Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 6444 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 29EAF4B051758C9946539B6BA8AA475F) - explorer.exe (PID: 4004 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- fbtdajh (PID: 5492 cmdline:
C:\Users\u ser\AppDat a\Roaming\ fbtdajh MD5: 29EAF4B051758C9946539B6BA8AA475F)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://nwgrus.ru/tmp/index.php", "http://tech-servers.in.net/tmp/index.php", "http://unicea.ws/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Click to see the 8 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-14T06:02:41.580888+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49862 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:43.242369+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49873 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:44.741563+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49884 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:46.242232+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49895 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:47.819583+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49906 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:49.336141+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49917 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:50.858357+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49928 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:52.382811+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49939 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:53.931040+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49949 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:55.571568+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49960 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:57.199668+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49972 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:58.792799+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49983 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:00.282605+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49994 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:02.013801+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49996 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:03.632852+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49997 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:05.160241+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 49999 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:06.773833+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50001 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:08.494699+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50002 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:10.116735+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50003 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:11.620256+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50004 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:13.111163+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50005 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:14.871674+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50006 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:16.441473+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50007 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:18.047258+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50008 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:19.642690+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50009 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:21.149882+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50010 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:22.762582+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50011 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:24.252561+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50012 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:25.849542+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50013 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:27.421559+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50014 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:29.192946+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50015 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:30.817494+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50016 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:32.304663+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50017 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:34.246847+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50018 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:36.144916+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50019 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:04:45.418789+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50023 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:04:51.149380+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50024 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:04:58.244487+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50025 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:05:04.062889+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50026 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:05:10.088773+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50027 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:05:18.035144+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50028 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:24.004900+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50030 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:31.785512+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50031 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:37.620142+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50032 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:43.752844+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50033 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:49.451325+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50034 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:55.638546+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50035 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:06:00.592981+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50036 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:06:06.826789+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50037 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:06:13.270043+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.6 | 50038 | 211.171.233.129 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_0040327D | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 4_2_00401514 | |
Source: | Code function: | 4_2_00402F97 | |
Source: | Code function: | 4_2_00401542 | |
Source: | Code function: | 4_2_00403247 | |
Source: | Code function: | 4_2_00401549 | |
Source: | Code function: | 4_2_0040324F | |
Source: | Code function: | 4_2_00403256 | |
Source: | Code function: | 4_2_00401557 | |
Source: | Code function: | 4_2_0040326C | |
Source: | Code function: | 4_2_0040327D | |
Source: | Code function: | 4_2_004014FE | |
Source: | Code function: | 4_2_00403290 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_02C200B4 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_02C2A2D0 | |
Source: | Code function: | 0_2_02C2A1FC | |
Source: | Code function: | 0_2_02C2A2E0 | |
Source: | Code function: | 0_2_02C2A2F0 | |
Source: | Code function: | 0_2_02C2A300 | |
Source: | Code function: | 0_2_02C2A20C | |
Source: | Code function: | 0_2_02C2A290 | |
Source: | Code function: | 0_2_02C2A39C | |
Source: | Code function: | 0_2_02C2A1CC | |
Source: | Code function: | 0_2_02C229AE | |
Source: | Code function: | 0_2_02C21EE7 | |
Source: | Code function: | 0_2_02C2A2C0 | |
Source: | Code function: | 0_2_02C2A270 | |
Source: | Code function: | 0_2_02C2A37C | |
Source: | Code function: | 0_2_02C2A280 | |
Source: | Code function: | 0_2_02C2A1A4 | |
Source: | Code function: | 0_2_02C2A38C | |
Source: | Code function: | 0_2_02C2A310 | |
Source: | Code function: | 0_2_02C2A21C | |
Source: | Code function: | 0_2_02C23B0F | |
Source: | Code function: | 0_2_02C2A320 | |
Source: | Code function: | 0_2_02C2A22C | |
Source: | Code function: | 0_2_02C2A330 | |
Source: | Code function: | 0_2_02C2A17C | |
Source: | Code function: | 0_2_02C2A244 | |
Source: | Code function: | 0_2_04791550 | |
Source: | Code function: | 4_2_004014E9 | |
Source: | Code function: | 4_2_004032AB | |
Source: | Code function: | 4_2_02C131AE |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_02C1F991 | |
Source: | Code function: | 0_2_0479092B | |
Source: | Code function: | 0_2_04790D90 | |
Source: | Code function: | 4_2_02C10191 | |
Source: | Code function: | 4_2_02CF0D90 | |
Source: | Code function: | 4_2_02CF092B |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_004173E0 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 511 Security Software Discovery | Remote Services | Data from Local System | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 12 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 3 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 113 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Software Packing | Cached Domain Credentials | 13 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | ReversingLabs | Win32.Trojan.Generic | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
42% | ReversingLabs | Win32.Trojan.Generic |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
nwgrus.ru | 125.7.253.10 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
211.171.233.129 | unknown | Korea Republic of | 3786 | LGDACOMLGDACOMCorporationKR | true | |
125.7.253.10 | nwgrus.ru | Korea Republic of | 3786 | LGDACOMLGDACOMCorporationKR | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1532900 |
Start date and time: | 2024-10-14 06:01:11 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 8s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@2/2@7/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
- Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: file.exe
Time | Type | Description |
---|---|---|
00:02:36 | API Interceptor | |
06:02:35 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
211.171.233.129 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | Babuk, Clipboard Hijacker, Djvu, Vidar | Browse |
| ||
Get hash | malicious | Babuk, Clipboard Hijacker, Djvu, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Glupteba, LummaC Stealer, SmokeLoader, Socks5Systemz, Stealc | Browse |
