 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:49.898590088 CEST | 64972 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:49.898884058 CEST | 64972 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:49.903760910 CEST | 80 | 64972 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:49.905847073 CEST | 64973 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:49.911154985 CEST | 80 | 64973 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:49.911473036 CEST | 64973 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:49.911473989 CEST | 64973 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:49.911564112 CEST | 64973 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:49.916601896 CEST | 80 | 64973 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:49.916651964 CEST | 80 | 64973 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:50.853787899 CEST | 80 | 64973 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:50.854746103 CEST | 80 | 64973 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:50.854819059 CEST | 64973 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:50.854877949 CEST | 64973 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:50.858681917 CEST | 64974 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:50.859802008 CEST | 80 | 64973 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:50.863645077 CEST | 80 | 64974 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:50.863720894 CEST | 64974 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:50.863857985 CEST | 64974 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:50.863874912 CEST | 64974 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:50.868678093 CEST | 80 | 64974 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:50.868818998 CEST | 80 | 64974 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:51.826019049 CEST | 80 | 64974 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:51.827100992 CEST | 80 | 64974 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:51.827442884 CEST | 64974 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:51.827442884 CEST | 64974 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:51.830374002 CEST | 64975 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:51.832489014 CEST | 80 | 64974 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:51.835539103 CEST | 80 | 64975 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:51.835630894 CEST | 64975 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:51.835762024 CEST | 64975 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:51.835762978 CEST | 64975 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:51.840539932 CEST | 80 | 64975 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:51.840759039 CEST | 80 | 64975 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:52.776384115 CEST | 80 | 64975 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:52.778186083 CEST | 80 | 64975 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:52.778260946 CEST | 64975 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:52.778408051 CEST | 64975 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:52.783457041 CEST | 80 | 64975 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:52.784629107 CEST | 64976 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:52.789630890 CEST | 80 | 64976 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:52.789715052 CEST | 64976 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:52.789835930 CEST | 64976 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:52.789871931 CEST | 64976 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:52.794759989 CEST | 80 | 64976 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:52.794789076 CEST | 80 | 64976 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:53.737190962 CEST | 80 | 64976 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:53.738106966 CEST | 80 | 64976 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:53.738200903 CEST | 64976 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:53.738276958 CEST | 64976 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:53.742254019 CEST | 64977 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:53.743436098 CEST | 80 | 64976 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:53.747360945 CEST | 80 | 64977 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:53.747476101 CEST | 64977 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:53.747736931 CEST | 64977 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:53.747826099 CEST | 64977 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:53.752556086 CEST | 80 | 64977 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:53.752806902 CEST | 80 | 64977 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:54.709198952 CEST | 80 | 64977 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:54.709252119 CEST | 80 | 64977 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:54.709328890 CEST | 64977 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:54.709528923 CEST | 64977 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:54.714521885 CEST | 80 | 64977 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:54.715270042 CEST | 64978 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:54.720423937 CEST | 80 | 64978 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:54.720614910 CEST | 64978 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:54.720984936 CEST | 64978 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:54.720984936 CEST | 64978 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:54.726246119 CEST | 80 | 64978 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:54.726284981 CEST | 80 | 64978 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:55.663595915 CEST | 80 | 64978 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:55.663693905 CEST | 80 | 64978 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:55.664114952 CEST | 64978 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:55.664482117 CEST | 64978 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:55.667546988 CEST | 64979 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:55.669501066 CEST | 80 | 64978 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:55.672902107 CEST | 80 | 64979 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:55.673187971 CEST | 64979 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:55.673388004 CEST | 64979 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:55.673423052 CEST | 64979 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:55.678523064 CEST | 80 | 64979 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:55.678551912 CEST | 80 | 64979 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:56.622756004 CEST | 80 | 64979 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:56.623907089 CEST | 80 | 64979 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:56.624120951 CEST | 64979 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:56.624121904 CEST | 64979 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:56.627789021 CEST | 64981 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:56.629053116 CEST | 80 | 64979 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:56.633394003 CEST | 80 | 64981 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:56.633800030 CEST | 64981 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:56.633893013 CEST | 64981 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:56.633893013 CEST | 64981 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:56.638823986 CEST | 80 | 64981 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:56.638865948 CEST | 80 | 64981 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:57.589418888 CEST | 80 | 64981 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:57.590377092 CEST | 80 | 64981 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:57.590519905 CEST | 64981 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:57.590631962 CEST | 64981 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:57.594156027 CEST | 64987 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:57.596261024 CEST | 80 | 64981 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:57.600029945 CEST | 80 | 64987 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:57.600227118 CEST | 64987 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:57.600322008 CEST | 64987 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:57.600322008 CEST | 64987 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:57.605448008 CEST | 80 | 64987 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:57.605752945 CEST | 80 | 64987 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:58.543081999 CEST | 80 | 64987 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:58.543134928 CEST | 80 | 64987 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:58.543210030 CEST | 64987 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:58.543427944 CEST | 64987 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:58.546967983 