| ||
Get hash | malicious | SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | Amadey, SmokeLoader | Browse |
| ||
Get hash | malicious | Amadey, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Glupteba, SmokeLoader, Stealc | Browse |
| ||
125.7.253.10 | Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| |
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
nwgrus.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
LGDACOMLGDACOMCorporationKR | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | RMSRemoteAdmin | Browse |
| ||
Get hash | malicious | RMSRemoteAdmin | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
LGDACOMLGDACOMCorporationKR | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | RMSRemoteAdmin | Browse |
| ||
Get hash | malicious | RMSRemoteAdmin | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 274944 |
Entropy (8bit): | 5.743757942440379 |
Encrypted: | false |
SSDEEP: | 3072:tOe0QuzbNAj5HG/NTG7U+L50CyxF9Dav/cGKt6KUCIqzpjAqMi:we0QCyj5Ho08/4/wVIqzpjAqh |
MD5: | 29EAF4B051758C9946539B6BA8AA475F |
SHA1: | 7F2CE245C72D8689AAA7460CD6D12DB57B9C36BA |
SHA-256: | 8001AF6BBC3CC10B1382C5EFC800E479804AD1E30F0D99A57ADD656A811AFBCD |
SHA-512: | AB2C9443AB55E81D17CA452A4D0508F52E3A3AC23801E4D6375496A6FD230094B5CB2991BD467087F03D27BC3DA387973D308880402D565899177722BE5BE032 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.743757942440379 |
TrID: |
|
File name: | file.exe |
File size: | 274'944 bytes |
MD5: | 29eaf4b051758c9946539b6ba8aa475f |
SHA1: | 7f2ce245c72d8689aaa7460cd6d12db57b9c36ba |
SHA256: | 8001af6bbc3cc10b1382c5efc800e479804ad1e30f0d99a57add656a811afbcd |
SHA512: | ab2c9443ab55e81d17ca452a4d0508f52e3a3ac23801e4d6375496a6fd230094b5cb2991bd467087f03d27bc3da387973d308880402d565899177722be5be032 |
SSDEEP: | 3072:tOe0QuzbNAj5HG/NTG7U+L50CyxF9Dav/cGKt6KUCIqzpjAqMi:we0QCyj5Ho08/4/wVIqzpjAqh |
TLSH: | D344F7816AF16C13FFB64B314E39D9942A3FBCA25E7572DFA100760F187B1A1A513B12 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................U.c.......q.......`.......v......E........................a.......d.....Rich....................PE..L......d... |
Icon Hash: | 17694cb2b24d2117 |
Entrypoint: | 0x401a22 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x64BAF5C9 [Fri Jul 21 21:16:57 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | dc51987737c4af4f71f5c3733cf2b1f2 |
Instruction |
---|
call 00007FF694E054C2h |
jmp 00007FF694E01D3Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [0041C650h], eax |
mov dword ptr [0041C64Ch], ecx |
mov dword ptr [0041C648h], edx |
mov dword ptr [0041C644h], ebx |
mov dword ptr [0041C640h], esi |
mov dword ptr [0041C63Ch], edi |
mov word ptr [0041C668h], ss |
mov word ptr [0041C65Ch], cs |
mov word ptr [0041C638h], ds |
mov word ptr [0041C634h], es |
mov word ptr [0041C630h], fs |
mov word ptr [0041C62Ch], gs |
pushfd |
pop dword ptr [0041C660h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [0041C654h], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [0041C658h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [0041C664h], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [0041C5A0h], 00010001h |
mov eax, dword ptr [0041C658h] |
mov dword ptr [0041C554h], eax |
mov dword ptr [0041C548h], C0000409h |
mov dword ptr [0041C54Ch], 00000001h |
mov eax, dword ptr [0041B008h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [0041B00Ch] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000D8h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x1985c | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x2725000 | 0x22dd0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x18000 | 0x19c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x167af | 0x16800 | 43c1bbcfda4f28a6db426899f1d4530d | False | 0.80537109375 | data | 7.5080418109409415 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x18000 | 0x21b0 | 0x2200 | 8f7390606cfa5526c62a62295eb9b3af | False | 0.37247242647058826 | data | 5.561090816497167 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x1b000 | 0x270121c | 0x1600 | 4ed3ce2f485fe937021c499d3aa5b9cb | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.cip | 0x271d000 | 0x4400 | 0x3800 | b211778b80f6d441b6cf61ada776fc6d | False | 0.0025809151785714285 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.cer | 0x2722000 | 0x2800 | 0x2800 | 1276481102f218c981e0324180bafd9f | False | 0.00322265625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x2725000 | 0x22dd0 | 0x22e00 | 98cbbd9c6f082883c092beb04fa7479f | False | 0.3801873319892473 | data | 4.840484397561957 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0x273d678 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x273d7a8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_CURSOR | 0x273fd78 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x273fea8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_ICON | 0x2725b50 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.5674307036247335 |
RT_ICON | 0x27269f8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.6376353790613718 |
RT_ICON | 0x27272a0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.6849078341013825 |
RT_ICON | 0x2727968 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.7456647398843931 |
RT_ICON | 0x2727ed0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | Turkish | Turkey | 0.512863070539419 |
RT_ICON | 0x272a478 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | Turkish | Turkey | 0.6137429643527205 |
RT_ICON | 0x272b520 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | Turkish | Turkey | 0.6163934426229508 |
RT_ICON | 0x272bea8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | Turkish | Turkey | 0.7553191489361702 |
RT_ICON | 0x272c388 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.39925373134328357 |
RT_ICON | 0x272d230 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.5036101083032491 |
RT_ICON | 0x272dad8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.5264976958525346 |
RT_ICON | 0x272e1a0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.5570809248554913 |
RT_ICON | 0x272e708 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Turkish | Turkey | 0.3549792531120332 |
RT_ICON | 0x2730cb0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Turkish | Turkey | 0.38320825515947465 |
RT_ICON | 0x2731d58 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Turkish | Turkey | 0.4036885245901639 |
RT_ICON | 0x27326e0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Turkish | Turkey | 0.42021276595744683 |
RT_ICON | 0x2732bc0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.39285714285714285 |
RT_ICON | 0x2733a68 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5537003610108303 |
RT_ICON | 0x2734310 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.6226958525345622 |
RT_ICON | 0x27349d8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6372832369942196 |
RT_ICON | 0x2734f40 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.425422138836773 |
RT_ICON | 0x2735fe8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.4209016393442623 |
RT_ICON | 0x2736970 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.46187943262411346 |
RT_ICON | 0x2736e40 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.279317697228145 |
RT_ICON | 0x2737ce8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.3664259927797834 |
RT_ICON | 0x2738590 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.3773041474654378 |
RT_ICON | 0x2738c58 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.3764450867052023 |
RT_ICON | 0x27391c0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.2587136929460581 |
RT_ICON | 0x273b768 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.27345215759849906 |
RT_ICON | 0x273c810 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.28852459016393445 |
RT_ICON | 0x273d198 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.32180851063829785 |
RT_STRING | 0x2742630 | 0xaa | data | 0.5588235294117647 | ||
RT_STRING | 0x27426e0 | 0x600 | data | 0.4361979166666667 | ||
RT_STRING | 0x2742ce0 | 0x460 | data | 0.45 | ||
RT_STRING | 0x2743140 | 0x64a | data | 0.4360248447204969 | ||
RT_STRING | 0x2743790 | 0x7b4 | data | 0.417342799188641 | ||
RT_STRING | 0x2743f48 | 0x6d0 | data | 0.4294724770642202 | ||
RT_STRING | 0x2744618 | 0x76c | data | 0.42526315789473684 | ||
RT_STRING | 0x2744d88 | 0x606 | data | 0.4455252918287938 | ||
RT_STRING | 0x2745390 | 0x7c2 | data | 0.42245720040281975 | ||
RT_STRING | 0x2745b58 | 0x810 | data | 0.42102713178294576 | ||
RT_STRING | 0x2746368 | 0x584 | data | 0.4461756373937677 | ||
RT_STRING | 0x27468f0 | 0x74c | data | 0.4234475374732334 | ||
RT_STRING | 0x2747040 | 0x710 | data | 0.4303097345132743 | ||
RT_STRING | 0x2747750 | 0x5f6 | data | 0.4325032765399738 | ||
RT_STRING | 0x2747d48 | 0x88 | data | 0.625 | ||
RT_GROUP_CURSOR | 0x273fd50 | 0x22 | data | 1.0588235294117647 | ||
RT_GROUP_CURSOR | 0x2742450 | 0x22 | data | 1.088235294117647 | ||
RT_GROUP_ICON | 0x2732b48 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x273d600 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x272c310 | 0x76 | data | Turkish | Turkey | 0.6610169491525424 |
RT_GROUP_ICON | 0x2736dd8 | 0x68 | data | Turkish | Turkey | 0.7211538461538461 |
RT_VERSION | 0x2742478 | 0x1b4 | data | 0.5756880733944955 |
DLL | Import |
---|---|
KERNEL32.dll | OpenJobObjectA, ReadConsoleA, InterlockedDecrement, GlobalSize, SetDefaultCommConfigW, QueryDosDeviceA, GetComputerNameW, SetEvent, GetNumaAvailableMemoryNode, FreeEnvironmentStringsA, GetModuleHandleW, GetConsoleAliasesLengthA, SetCommState, GetConsoleWindow, ReadConsoleOutputW, GetVersionExW, GetStringTypeExW, HeapDestroy, GetFileAttributesA, DeleteVolumeMountPointA, DisconnectNamedPipe, LCMapStringA, GetLastError, GetProcAddress, MoveFileW, SetStdHandle, LoadLibraryA, InterlockedExchangeAdd, LocalAlloc, WritePrivateProfileStringA, GetModuleFileNameA, BuildCommDCBA, FatalAppExitA, GetShortPathNameW, SetCalendarInfoA, FindAtomW, SearchPathW, GetNumaProcessorNode, GetConsoleFontSize, PulseEvent, HeapAlloc, MultiByteToWideChar, Sleep, ExitProcess, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapFree, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, WriteFile, GetStdHandle, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, InitializeCriticalSectionAndSpinCount, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, SetFilePointer, GetConsoleCP, GetConsoleMode, FlushFileBuffers, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CloseHandle, CreateFileA |
GDI32.dll | GetBoundsRect |
ADVAPI32.dll | ClearEventLogW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkish | Turkey |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-14T06:02:41.580888+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49862 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:43.242369+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49873 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:44.741563+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49884 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:46.242232+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49895 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:47.819583+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49906 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:49.336141+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49917 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:50.858357+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49928 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:52.382811+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49939 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:53.931040+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49949 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:55.571568+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49960 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:57.199668+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49972 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:02:58.792799+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49983 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:00.282605+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49994 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:02.013801+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49996 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:03.632852+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49997 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:05.160241+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 49999 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:06.773833+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50001 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:08.494699+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50002 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:10.116735+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50003 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:11.620256+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50004 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:13.111163+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50005 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:14.871674+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50006 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:16.441473+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50007 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:18.047258+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50008 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:19.642690+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50009 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:21.149882+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50010 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:22.762582+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50011 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:24.252561+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50012 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:25.849542+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50013 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:27.421559+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50014 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:29.192946+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50015 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:30.817494+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50016 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:32.304663+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50017 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:34.246847+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50018 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:03:36.144916+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50019 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:04:45.418789+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50023 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:04:51.149380+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50024 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:04:58.244487+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50025 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:05:04.062889+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50026 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:05:10.088773+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50027 | 125.7.253.10 | 80 | TCP |
2024-10-14T06:05:18.035144+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50028 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:24.004900+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50030 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:31.785512+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50031 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:37.620142+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50032 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:43.752844+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50033 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:49.451325+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50034 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:05:55.638546+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50035 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:06:00.592981+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50036 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:06:06.826789+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50037 | 211.171.233.129 | 80 | TCP |
2024-10-14T06:06:13.270043+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.6 | 50038 | 211.171.233.129 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 14, 2024 06:02:40.025950909 CEST | 49862 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:40.032541990 CEST | 80 | 49862 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:40.032609940 CEST | 49862 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:40.032846928 CEST | 49862 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:40.032867908 CEST | 49862 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:40.040524006 CEST | 80 | 49862 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:40.040539026 CEST | 80 | 49862 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:41.580789089 CEST | 80 | 49862 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:41.580813885 CEST | 80 | 49862 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:41.580888033 CEST | 49862 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:41.581661940 CEST | 49862 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:41.587639093 CEST | 80 | 49862 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:41.589195967 CEST | 49873 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:41.594316959 CEST | 80 | 49873 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:41.594394922 CEST | 49873 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:41.594649076 CEST | 49873 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:41.594671965 CEST | 49873 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:41.599529028 CEST | 80 | 49873 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:41.599581957 CEST | 80 | 49873 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:43.242265940 CEST | 80 | 49873 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:43.242290020 CEST | 80 | 49873 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:43.242368937 CEST | 49873 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:43.242588997 CEST | 49873 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:43.246500015 CEST | 49884 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:43.247342110 CEST | 80 | 49873 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:43.254968882 CEST | 80 | 49884 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:43.255060911 CEST | 49884 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:43.255192995 CEST | 49884 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:43.255213976 CEST | 49884 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:43.262501955 CEST | 80 | 49884 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:43.262671947 CEST | 80 | 49884 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:44.741344929 CEST | 80 | 49884 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:44.741503954 CEST | 80 | 49884 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:44.741563082 CEST | 49884 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:44.741604090 CEST | 49884 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:44.744487047 CEST | 49895 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:44.746642113 CEST | 80 | 49884 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:44.749469995 CEST | 80 | 49895 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:44.749548912 CEST | 49895 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:44.749665976 CEST | 49895 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:44.749686003 CEST | 49895 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:44.754625082 CEST | 80 | 49895 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:44.754796028 CEST | 80 | 49895 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:46.242067099 CEST | 80 | 49895 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:46.242105961 CEST | 80 | 49895 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:46.242232084 CEST | 49895 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:46.242408991 CEST | 49895 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:46.244980097 CEST | 49906 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:46.247126102 CEST | 80 | 49895 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:46.249728918 CEST | 80 | 49906 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:46.249994993 CEST | 49906 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:46.250042915 CEST | 49906 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:46.250042915 CEST | 49906 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:46.254798889 