CEST | 64993 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:58.548624992 CEST | 80 | 64987 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:58.552083015 CEST | 80 | 64993 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:58.552161932 CEST | 64993 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:58.552355051 CEST | 64993 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:58.552355051 CEST | 64993 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:58.557485104 CEST | 80 | 64993 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:58.557537079 CEST | 80 | 64993 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:59.554004908 CEST | 80 | 64993 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:59.557687044 CEST | 80 | 64993 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:59.558358908 CEST | 64993 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:59.558458090 CEST | 64993 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:59.563669920 CEST | 80 | 64993 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:59.569158077 CEST | 64999 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:59.574127913 CEST | 80 | 64999 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:59.575916052 CEST | 64999 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:59.576095104 CEST | 64999 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:59.576131105 CEST | 64999 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:27:59.581012964 CEST | 80 | 64999 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:27:59.581042051 CEST | 80 | 64999 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:00.520693064 CEST | 80 | 64999 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:00.521313906 CEST | 80 | 64999 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:00.521490097 CEST | 64999 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:00.521490097 CEST | 64999 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:00.525887012 CEST | 65005 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:00.526396036 CEST | 80 | 64999 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:00.530810118 CEST | 80 | 65005 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:00.530884981 CEST | 65005 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:00.531119108 CEST | 65005 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:00.531119108 CEST | 65005 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:00.536029100 CEST | 80 | 65005 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:00.536241055 CEST | 80 | 65005 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:01.491563082 CEST | 80 | 65005 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:01.492470980 CEST | 80 | 65005 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:01.500523090 CEST | 65005 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:01.500610113 CEST | 65005 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:01.504095078 CEST | 65016 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:01.505594015 CEST | 80 | 65005 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:01.509320021 CEST | 80 | 65016 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:01.509593964 CEST | 65016 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:01.509685040 CEST | 65016 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:01.509685040 CEST | 65016 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:01.514688969 CEST | 80 | 65016 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:01.514992952 CEST | 80 | 65016 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:02.469595909 CEST | 80 | 65016 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:02.470587015 CEST | 80 | 65016 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:02.470685005 CEST | 65016 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:02.472939014 CEST | 65016 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:02.477936029 CEST | 80 | 65016 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:02.670990944 CEST | 65022 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:02.677385092 CEST | 80 | 65022 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:02.677472115 CEST | 65022 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:02.677640915 CEST | 65022 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:02.677666903 CEST | 65022 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:02.682852030 CEST | 80 | 65022 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:02.682882071 CEST | 80 | 65022 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:03.625276089 CEST | 80 | 65022 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:03.627130985 CEST | 80 | 65022 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:03.627242088 CEST | 65022 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:03.627324104 CEST | 65022 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:03.629564047 CEST | 65028 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:03.633361101 CEST | 80 | 65022 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:03.634588957 CEST | 80 | 65028 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:03.634689093 CEST | 65028 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:03.634772062 CEST | 65028 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:03.634807110 CEST | 65028 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:03.639683962 CEST | 80 | 65028 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:03.640933037 CEST | 80 | 65028 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:04.591512918 CEST | 80 | 65028 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:04.593071938 CEST | 80 | 65028 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:04.593153954 CEST | 65028 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:04.593211889 CEST | 65028 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:04.595581055 CEST | 65034 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:04.599550962 CEST | 80 | 65028 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:04.602621078 CEST | 80 | 65034 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:04.602715969 CEST | 65034 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:04.602816105 CEST | 65034 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:04.602850914 CEST | 65034 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:04.607774973 CEST | 80 | 65034 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:04.607805967 CEST | 80 | 65034 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:05.563189983 CEST | 80 | 65034 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:05.564156055 CEST | 80 | 65034 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:05.564244986 CEST | 65034 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:05.564326048 CEST | 65034 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:05.567614079 CEST | 65046 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:05.569468975 CEST | 80 | 65034 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:05.572645903 CEST | 80 | 65046 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:05.572738886 CEST | 65046 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:05.572858095 CEST | 65046 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:05.572884083 CEST | 65046 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:05.578213930 CEST | 80 | 65046 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:05.578257084 CEST | 80 | 65046 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:06.520082951 CEST | 80 | 65046 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:06.520153999 CEST | 80 | 65046 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:06.520404100 CEST | 65046 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:06.520405054 CEST | 65046 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:06.522823095 CEST | 65052 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:06.525418997 CEST | 80 | 65046 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:06.527791977 CEST | 80 | 65052 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:06.529058933 CEST | 65052 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:06.529167891 CEST | 65052 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:06.529226065 CEST | 65052 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:06.534014940 CEST | 80 | 65052 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:06.534188986 CEST | 80 | 65052 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:07.527420044 CEST | 80 | 65052 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:07.527539015 CEST | 80 | 65052 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:07.527667999 CEST | 65052 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:07.544464111 CEST | 65052 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:07.550980091 CEST | 80 | 65052 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:07.592680931 CEST | 65058 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:07.597636938 