CEST | 80 | 49906 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:46.254945993 CEST | 80 | 49906 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:47.819247007 CEST | 80 | 49906 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:47.819500923 CEST | 80 | 49906 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:47.819582939 CEST | 49906 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:47.819700003 CEST | 49906 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:47.822145939 CEST | 49917 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:47.824464083 CEST | 80 | 49906 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:47.827965021 CEST | 80 | 49917 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:47.828056097 CEST | 49917 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:47.828154087 CEST | 49917 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:47.828191996 CEST | 49917 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:47.833005905 CEST | 80 | 49917 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:47.833122969 CEST | 80 | 49917 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:49.335956097 CEST | 80 | 49917 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:49.336078882 CEST | 80 | 49917 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:49.336141109 CEST | 49917 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:49.336230993 CEST | 49917 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:49.339163065 CEST | 49928 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:49.341037035 CEST | 80 | 49917 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:49.343990088 CEST | 80 | 49928 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:49.344108105 CEST | 49928 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:49.344197035 CEST | 49928 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:49.344212055 CEST | 49928 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:49.348948002 CEST | 80 | 49928 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:49.348958015 CEST | 80 | 49928 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:50.857863903 CEST | 80 | 49928 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:50.857980013 CEST | 80 | 49928 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:50.858356953 CEST | 49928 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:50.858356953 CEST | 49928 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:50.861288071 CEST | 49939 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:50.863296032 CEST | 80 | 49928 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:50.866193056 CEST | 80 | 49939 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:50.866262913 CEST | 49939 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:50.866394997 CEST | 49939 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:50.866425037 CEST | 49939 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:50.871141911 CEST | 80 | 49939 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:50.871159077 CEST | 80 | 49939 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:52.382548094 CEST | 80 | 49939 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:52.382668018 CEST | 80 | 49939 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:52.382811069 CEST | 49939 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:52.382857084 CEST | 49939 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:52.385863066 CEST | 49949 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:52.388874054 CEST | 80 | 49939 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:52.391772032 CEST | 80 | 49949 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:52.391956091 CEST | 49949 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:52.391983032 CEST | 49949 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:52.392024040 CEST | 49949 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:52.412863970 CEST | 80 | 49949 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:52.412879944 CEST | 80 | 49949 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:53.929398060 CEST | 80 | 49949 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:53.929459095 CEST | 80 | 49949 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:53.931040049 CEST | 49949 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:53.932104111 CEST | 49949 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:53.937017918 CEST | 80 | 49949 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:53.939063072 CEST | 49960 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:53.944382906 CEST | 80 | 49960 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:53.947237968 CEST | 49960 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:53.950583935 CEST | 49960 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:53.950615883 CEST | 49960 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:53.956269979 CEST | 80 | 49960 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:53.956836939 CEST | 80 | 49960 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:55.571316004 CEST | 80 | 49960 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:55.571408987 CEST | 80 | 49960 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:55.571568012 CEST | 49960 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:55.571636915 CEST | 49960 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:55.574814081 CEST | 49972 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:55.577410936 CEST | 80 | 49960 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:55.579849958 CEST | 80 | 49972 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:55.579982996 CEST | 49972 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:55.580125093 CEST | 49972 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:55.580125093 CEST | 49972 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:55.584933996 CEST | 80 | 49972 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:55.585016966 CEST | 80 | 49972 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:57.199507952 CEST | 80 | 49972 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:57.199559927 CEST | 80 | 49972 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:57.199667931 CEST | 49972 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:57.200160980 CEST | 49972 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:57.203012943 CEST | 49983 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:57.204972982 CEST | 80 | 49972 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:57.207842112 CEST | 80 | 49983 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:57.207912922 CEST | 49983 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:57.208039999 CEST | 49983 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:57.208080053 CEST | 49983 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:57.212776899 CEST | 80 | 49983 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:57.212939024 CEST | 80 | 49983 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:58.792424917 CEST | 80 | 49983 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:58.792507887 CEST | 80 | 49983 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:58.792798996 CEST | 49983 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:58.792840004 CEST | 49983 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:58.795728922 CEST | 49994 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:58.797585964 CEST | 80 | 49983 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:58.800518990 CEST | 80 | 49994 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:58.800605059 CEST | 49994 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:58.800740957 CEST | 49994 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:58.800764084 CEST | 49994 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:02:58.805566072 CEST | 80 | 49994 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:02:58.805588961 CEST | 80 | 49994 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:00.281709909 CEST | 80 | 49994 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:00.282293081 CEST | 80 | 49994 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:00.282604933 CEST | 49994 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:00.303474903 CEST | 49994 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:00.308234930 CEST | 80 | 49994 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:00.425460100 CEST | 49996 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:00.430283070 CEST | 80 | 49996 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:00.430362940 CEST | 49996 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:00.430532932 CEST | 49996 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:00.430532932 CEST | 49996 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:00.435278893 CEST | 80 | 49996 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:00.435607910 CEST | 80 | 49996 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:02.013729095 CEST | 80 | 49996 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:02.013747931 CEST | 80 | 49996 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:02.013801098 CEST | 49996 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:02.013972998 CEST | 49996 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:02.016624928 CEST | 49997 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:02.018723965 CEST | 80 | 49996 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:02.021451950 CEST | 80 | 49997 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:02.021528006 CEST | 49997 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:02.021666050 CEST | 49997 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:02.021719933 CEST | 49997 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:02.026429892 CEST | 80 | 49997 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:02.026612997 CEST | 80 | 49997 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:03.632520914 CEST | 80 | 49997 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:03.632677078 CEST | 80 | 49997 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:03.632852077 CEST | 49997 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:03.632947922 CEST | 49997 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:03.635435104 CEST | 49999 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:03.637784958 CEST | 80 | 49997 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:03.640347004 CEST | 80 | 49999 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:03.640429974 CEST | 49999 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:03.640562057 CEST | 49999 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:03.640578985 CEST | 49999 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:03.645299911 CEST | 80 | 49999 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:03.645558119 CEST | 80 | 49999 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:05.159991026 CEST | 80 | 49999 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:05.160130978 CEST | 80 | 49999 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:05.160240889 CEST | 49999 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:05.160463095 CEST | 49999 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:05.165219069 CEST | 80 | 49999 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:05.168296099 CEST | 50001 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:05.173109055 CEST | 80 | 50001 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:05.173202038 CEST | 50001 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:05.173413038 CEST | 50001 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:05.173717022 CEST | 50001 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:05.178136110 CEST | 80 | 50001 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:05.178442001 CEST | 80 | 50001 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:06.773724079 CEST | 80 | 50001 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:06.773763895 CEST | 80 | 50001 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:06.773833036 CEST | 50001 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:06.774007082 CEST | 50001 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:06.777297020 CEST | 50002 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:06.780149937 CEST | 80 | 50001 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:06.783360004 CEST | 80 | 50002 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:06.783536911 CEST | 50002 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:06.783716917 CEST | 50002 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:06.783741951 CEST | 50002 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:06.789134026 CEST | 80 | 50002 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:06.789211988 CEST | 80 | 50002 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:08.494596004 CEST | 80 | 50002 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:08.494635105 CEST | 80 | 50002 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:08.494692087 CEST | 80 | 50002 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:08.494699001 CEST | 50002 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:08.494736910 CEST | 50002 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:08.494962931 CEST | 50002 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:08.497975111 CEST | 50003 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:08.499794960 CEST | 80 | 50002 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:08.502835035 CEST | 80 | 50003 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:08.502958059 CEST | 50003 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:08.503218889 CEST | 50003 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:08.503252983 CEST | 50003 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:08.508008957 CEST | 80 | 50003 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:08.508171082 CEST | 80 | 50003 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:10.116532087 CEST | 80 | 50003 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:10.116662979 CEST | 80 | 50003 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:10.116734982 CEST | 50003 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:10.117698908 CEST | 50003 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:10.121913910 CEST | 50004 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:10.122476101 CEST | 80 | 50003 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:10.126740932 CEST | 80 | 50004 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:10.126835108 CEST | 50004 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:10.127156973 CEST | 50004 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:10.127182007 CEST | 50004 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:10.131994009 CEST | 80 | 50004 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:10.132005930 CEST | 80 | 50004 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:11.620177984 CEST | 80 | 50004 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:11.620196104 CEST | 80 | 50004 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:11.620255947 CEST | 50004 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:11.620501995 CEST | 50004 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:11.623652935 CEST | 50005 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:11.628087044 CEST | 80 | 50004 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:11.631289959 CEST | 80 | 50005 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:11.631561041 CEST | 50005 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:11.631721020 CEST | 50005 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:11.631755114 CEST | 50005 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:11.638897896 CEST | 80 | 50005 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:11.638907909 CEST | 80 | 50005 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:13.110871077 CEST | 80 | 50005 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:13.111001968 CEST | 80 | 50005 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:13.111162901 CEST | 50005 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:13.111265898 CEST | 50005 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:13.113769054 CEST | 50006 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:13.116951942 CEST | 80 | 50005 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:13.119976997 CEST | 80 | 50006 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:13.120055914 CEST | 50006 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:13.120213985 CEST | 50006 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:13.120213985 CEST | 50006 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:13.126080990 CEST | 80 | 50006 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:13.126672983 CEST | 80 | 50006 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:14.871304035 CEST | 80 | 50006 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:14.871526003 CEST | 80 | 50006 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:14.871674061 CEST | 50006 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:14.871865988 CEST | 50006 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:14.874526978 CEST | 50007 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:14.876704931 CEST | 80 | 50006 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:14.879425049 CEST | 80 | 50007 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:14.883253098 CEST | 50007 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:14.883373976 CEST | 50007 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:14.883388996 CEST | 50007 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:14.888149023 CEST | 80 | 50007 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:14.888326883 CEST | 80 | 50007 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:16.441132069 CEST | 80 | 50007 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:16.441256046 CEST | 80 | 50007 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:16.441473007 CEST | 50007 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:16.441533089 CEST | 50007 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:16.444164991 CEST | 50008 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:16.446314096 CEST | 80 | 50007 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:16.449058056 CEST | 80 | 50008 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:16.449140072 CEST | 50008 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:16.449224949 CEST | 50008 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:16.449242115 CEST | 50008 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:16.454006910 CEST | 80 | 50008 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:16.454152107 CEST | 80 | 50008 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:18.047068119 CEST | 80 | 50008 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:18.047199011 CEST | 80 | 50008 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:18.047257900 CEST | 50008 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:18.051579952 CEST | 50008 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:18.054497957 CEST | 50009 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:18.056449890 CEST | 80 | 50008 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:18.059350014 CEST | 80 | 50009 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:18.059448957 CEST | 50009 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:18.059562922 CEST | 50009 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:18.059576035 CEST | 50009 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:18.064452887 CEST | 80 | 50009 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:18.064482927 CEST | 80 | 50009 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:19.642184973 CEST | 80 | 50009 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:19.642496109 CEST | 80 | 50009 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:19.642689943 CEST | 50009 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:19.642844915 CEST | 50009 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:19.645824909 CEST | 50010 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:19.649708986 CEST | 80 | 50009 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:19.652997971 CEST | 80 | 50010 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:19.653191090 CEST | 50010 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:19.653225899 CEST | 50010 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:19.653278112 CEST | 50010 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:19.658183098 CEST | 80 | 50010 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:19.658227921 CEST | 80 | 50010 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:21.149692059 CEST | 80 | 50010 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:21.149817944 CEST | 80 | 50010 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:21.149882078 CEST | 50010 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:21.150099039 