CEST | 80 | 65058 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:07.600336075 CEST | 65058 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:07.604176044 CEST | 65058 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:07.604176044 CEST | 65058 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:07.609595060 CEST | 80 | 65058 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:07.609627008 CEST | 80 | 65058 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:08.549442053 CEST | 80 | 65058 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:08.550466061 CEST | 80 | 65058 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:08.550642967 CEST | 65058 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:08.551187992 CEST | 65058 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:08.553847075 CEST | 65064 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:08.556096077 CEST | 80 | 65058 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:08.558968067 CEST | 80 | 65064 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:08.561141968 CEST | 65064 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:08.561347961 CEST | 65064 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:08.561381102 CEST | 65064 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:08.566235065 CEST | 80 | 65064 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:08.566396952 CEST | 80 | 65064 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:09.502774000 CEST | 80 | 65064 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:09.503849983 CEST | 80 | 65064 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:09.504054070 CEST | 65064 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:09.504054070 CEST | 65064 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:09.507870913 CEST | 65070 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:09.509027004 CEST | 80 | 65064 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:09.512835026 CEST | 80 | 65070 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:09.512912035 CEST | 65070 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:09.548398018 CEST | 65070 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:09.548398018 CEST | 65070 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:09.553726912 CEST | 80 | 65070 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:09.553765059 CEST | 80 | 65070 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:10.463885069 CEST | 80 | 65070 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:10.464965105 CEST | 80 | 65070 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:10.465257883 CEST | 65070 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:10.465357065 CEST | 65070 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:10.467438936 CEST | 65080 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:10.470698118 CEST | 80 | 65070 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:10.472448111 CEST | 80 | 65080 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:10.476519108 CEST | 65080 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:10.477514029 CEST | 65080 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:10.477514029 CEST | 65080 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:10.482857943 CEST | 80 | 65080 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:10.482887983 CEST | 80 | 65080 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:11.447698116 CEST | 80 | 65080 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:11.447735071 CEST | 80 | 65080 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:11.447931051 CEST | 65080 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:11.448312044 CEST | 65080 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:11.452414989 CEST | 65082 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:11.457897902 CEST | 80 | 65080 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:11.458045959 CEST | 80 | 65082 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:11.458132029 CEST | 65082 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:11.458384037 CEST | 65082 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:11.458384037 CEST | 65082 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:11.463422060 CEST | 80 | 65082 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:11.463454008 CEST | 80 | 65082 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:12.403850079 CEST | 80 | 65082 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:12.403913021 CEST | 80 | 65082 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:12.404006958 CEST | 65082 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:12.404227972 CEST | 65082 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:12.407248974 CEST | 65092 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:12.409064054 CEST | 80 | 65082 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:12.412242889 CEST | 80 | 65092 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:12.412436962 CEST | 65092 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:12.412687063 CEST | 65092 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:12.412687063 CEST | 65092 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:12.417776108 CEST | 80 | 65092 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:12.417818069 CEST | 80 | 65092 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:13.359931946 CEST | 80 | 65092 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:13.361891031 CEST | 80 | 65092 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:13.361964941 CEST | 65092 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:13.362041950 CEST | 65092 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:13.364820004 CEST | 65099 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:13.366909981 CEST | 80 | 65092 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:13.369702101 CEST | 80 | 65099 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:13.370102882 CEST | 65099 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:13.370277882 CEST | 65099 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:13.370277882 CEST | 65099 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:13.375320911 CEST | 80 | 65099 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:13.375349998 CEST | 80 | 65099 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:14.317760944 CEST | 80 | 65099 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:14.318645954 CEST | 80 | 65099 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:14.318727970 CEST | 65099 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:14.336577892 CEST | 65099 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:14.341597080 CEST | 80 | 65099 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:14.874433994 CEST | 65105 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:14.879658937 CEST | 80 | 65105 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:14.879870892 CEST | 65105 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:14.879990101 CEST | 65105 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:14.879990101 CEST | 65105 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:14.884979010 CEST | 80 | 65105 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:14.885008097 CEST | 80 | 65105 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:15.827591896 CEST | 80 | 65105 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:15.828577995 CEST | 80 | 65105 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:15.828923941 CEST | 65105 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:15.830322027 CEST | 65105 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:15.831439972 CEST | 65115 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:15.835700989 CEST | 80 | 65105 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:15.836549997 CEST | 80 | 65115 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:15.836635113 CEST | 65115 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:15.840307951 CEST | 65115 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:15.840347052 CEST | 65115 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:15.845371008 CEST | 80 | 65115 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:15.845386028 CEST | 80 | 65115 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:16.790606976 CEST | 80 | 65115 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:16.790745974 CEST | 80 | 65115 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:16.790815115 CEST | 65115 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:16.790896893 CEST | 65115 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:16.795906067 CEST | 80 | 65115 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:16.798844099 CEST | 65122 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:16.803783894 CEST | 80 | 65122 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:16.803915977 CEST | 65122 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:16.804027081 CEST | 65122 