CEST | 50010 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:21.152676105 CEST | 50011 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:21.154891014 CEST | 80 | 50010 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:21.157593012 CEST | 80 | 50011 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:21.157727003 CEST | 50011 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:21.158194065 CEST | 50011 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:21.158229113 CEST | 50011 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:21.163177013 CEST | 80 | 50011 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:21.163208008 CEST | 80 | 50011 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:22.762264013 CEST | 80 | 50011 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:22.762435913 CEST | 80 | 50011 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:22.762582064 CEST | 50011 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:22.762660980 CEST | 50011 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:22.767488003 CEST | 80 | 50011 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:22.768412113 CEST | 50012 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:22.773644924 CEST | 80 | 50012 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:22.773803949 CEST | 50012 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:22.773956060 CEST | 50012 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:22.773974895 CEST | 50012 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:22.778783083 CEST | 80 | 50012 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:22.778902054 CEST | 80 | 50012 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:24.251450062 CEST | 80 | 50012 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:24.252487898 CEST | 80 | 50012 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:24.252561092 CEST | 50012 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:24.252649069 CEST | 50012 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:24.257479906 CEST | 80 | 50012 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:24.264885902 CEST | 50013 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:24.269844055 CEST | 80 | 50013 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:24.270028114 CEST | 50013 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:24.270028114 CEST | 50013 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:24.270092964 CEST | 50013 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:24.274941921 CEST | 80 | 50013 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:24.274971962 CEST | 80 | 50013 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:25.849334002 CEST | 80 | 50013 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:25.849361897 CEST | 80 | 50013 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:25.849541903 CEST | 50013 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:25.850030899 CEST | 50013 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:25.853420973 CEST | 50014 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:25.854768038 CEST | 80 | 50013 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:25.858289003 CEST | 80 | 50014 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:25.858442068 CEST | 50014 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:25.858557940 CEST | 50014 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:25.858557940 CEST | 50014 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:25.863465071 CEST | 80 | 50014 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:25.863487959 CEST | 80 | 50014 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:27.421068907 CEST | 80 | 50014 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:27.421295881 CEST | 80 | 50014 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:27.421559095 CEST | 50014 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:27.421588898 CEST | 50014 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:27.425126076 CEST | 50015 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:27.426342964 CEST | 80 | 50014 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:27.429918051 CEST | 80 | 50015 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:27.430119038 CEST | 50015 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:27.430206060 CEST | 50015 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:27.430206060 CEST | 50015 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:27.436080933 CEST | 80 | 50015 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:27.437211990 CEST | 80 | 50015 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:29.192805052 CEST | 80 | 50015 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:29.192902088 CEST | 80 | 50015 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:29.192945957 CEST | 50015 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:29.193065882 CEST | 50015 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:29.197845936 CEST | 80 | 50015 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:29.198802948 CEST | 50016 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:29.203674078 CEST | 80 | 50016 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:29.203737974 CEST | 50016 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:29.203883886 CEST | 50016 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:29.204062939 CEST | 50016 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:29.208640099 CEST | 80 | 50016 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:29.208779097 CEST | 80 | 50016 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:30.817409039 CEST | 80 | 50016 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:30.817430973 CEST | 80 | 50016 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:30.817493916 CEST | 50016 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:30.817688942 CEST | 50016 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:30.820821047 CEST | 50017 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:30.822470903 CEST | 80 | 50016 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:30.825829983 CEST | 80 | 50017 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:30.825891972 CEST | 50017 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:30.826036930 CEST | 50017 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:30.826054096 CEST | 50017 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:30.830816984 CEST | 80 | 50017 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:30.830827951 CEST | 80 | 50017 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:32.304296970 CEST | 80 | 50017 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:32.304611921 CEST | 80 | 50017 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:32.304662943 CEST | 50017 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:32.304708958 CEST | 50017 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:32.307529926 CEST | 50018 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:32.309492111 CEST | 80 | 50017 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:32.312325954 CEST | 80 | 50018 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:32.312400103 CEST | 50018 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:32.312530994 CEST | 50018 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:32.312586069 CEST | 50018 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:32.317257881 CEST | 80 | 50018 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:32.318058968 CEST | 80 | 50018 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:34.246735096 CEST | 80 | 50018 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:34.246750116 CEST | 80 | 50018 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:34.246846914 CEST | 50018 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:34.262536049 CEST | 50018 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:34.268454075 CEST | 80 | 50018 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:34.559097052 CEST | 50019 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:34.563999891 CEST | 80 | 50019 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:34.564124107 CEST | 50019 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:34.564255953 CEST | 50019 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:34.564279079 CEST | 50019 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:34.569087029 CEST | 80 | 50019 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:34.569169998 CEST | 80 | 50019 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:36.144678116 CEST | 80 | 50019 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:36.144823074 CEST | 80 | 50019 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:03:36.144916058 CEST | 50019 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:36.145157099 CEST | 50019 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:03:36.151093960 CEST | 80 | 50019 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:43.886802912 CEST | 50023 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:43.891743898 CEST | 80 | 50023 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:43.891823053 CEST | 50023 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:43.891976118 CEST | 50023 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:43.891976118 CEST | 50023 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:43.898107052 CEST | 80 | 50023 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:43.899669886 CEST | 80 | 50023 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:45.418653011 CEST | 80 | 50023 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:45.418693066 CEST | 80 | 50023 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:45.418788910 CEST | 50023 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:45.419913054 CEST | 50023 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:45.424691916 CEST | 80 | 50023 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:49.583843946 CEST | 50024 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:49.589390039 CEST | 80 | 50024 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:49.589489937 CEST | 50024 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:49.589613914 CEST | 50024 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:49.589648962 CEST | 50024 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:49.594459057 CEST | 80 | 50024 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:49.594595909 CEST | 80 | 50024 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:51.149257898 CEST | 80 | 50024 