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:16.804059982 CEST | 65122 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:16.809787035 CEST | 80 | 65122 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:16.809815884 CEST | 80 | 65122 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:17.753078938 CEST | 80 | 65122 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:17.753123045 CEST | 80 | 65122 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:17.753341913 CEST | 65122 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:17.762639999 CEST | 65122 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:17.767564058 CEST | 80 | 65122 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:17.806852102 CEST | 65128 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:17.812514067 CEST | 80 | 65128 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:17.812601089 CEST | 65128 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:17.812771082 CEST | 65128 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:17.812810898 CEST | 65128 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:17.817683935 CEST | 80 | 65128 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:17.817768097 CEST | 80 | 65128 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:18.774601936 CEST | 80 | 65128 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:18.775686979 CEST | 80 | 65128 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:18.775757074 CEST | 65128 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:18.775999069 CEST | 65128 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:18.778984070 CEST | 65134 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:18.780981064 CEST | 80 | 65128 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:18.784069061 CEST | 80 | 65134 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:18.784166098 CEST | 65134 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:18.784312963 CEST | 65134 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:18.784347057 CEST | 65134 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:18.789195061 CEST | 80 | 65134 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:18.789247990 CEST | 80 | 65134 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:19.727567911 CEST | 80 | 65134 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:19.728682041 CEST | 80 | 65134 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:19.728904009 CEST | 65134 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:19.729233027 CEST | 65134 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:19.734323978 CEST | 80 | 65134 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:19.734853029 CEST | 65140 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:19.739847898 CEST | 80 | 65140 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:19.739960909 CEST | 65140 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:19.740135908 CEST | 65140 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:19.740176916 CEST | 65140 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:19.744988918 CEST | 80 | 65140 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:19.745142937 CEST | 80 | 65140 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:20.703269005 CEST | 80 | 65140 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:20.704267979 CEST | 80 | 65140 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:28:20.704700947 CEST | 65140 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:20.709239960 CEST | 65140 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:28:20.714406967 CEST | 80 | 65140 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:25.650063038 CEST | 65270 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:25.655219078 CEST | 80 | 65270 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:25.655355930 CEST | 65270 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:25.655539989 CEST | 65270 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:25.655575037 CEST | 65270 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:25.660574913 CEST | 80 | 65270 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:25.660605907 CEST | 80 | 65270 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:26.607275963 CEST | 80 | 65270 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:26.607450962 CEST | 80 | 65270 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:26.607711077 CEST | 65270 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:26.610852957 CEST | 65270 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:26.615865946 CEST | 80 | 65270 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:27.826234102 CEST | 65271 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:27.831506014 CEST | 80 | 65271 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:27.831624985 CEST | 65271 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:27.831768036 CEST | 65271 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:27.831768990 CEST | 65271 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:27.836638927 CEST | 80 | 65271 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:27.836807013 CEST | 80 | 65271 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:28.770073891 CEST | 80 | 65271 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:28.771136045 CEST | 80 | 65271 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:28.771259069 CEST | 65271 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:28.771318913 CEST | 65271 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:28.776321888 CEST | 80 | 65271 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:29.086436033 CEST | 65272 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:29.091653109 CEST | 80 | 65272 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:29.091912031 CEST | 65272 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:29.091999054 CEST | 65272 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:29.092036963 CEST | 65272 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:29.097230911 CEST | 80 | 65272 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:29.097259998 CEST | 80 | 65272 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:30.032151937 CEST | 80 | 65272 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:30.033135891 CEST | 80 | 65272 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:30.033310890 CEST | 65272 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:30.059278011 CEST | 65272 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:30.064582109 CEST | 80 | 65272 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:30.597359896 CEST | 65273 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:30.603868961 CEST | 80 | 65273 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:30.603980064 CEST | 65273 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:30.604149103 CEST | 65273 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:30.604204893 CEST | 65273 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:30.609294891 CEST | 80 | 65273 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:30.609323978 CEST | 80 | 65273 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:31.548640966 CEST | 80 | 65273 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:31.548719883 CEST | 80 | 65273 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:31.548788071 CEST | 65273 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:31.548968077 CEST | 65273 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:31.554034948 CEST | 80 | 65273 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:31.759579897 CEST | 65274 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:31.764739990 CEST | 80 | 65274 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:31.764832020 CEST | 65274 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:31.764997005 CEST | 65274 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:31.765028000 CEST | 65274 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:31.769836903 CEST | 80 | 65274 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:31.769892931 CEST | 80 | 65274 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:32.705795050 CEST | 80 | 65274 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:32.705883026 CEST | 80 | 65274 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:32.705945015 CEST | 65274 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:32.706151009 CEST | 65274 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:32.711270094 CEST | 80 | 65274 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:37.420042038 CEST | 65275 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:37.425733089 CEST | 80 | 65275 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:37.426176071 CEST | 65275 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:37.426177025 CEST | 65275 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:37.426275969 CEST | 65275 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:37.431365967 CEST | 80 | 65275 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:37.431417942 CEST | 80 | 65275 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:38.369604111 CEST | 80 | 65275 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:38.369868994 CEST | 80 | 65275 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:38.370062113 CEST | 65275 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:38.374594927 CEST | 65275 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:38.379633904 CEST | 80 | 65275 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:42.453030109 CEST | 65276 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:42.458642006 CEST | 80 | 65276 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:42.459079981 CEST | 65276 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:42.459172010 CEST | 65276 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:42.459172010 CEST | 65276 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:42.464067936 CEST | 80 | 65276 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:42.464165926 CEST | 80 | 65276 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:43.415448904 CEST | 80 | 65276 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:43.415518999 CEST | 80 | 65276 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:43.415783882 CEST | 65276 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:43.422976017 CEST | 65276 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:43.427985907 CEST | 80 | 65276 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:47.519145966 CEST | 65277 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:47.524502993 CEST | 80 | 65277 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:47.524744987 CEST | 65277 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:47.524832010 CEST | 65277 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:47.524864912 CEST | 65277 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:47.529989958 CEST | 80 | 65277 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:47.530004025 CEST | 80 | 65277 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:48.485850096 CEST | 80 | 65277 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:48.487097979 CEST | 80 | 65277 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:48.487283945 CEST | 65277 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:48.487400055 CEST | 65277 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:48.492595911 CEST | 80 | 65277 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:52.678787947 CEST | 65278 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:52.684046984 CEST | 80 | 65278 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:52.684268951 CEST | 65278 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:52.684465885 CEST | 65278 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:52.684540987 CEST | 65278 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:52.689568043 CEST | 80 | 65278 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:52.689577103 CEST | 80 | 65278 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:53.627422094 CEST | 80 | 65278 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:53.628232002 CEST | 80 | 65278 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:53.628328085 CEST | 65278 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:53.630148888 CEST | 65278 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:53.635132074 CEST | 80 | 65278 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:58.712245941 CEST | 65279 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:58.718581915 CEST | 80 | 65279 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:58.718908072 CEST | 65279 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:58.718908072 CEST | 65279 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:58.718909025 CEST | 65279 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:58.724266052 CEST | 80 | 65279 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:58.724297047 CEST | 80 | 65279 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:59.680485964 CEST | 80 | 65279 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:59.682029963 CEST | 80 | 65279 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:29:59.682272911 CEST | 65279 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:59.685296059 CEST | 65279 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:29:59.690716982 CEST | 80 | 65279 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:05.138192892 CEST | 65280 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:05.143424034 CEST | 80 | 65280 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:05.143526077 CEST | 65280 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:05.143635035 CEST | 65280 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:05.143667936 CEST | 65280 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:05.148509979 CEST | 80 | 65280 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:05.148673058 CEST | 80 | 65280 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:06.085484028 CEST | 80 | 65280 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:06.086147070 CEST | 80 | 65280 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:06.086267948 CEST | 65280 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:06.086997032 CEST | 65280 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:06.091850996 CEST | 80 | 65280 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:11.310967922 CEST | 65281 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:11.316101074 CEST | 80 | 65281 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:11.316200972 CEST | 65281 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:11.316328049 CEST | 65281 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:11.316346884 CEST | 65281 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:11.321192026 CEST | 80 | 65281 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:11.321223021 CEST | 80 | 65281 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:12.261116028 CEST | 80 | 65281 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:12.261282921 CEST | 80 | 65281 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:12.261434078 CEST | 65281 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:12.263565063 CEST | 65281 | 80 | 192.168.2.4 | 148.230.249.9 |
Oct 13, 2024 18:30:12.268507957 CEST | 80 | 65281 | 148.230.249.9 | 192.168.2.4 |
Oct 13, 2024 18:30:20.010098934 CEST | 65282 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:20.015103102 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:20.015494108 CEST | 65282 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:20.015578032 CEST | 65282 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:20.015578032 CEST | 65282 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:20.020554066 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:20.020781994 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:21.478468895 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:21.478521109 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:21.478549957 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:21.478584051 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:21.478641033 CEST | 65282 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:21.478641987 CEST | 65282 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:21.478907108 CEST | 65282 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:21.483680964 CEST | 80 | 65282 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:26.123940945 CEST | 65283 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:26.129339933 CEST | 80 | 65283 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:26.129496098 CEST | 65283 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:26.129671097 CEST | 65283 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:26.129710913 CEST | 65283 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:26.134785891 CEST | 80 | 65283 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:26.134815931 CEST | 80 | 65283 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:27.201457977 CEST | 80 | 65283 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:27.201617002 CEST | 80 | 65283 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:27.201694012 CEST | 65283 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:27.209893942 CEST | 65283 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:27.215029955 CEST | 80 | 65283 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:32.347740889 CEST | 65284 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:32.353072882 CEST | 80 | 65284 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:32.353173971 CEST | 65284 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:32.353360891 CEST | 65284 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:32.353400946 CEST | 65284 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:32.358455896 CEST | 80 | 65284 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:32.358616114 CEST | 80 | 65284 