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:51.149308920 CEST | 80 | 50024 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:51.149379969 CEST | 50024 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:51.149580956 CEST | 50024 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:51.154400110 CEST | 80 | 50024 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:56.724909067 CEST | 50025 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:56.729919910 CEST | 80 | 50025 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:56.730031967 CEST | 50025 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:56.730218887 CEST | 50025 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:56.730258942 CEST | 50025 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:56.734994888 CEST | 80 | 50025 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:56.735008001 CEST | 80 | 50025 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:58.244179964 CEST | 80 | 50025 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:58.244283915 CEST | 80 | 50025 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:04:58.244487047 CEST | 50025 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:58.244621992 CEST | 50025 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:04:58.249521971 CEST | 80 | 50025 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:02.499749899 CEST | 50026 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:02.504981995 CEST | 80 | 50026 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:02.506556034 CEST | 50026 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:02.506752014 CEST | 50026 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:02.506829977 CEST | 50026 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:02.511853933 CEST | 80 | 50026 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:02.511872053 CEST | 80 | 50026 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:04.062722921 CEST | 80 | 50026 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:04.062818050 CEST | 80 | 50026 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:04.062889099 CEST | 50026 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:04.086353064 CEST | 50026 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:04.091259956 CEST | 80 | 50026 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:08.607712984 CEST | 50027 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:08.613080025 CEST | 80 | 50027 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:08.613198996 CEST | 50027 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:08.613362074 CEST | 50027 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:08.613362074 CEST | 50027 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:08.618210077 CEST | 80 | 50027 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:08.618359089 CEST | 80 | 50027 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:10.088608027 CEST | 80 | 50027 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:10.088699102 CEST | 80 | 50027 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:10.088773012 CEST | 50027 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:10.088891029 CEST | 50027 | 80 | 192.168.2.6 | 125.7.253.10 |
Oct 14, 2024 06:05:10.093709946 CEST | 80 | 50027 | 125.7.253.10 | 192.168.2.6 |
Oct 14, 2024 06:05:16.541982889 CEST | 50028 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:16.546932936 CEST | 80 | 50028 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:16.547058105 CEST | 50028 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:16.547518969 CEST | 50028 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:16.547554970 CEST | 50028 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:16.552606106 CEST | 80 | 50028 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:16.552635908 CEST | 80 | 50028 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:18.034732103 CEST | 80 | 50028 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:18.035060883 CEST | 80 | 50028 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:18.035144091 CEST | 50028 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:18.035245895 CEST | 50028 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:18.040147066 CEST | 80 | 50028 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:22.422699928 CEST | 50030 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:22.427797079 CEST | 80 | 50030 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:22.429400921 CEST | 50030 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:22.429583073 CEST | 50030 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:22.429619074 CEST | 50030 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:22.434434891 CEST | 80 | 50030 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:22.434561014 CEST | 80 | 50030 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:24.004805088 CEST | 80 | 50030 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:24.004853964 CEST | 80 | 50030 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:24.004899979 CEST | 50030 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:24.005111933 CEST | 50030 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:24.009852886 CEST | 80 | 50030 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:30.240297079 CEST | 50031 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:30.248635054 CEST | 80 | 50031 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:30.250374079 CEST | 50031 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:30.250528097 CEST | 50031 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:30.250555038 CEST | 50031 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:30.258167982 CEST | 80 | 50031 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:30.258184910 CEST | 80 | 50031 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:31.785276890 CEST | 80 | 50031 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:31.785337925 CEST | 80 | 50031 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:31.785511971 CEST | 50031 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:31.802289009 CEST | 50031 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:31.807192087 CEST | 80 | 50031 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:36.015259981 CEST | 50032 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:36.020276070 CEST | 80 | 50032 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:36.023456097 CEST | 50032 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:36.023633003 CEST | 50032 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:36.023652077 CEST | 50032 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:36.028383970 CEST | 80 | 50032 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:36.028527975 CEST | 80 | 50032 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:37.619925022 CEST | 80 | 50032 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:37.619946003 CEST | 80 | 50032 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:37.620141983 CEST | 50032 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:37.627446890 CEST | 50032 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:37.632394075 CEST | 80 | 50032 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:42.118025064 CEST | 50033 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:42.123656988 CEST | 80 | 50033 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:42.127213955 CEST | 50033 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:42.127414942 CEST | 50033 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:42.127444983 CEST | 50033 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:42.132190943 CEST | 80 | 50033 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:42.132280111 CEST | 80 | 50033 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:43.752674103 CEST | 80 | 50033 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:43.752775908 CEST | 80 | 50033 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:43.752844095 CEST | 50033 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:43.752986908 CEST | 50033 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:43.758641005 CEST | 80 | 50033 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:47.910743952 CEST | 50034 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:47.915771961 CEST | 80 | 50034 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:47.919455051 CEST | 50034 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:47.919637918 CEST | 50034 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:47.919661045 CEST | 50034 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:47.924388885 CEST | 80 | 50034 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:47.924493074 CEST | 80 | 50034 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:49.450983047 CEST | 80 | 50034 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:49.451270103 CEST | 80 | 50034 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:49.451324940 CEST | 50034 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:49.451364040 CEST | 50034 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:49.456125021 CEST | 80 | 50034 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:53.113256931 CEST | 50035 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:53.118541956 CEST | 80 | 50035 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:53.119483948 CEST | 50035 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:53.119637966 CEST | 50035 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:53.119656086 CEST | 50035 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:53.124546051 CEST | 80 | 50035 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:53.124577045 CEST | 80 | 50035 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:55.638432980 CEST | 80 | 50035 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:55.638457060 CEST | 80 | 50035 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:55.638545990 CEST | 50035 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:55.638787031 CEST | 50035 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:55.643518925 CEST | 80 | 50035 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:59.054759979 CEST | 50036 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:59.059921026 CEST | 80 | 50036 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:59.062072039 CEST | 50036 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:59.062105894 CEST | 50036 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:59.062125921 CEST | 50036 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:05:59.066992998 