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:33.412847996 CEST | 80 | 65284 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:33.412944078 CEST | 80 | 65284 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:33.413089037 CEST | 65284 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:33.414274931 CEST | 65284 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:33.419094086 CEST | 80 | 65284 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:38.902930975 CEST | 65285 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:38.908217907 CEST | 80 | 65285 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:38.908505917 CEST | 65285 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:38.908505917 CEST | 65285 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:38.908505917 CEST | 65285 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:38.913501024 CEST | 80 | 65285 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:38.913532019 CEST | 80 | 65285 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:39.981079102 CEST | 80 | 65285 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:39.987359047 CEST | 80 | 65285 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:39.987751007 CEST | 65285 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:39.987751961 CEST | 65285 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:39.992949963 CEST | 80 | 65285 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:44.553365946 CEST | 65286 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:44.558906078 CEST | 80 | 65286 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:44.559143066 CEST | 65286 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:44.559293985 CEST | 65286 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:44.559294939 CEST | 65286 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:44.564346075 CEST | 80 | 65286 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:44.564374924 CEST | 80 | 65286 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:45.632917881 CEST | 80 | 65286 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:45.632966995 CEST | 80 | 65286 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:45.633160114 CEST | 65286 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:45.633161068 CEST | 65286 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:45.638246059 CEST | 80 | 65286 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:50.964096069 CEST | 65287 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:50.969412088 CEST | 80 | 65287 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:50.969518900 CEST | 65287 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:50.969672918 CEST | 65287 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:50.969698906 CEST | 65287 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:50.974596024 CEST | 80 | 65287 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:50.974745989 CEST | 80 | 65287 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:52.041395903 CEST | 80 | 65287 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:52.041446924 CEST | 80 | 65287 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:52.041560888 CEST | 65287 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:52.041975021 CEST | 65287 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:52.048170090 CEST | 80 | 65287 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:56.473633051 CEST | 65288 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:56.478847980 CEST | 80 | 65288 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:56.479007006 CEST | 65288 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:56.479343891 CEST | 65288 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:56.479343891 CEST | 65288 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:56.484225988 CEST | 80 | 65288 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:56.484360933 CEST | 80 | 65288 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:57.539180040 CEST | 80 | 65288 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:57.539336920 CEST | 80 | 65288 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:30:57.539699078 CEST | 65288 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:57.539700031 CEST | 65288 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:30:57.544656038 CEST | 80 | 65288 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:03.435033083 CEST | 65289 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:03.440574884 CEST | 80 | 65289 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:03.440665007 CEST | 65289 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:03.440818071 CEST | 65289 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:03.440851927 CEST | 65289 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:03.445816040 CEST | 80 | 65289 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:03.445915937 CEST | 80 | 65289 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:04.500907898 CEST | 80 | 65289 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:04.509406090 CEST | 80 | 65289 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:04.509515047 CEST | 65289 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:04.509599924 CEST | 65289 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:04.514774084 CEST | 80 | 65289 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:09.030992985 CEST | 65290 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:09.036115885 CEST | 80 | 65290 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:09.036257982 CEST | 65290 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:09.036417961 CEST | 65290 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:09.036448956 CEST | 65290 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:09.041256905 CEST | 80 | 65290 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:09.041536093 CEST | 80 | 65290 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:10.096421957 CEST | 80 | 65290 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:10.096517086 CEST | 80 | 65290 | 190.156.239.49 | 192.168.2.4 |
Oct 13, 2024 18:31:10.096613884 CEST | 65290 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:10.096738100 CEST | 65290 | 80 | 192.168.2.4 | 190.156.239.49 |
Oct 13, 2024 18:31:10.101636887 CEST | 80 | 65290 | 190.156.239.49 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 13, 2024 18:27:28.655493021 CEST | 53 | 64862 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 18:27:41.999279022 CEST | 61734 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 18:27:43.007685900 CEST | 61734 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 18:27:44.048820972 CEST | 61734 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 18:27:44.320143938 CEST | 53 | 61734 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 18:27:44.320195913 CEST | 53 | 61734 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 18:27:44.320225954 CEST | 53 | 61734 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 18:30:17.703927040 CEST | 63384 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 18:30:18.713279009 CEST | 63384 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 18:30:19.713051081 CEST | 63384 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 13, 2024 18:30:20.008795977 CEST | 53 | 63384 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 18:30:20.008842945 CEST | 53 | 63384 | 1.1.1.1 | 192.168.2.4 |
Oct 13, 2024 18:30:20.008871078 CEST | 53 | 63384 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 13, 2024 18:27:41.999279022 CEST | 192.168.2.4 | 1.1.1.1 | 0x43c9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 18:27:43.007685900 CEST | 192.168.2.4 | 1.1.1.1 | 0x43c9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 18:27:44.048820972 CEST | 192.168.2.4 | 1.1.1.1 | 0x43c9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 18:30:17.703927040 CEST | 192.168.2.4 | 1.1.1.1 | 0x3f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 18:30:18.713279009 CEST | 192.168.2.4 | 1.1.1.1 | 0x3f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 13, 2024 18:30:19.713051081 CEST | 192.168.2.4 | 1.1.1.1 | 0x3f9 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 185.12.79.25 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 190.219.117.240 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 211.181.24.133 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 175.119.10.231 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320143938 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 185.12.79.25 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 190.219.117.240 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 211.181.24.133 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 175.119.10.231 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320195913 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 185.12.79.25 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 190.219.117.240 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 211.181.24.133 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 175.119.10.231 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:27:44.320225954 CEST | 1.1.1.1 | 192.168.2.4 | 0x43c9 | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 130.204.29.121 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 2.185.214.11 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 201.212.52.197 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 211.171.233.126 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.187.52.42 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 116.58.10.60 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008795977 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.249.249.14 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 130.204.29.121 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 2.185.214.11 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 201.212.52.197 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 211.171.233.126 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.187.52.42 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 116.58.10.60 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008842945 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.249.249.14 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.156.239.49 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 130.204.29.121 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 2.185.214.11 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 201.212.52.197 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 211.171.233.126 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.187.52.42 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 116.58.10.60 | A (IP address) | IN (0x0001) | false | ||
Oct 13, 2024 18:30:20.008871078 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f9 | No error (0) | 190.249.249.14 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 64968 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:44.338875055 CEST | 281 | OUT | |
Oct 13, 2024 18:27:44.338875055 CEST | 222 | OUT | |
Oct 13, 2024 18:27:45.302810907 CEST | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 64969 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:45.331068039 CEST | 280 | OUT | |
Oct 13, 2024 18:27:45.331068039 CEST | 123 | OUT | |
Oct 13, 2024 18:27:46.963160038 CEST | 484 | IN | |
Oct 13, 2024 18:27:46.963268042 CEST | 484 | IN | |
Oct 13, 2024 18:27:46.967463017 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 64970 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:46.976579905 CEST | 281 | OUT | |
Oct 13, 2024 18:27:46.976579905 CEST | 126 | OUT | |
Oct 13, 2024 18:27:47.918625116 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 64971 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:47.928205967 CEST | 281 | OUT | |
Oct 13, 2024 18:27:47.929371119 CEST | 306 | OUT | |
Oct 13, 2024 18:27:48.893680096 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 64972 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:48.933195114 CEST | 279 | OUT | |
Oct 13, 2024 18:27:48.933260918 CEST | 112 | OUT | |
Oct 13, 2024 18:27:49.898473024 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 64973 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:49.911473989 CEST | 283 | OUT | |
Oct 13, 2024 18:27:49.911564112 CEST | 226 | OUT | |
Oct 13, 2024 18:27:50.853787899 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 64974 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:50.863857985 CEST | 280 | OUT | |
Oct 13, 2024 18:27:50.863874912 CEST | 234 | OUT | |
Oct 13, 2024 18:27:51.826019049 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 64975 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:51.835762024 CEST | 283 | OUT | |
Oct 13, 2024 18:27:51.835762978 CEST | 241 | OUT | |
Oct 13, 2024 18:27:52.776384115 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 64976 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:52.789835930 CEST | 279 | OUT | |
Oct 13, 2024 18:27:52.789871931 CEST | 347 | OUT | |
Oct 13, 2024 18:27:53.737190962 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 64977 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:53.747736931 CEST | 282 | OUT | |
Oct 13, 2024 18:27:53.747826099 CEST | 238 | OUT | |
Oct 13, 2024 18:27:54.709198952 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 64978 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:54.720984936 CEST | 278 | OUT | |
Oct 13, 2024 18:27:54.720984936 CEST | 340 | OUT | |
Oct 13, 2024 18:27:55.663595915 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 64979 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:55.673388004 CEST | 283 | OUT | |
Oct 13, 2024 18:27:55.673423052 CEST | 337 | OUT | |
Oct 13, 2024 18:27:56.622756004 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 64981 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:56.633893013 CEST | 278 | OUT | |
Oct 13, 2024 18:27:56.633893013 CEST | 293 | OUT | |
Oct 13, 2024 18:27:57.589418888 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 64987 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:57.600322008 CEST | 278 | OUT | |
Oct 13, 2024 18:27:57.600322008 CEST | 305 | OUT | |
Oct 13, 2024 18:27:58.543081999 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 64993 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:58.552355051 CEST | 280 | OUT | |
Oct 13, 2024 18:27:58.552355051 CEST | 277 | OUT | |
Oct 13, 2024 18:27:59.554004908 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 64999 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:27:59.576095104 CEST | 280 | OUT | |
Oct 13, 2024 18:27:59.576131105 CEST | 311 | OUT | |
Oct 13, 2024 18:28:00.520693064 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 65005 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:00.531119108 CEST | 278 | OUT | |
Oct 13, 2024 18:28:00.531119108 CEST | 143 | OUT | |
Oct 13, 2024 18:28:01.491563082 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 65016 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:01.509685040 CEST | 281 | OUT | |
Oct 13, 2024 18:28:01.509685040 CEST | 225 | OUT | |
Oct 13, 2024 18:28:02.469595909 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 65022 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:02.677640915 CEST | 283 | OUT | |
Oct 13, 2024 18:28:02.677666903 CEST | 150 | OUT | |
Oct 13, 2024 18:28:03.625276089 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 65028 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:03.634772062 CEST | 278 | OUT | |
Oct 13, 2024 18:28:03.634807110 CEST | 131 | OUT | |
Oct 13, 2024 18:28:04.591512918 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 65034 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:04.602816105 CEST | 279 | OUT | |
Oct 13, 2024 18:28:04.602850914 CEST | 293 | OUT | |
Oct 13, 2024 18:28:05.563189983 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 65046 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:05.572858095 CEST | 281 | OUT | |
Oct 13, 2024 18:28:05.572884083 CEST | 279 | OUT | |
Oct 13, 2024 18:28:06.520082951 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 65052 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:06.529167891 CEST | 282 | OUT | |
Oct 13, 2024 18:28:06.529226065 CEST | 259 | OUT | |
Oct 13, 2024 18:28:07.527420044 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 65058 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:07.604176044 CEST | 279 | OUT | |
Oct 13, 2024 18:28:07.604176044 CEST | 154 | OUT | |
Oct 13, 2024 18:28:08.549442053 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 65064 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:08.561347961 CEST | 280 | OUT | |
Oct 13, 2024 18:28:08.561381102 CEST | 115 | OUT | |
Oct 13, 2024 18:28:09.502774000 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 65070 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:09.548398018 CEST | 280 | OUT | |
Oct 13, 2024 18:28:09.548398018 CEST | 220 | OUT | |
Oct 13, 2024 18:28:10.463885069 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 65080 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:10.477514029 CEST | 283 | OUT | |
Oct 13, 2024 18:28:10.477514029 CEST | 241 | OUT | |
Oct 13, 2024 18:28:11.447698116 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 65082 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:11.458384037 CEST | 282 | OUT | |
Oct 13, 2024 18:28:11.458384037 CEST | 139 | OUT | |
Oct 13, 2024 18:28:12.403850079 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 65092 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:12.412687063 CEST | 280 | OUT | |
Oct 13, 2024 18:28:12.412687063 CEST | 183 | OUT | |
Oct 13, 2024 18:28:13.359931946 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 65099 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:13.370277882 CEST | 281 | OUT | |
Oct 13, 2024 18:28:13.370277882 CEST | 200 | OUT | |
Oct 13, 2024 18:28:14.317760944 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 65105 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:14.879990101 CEST | 282 | OUT | |
Oct 13, 2024 18:28:14.879990101 CEST | 288 | OUT | |
Oct 13, 2024 18:28:15.827591896 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 65115 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:15.840307951 CEST | 279 | OUT | |
Oct 13, 2024 18:28:15.840347052 CEST | 330 | OUT | |
Oct 13, 2024 18:28:16.790606976 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 65122 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:16.804027081 CEST | 281 | OUT | |
Oct 13, 2024 18:28:16.804059982 CEST | 368 | OUT | |
Oct 13, 2024 18:28:17.753078938 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 65128 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:17.812771082 CEST | 280 | OUT | |
Oct 13, 2024 18:28:17.812810898 CEST | 188 | OUT | |
Oct 13, 2024 18:28:18.774601936 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 65134 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:18.784312963 CEST | 283 | OUT | |
Oct 13, 2024 18:28:18.784347057 CEST | 189 | OUT | |
Oct 13, 2024 18:28:19.727567911 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 65140 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:28:19.740135908 CEST | 281 | OUT | |
Oct 13, 2024 18:28:19.740176916 CEST | 232 | OUT | |
Oct 13, 2024 18:28:20.703269005 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 65270 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:25.655539989 CEST | 278 | OUT | |
Oct 13, 2024 18:29:25.655575037 CEST | 221 | OUT | |
Oct 13, 2024 18:29:26.607275963 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 65271 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:27.831768036 CEST | 282 | OUT | |
Oct 13, 2024 18:29:27.831768990 CEST | 220 | OUT | |
Oct 13, 2024 18:29:28.770073891 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 65272 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:29.091999054 CEST | 278 | OUT | |
Oct 13, 2024 18:29:29.092036963 CEST | 290 | OUT | |
Oct 13, 2024 18:29:30.032151937 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 65273 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:30.604149103 CEST | 280 | OUT | |
Oct 13, 2024 18:29:30.604204893 CEST | 302 | OUT | |
Oct 13, 2024 18:29:31.548640966 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 65274 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:31.764997005 CEST | 280 | OUT | |
Oct 13, 2024 18:29:31.765028000 CEST | 314 | OUT | |
Oct 13, 2024 18:29:32.705795050 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 65275 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:37.426177025 CEST | 283 | OUT | |
Oct 13, 2024 18:29:37.426275969 CEST | 361 | OUT | |
Oct 13, 2024 18:29:38.369604111 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 65276 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:42.459172010 CEST | 280 | OUT | |
Oct 13, 2024 18:29:42.459172010 CEST | 136 | OUT | |
Oct 13, 2024 18:29:43.415448904 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 65277 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:47.524832010 CEST | 283 | OUT | |
Oct 13, 2024 18:29:47.524864912 CEST | 267 | OUT | |
Oct 13, 2024 18:29:48.485850096 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 65278 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:52.684465885 CEST | 281 | OUT | |
Oct 13, 2024 18:29:52.684540987 CEST | 256 | OUT | |
Oct 13, 2024 18:29:53.627422094 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 65279 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:29:58.718908072 CEST | 279 | OUT | |
Oct 13, 2024 18:29:58.718909025 CEST | 265 | OUT | |
Oct 13, 2024 18:29:59.680485964 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 65280 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:05.143635035 CEST | 283 | OUT | |
Oct 13, 2024 18:30:05.143667936 CEST | 187 | OUT | |
Oct 13, 2024 18:30:06.085484028 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 65281 | 148.230.249.9 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:11.316328049 CEST | 278 | OUT | |
Oct 13, 2024 18:30:11.316346884 CEST | 338 | OUT | |
Oct 13, 2024 18:30:12.261116028 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 65282 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:20.015578032 CEST | 278 | OUT | |
Oct 13, 2024 18:30:20.015578032 CEST | 353 | OUT | |
Oct 13, 2024 18:30:21.478468895 CEST | 151 | IN | |
Oct 13, 2024 18:30:21.478584051 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 65283 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:26.129671097 CEST | 282 | OUT | |
Oct 13, 2024 18:30:26.129710913 CEST | 286 | OUT | |
Oct 13, 2024 18:30:27.201457977 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 65284 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:32.353360891 CEST | 282 | OUT | |
Oct 13, 2024 18:30:32.353400946 CEST | 220 | OUT | |
Oct 13, 2024 18:30:33.412847996 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 65285 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:38.908505917 CEST | 283 | OUT | |
Oct 13, 2024 18:30:38.908505917 CEST | 341 | OUT | |
Oct 13, 2024 18:30:39.981079102 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.4 | 65286 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:44.559293985 CEST | 280 | OUT | |
Oct 13, 2024 18:30:44.559294939 CEST | 216 | OUT | |
Oct 13, 2024 18:30:45.632917881 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.4 | 65287 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:50.969672918 CEST | 283 | OUT | |
Oct 13, 2024 18:30:50.969698906 CEST | 214 | OUT | |
Oct 13, 2024 18:30:52.041395903 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.4 | 65288 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:30:56.479343891 CEST | 283 | OUT | |
Oct 13, 2024 18:30:56.479343891 CEST | 139 | OUT | |
Oct 13, 2024 18:30:57.539180040 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.4 | 65289 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:31:03.440818071 CEST | 283 | OUT | |
Oct 13, 2024 18:31:03.440851927 CEST | 229 | OUT | |
Oct 13, 2024 18:31:04.500907898 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.4 | 65290 | 190.156.239.49 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 13, 2024 18:31:09.036417961 CEST | 280 | OUT | |
Oct 13, 2024 18:31:09.036448956 CEST | 339 | OUT | |
Oct 13, 2024 18:31:10.096421957 CEST | 151 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:27:06 |
Start date: | 13/10/2024 |
Path: | C:\Users\user\Desktop\K80v6DHFHE.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 294'400 bytes |
MD5 hash: | 278DF1E655D9D27B659468EA21758D17 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 12:27:19 |
Start date: | 13/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 12:27:41 |
Start date: | 13/10/2024 |
Path: | C:\Users\user\AppData\Roaming\wafguag |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 294'400 bytes |
MD5 hash: | 278DF1E655D9D27B659468EA21758D17 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 12:30:01 |
Start date: | 13/10/2024 |
Path: | C:\Users\user\AppData\Roaming\wafguag |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 294'400 bytes |
MD5 hash: | 278DF1E655D9D27B659468EA21758D17 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 9.6% |
Dynamic/Decrypted Code Coverage: | 28.5% |
Signature Coverage: | 41.9% |
Total number of Nodes: | 172 |
Total number of Limit Nodes: | 6 |
Graph
Function 00415530 Relevance: 49.3, APIs: 26, Strings: 2, Instructions: 302filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02B8016D Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02C7003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415867 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004151B0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C70E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02B7FE2C Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415180 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C7092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02B7FA4A Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403277 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C70D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040324F Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403256 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403290 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004154A0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.3% |
Dynamic/Decrypted Code Coverage: | 28.5% |
Signature Coverage: | 0% |
Total number of Nodes: | 172 |
Total number of Limit Nodes: | 6 |
Graph
Function 00415530 Relevance: 49.3, APIs: 26, Strings: 2, Instructions: 302filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C8003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415867 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004151B0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DFF805 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02C80E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DFF4C4 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415180 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004154A0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|