CEST | 80 | 50036 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:05:59.067147970 CEST | 80 | 50036 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:00.592765093 CEST | 80 | 50036 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:00.592866898 CEST | 80 | 50036 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:00.592981100 CEST | 50036 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:00.605973959 CEST | 50036 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:00.610966921 CEST | 80 | 50036 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:04.577682972 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:04.583138943 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:04.583221912 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:04.583408117 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:04.583408117 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:04.588236094 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:04.588387966 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:06.826704979 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:06.826725960 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:06.826734066 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:06.826754093 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:06.826762915 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:06.826788902 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:06.826857090 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:06.826966047 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:06.826966047 CEST | 50037 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:06.831743956 CEST | 80 | 50037 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:11.770308018 CEST | 50038 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:11.775631905 CEST | 80 | 50038 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:11.775715113 CEST | 50038 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:11.776343107 CEST | 50038 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:11.776376009 CEST | 50038 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:11.781261921 CEST | 80 | 50038 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:11.781315088 CEST | 80 | 50038 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:13.269507885 CEST | 80 | 50038 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:13.269561052 CEST | 80 | 50038 | 211.171.233.129 | 192.168.2.6 |
Oct 14, 2024 06:06:13.270042896 CEST | 50038 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:13.270133972 CEST | 50038 | 80 | 192.168.2.6 | 211.171.233.129 |
Oct 14, 2024 06:06:13.275003910 CEST | 80 | 50038 | 211.171.233.129 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 14, 2024 06:02:35.865875006 CEST | 50932 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 14, 2024 06:02:36.859611034 CEST | 50932 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 14, 2024 06:02:37.875413895 CEST | 50932 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 14, 2024 06:02:39.880238056 CEST | 50932 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 14, 2024 06:02:40.024979115 CEST | 53 | 50932 | 1.1.1.1 | 192.168.2.6 |
Oct 14, 2024 06:02:40.025001049 CEST | 53 | 50932 | 1.1.1.1 | 192.168.2.6 |
Oct 14, 2024 06:02:40.025012016 CEST | 53 | 50932 | 1.1.1.1 | 192.168.2.6 |
Oct 14, 2024 06:02:40.025026083 CEST | 53 | 50932 | 1.1.1.1 | 192.168.2.6 |
Oct 14, 2024 06:05:13.547768116 CEST | 56060 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 14, 2024 06:05:14.563180923 CEST | 56060 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 14, 2024 06:05:15.562882900 CEST | 56060 | 53 | 192.168.2.6 | 1.1.1.1 |
Oct 14, 2024 06:05:16.538158894 CEST | 53 | 56060 | 1.1.1.1 | 192.168.2.6 |
Oct 14, 2024 06:05:16.538187027 CEST | 53 | 56060 | 1.1.1.1 | 192.168.2.6 |
Oct 14, 2024 06:05:16.538199902 CEST | 53 | 56060 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 14, 2024 06:02:35.865875006 CEST | 192.168.2.6 | 1.1.1.1 | 0xe2f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 06:02:36.859611034 CEST | 192.168.2.6 | 1.1.1.1 | 0xe2f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 06:02:37.875413895 CEST | 192.168.2.6 | 1.1.1.1 | 0xe2f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 06:02:39.880238056 CEST | 192.168.2.6 | 1.1.1.1 | 0xe2f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 06:05:13.547768116 CEST | 192.168.2.6 | 1.1.1.1 | 0x1cd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 06:05:14.563180923 CEST | 192.168.2.6 | 1.1.1.1 | 0x1cd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 06:05:15.562882900 CEST | 192.168.2.6 | 1.1.1.1 | 0x1cd3 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 125.7.253.10 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.024979115 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 125.7.253.10 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025001049 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 125.7.253.10 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025012016 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 125.7.253.10 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:02:40.025026083 CEST | 1.1.1.1 | 192.168.2.6 | 0xe2f4 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538158894 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 125.7.253.10 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538187027 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 125.7.253.10 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 187.204.42.174 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 148.230.249.9 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 06:05:16.538199902 CEST | 1.1.1.1 | 192.168.2.6 | 0x1cd3 | No error (0) | 125.7.253.10 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49862 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:40.032846928 CEST | 279 | OUT | |
Oct 14, 2024 06:02:40.032867908 CEST | 303 | OUT | |
Oct 14, 2024 06:02:41.580789089 CEST | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49873 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:41.594649076 CEST | 282 | OUT | |
Oct 14, 2024 06:02:41.594671965 CEST | 178 | OUT | |
Oct 14, 2024 06:02:43.242265940 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49884 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:43.255192995 CEST | 280 | OUT | |
Oct 14, 2024 06:02:43.255213976 CEST | 222 | OUT | |
Oct 14, 2024 06:02:44.741344929 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49895 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:44.749665976 CEST | 279 | OUT | |
Oct 14, 2024 06:02:44.749686003 CEST | 295 | OUT | |
Oct 14, 2024 06:02:46.242067099 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49906 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:46.250042915 CEST | 282 | OUT | |
Oct 14, 2024 06:02:46.250042915 CEST | 241 | OUT | |
Oct 14, 2024 06:02:47.819247007 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49917 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:47.828154087 CEST | 280 | OUT | |
Oct 14, 2024 06:02:47.828191996 CEST | 230 | OUT | |
Oct 14, 2024 06:02:49.335956097 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49928 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:49.344197035 CEST | 278 | OUT | |
Oct 14, 2024 06:02:49.344212055 CEST | 353 | OUT | |
Oct 14, 2024 06:02:50.857863903 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49939 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:50.866394997 CEST | 279 | OUT | |
Oct 14, 2024 06:02:50.866425037 CEST | 341 | OUT | |
Oct 14, 2024 06:02:52.382548094 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.6 | 49949 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:52.391983032 CEST | 280 | OUT | |
Oct 14, 2024 06:02:52.392024040 CEST | 190 | OUT | |
Oct 14, 2024 06:02:53.929398060 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.6 | 49960 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:53.950583935 CEST | 282 | OUT | |
Oct 14, 2024 06:02:53.950615883 CEST | 247 | OUT | |
Oct 14, 2024 06:02:55.571316004 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.6 | 49972 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:55.580125093 CEST | 283 | OUT | |
Oct 14, 2024 06:02:55.580125093 CEST | 195 | OUT | |
Oct 14, 2024 06:02:57.199507952 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.6 | 49983 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:57.208039999 CEST | 278 | OUT | |
Oct 14, 2024 06:02:57.208080053 CEST | 196 | OUT | |
Oct 14, 2024 06:02:58.792424917 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.6 | 49994 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:02:58.800740957 CEST | 281 | OUT | |
Oct 14, 2024 06:02:58.800764084 CEST | 310 | OUT | |
Oct 14, 2024 06:03:00.281709909 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.6 | 49996 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:00.430532932 CEST | 283 | OUT | |
Oct 14, 2024 06:03:00.430532932 CEST | 213 | OUT | |
Oct 14, 2024 06:03:02.013729095 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.6 | 49997 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:02.021666050 CEST | 279 | OUT | |
Oct 14, 2024 06:03:02.021719933 CEST | 117 | OUT | |
Oct 14, 2024 06:03:03.632520914 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.6 | 49999 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:03.640562057 CEST | 280 | OUT | |
Oct 14, 2024 06:03:03.640578985 CEST | 250 | OUT | |
Oct 14, 2024 06:03:05.159991026 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.6 | 50001 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:05.173413038 CEST | 281 | OUT | |
Oct 14, 2024 06:03:05.173717022 CEST | 251 | OUT | |
Oct 14, 2024 06:03:06.773724079 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.6 | 50002 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:06.783716917 CEST | 282 | OUT | |
Oct 14, 2024 06:03:06.783741951 CEST | 210 | OUT | |
Oct 14, 2024 06:03:08.494596004 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.6 | 50003 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:08.503218889 CEST | 278 | OUT | |
Oct 14, 2024 06:03:08.503252983 CEST | 255 | OUT | |
Oct 14, 2024 06:03:10.116532087 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.6 | 50004 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:10.127156973 CEST | 282 | OUT | |
Oct 14, 2024 06:03:10.127182007 CEST | 338 | OUT | |
Oct 14, 2024 06:03:11.620177984 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.6 | 50005 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:11.631721020 CEST | 282 | OUT | |
Oct 14, 2024 06:03:11.631755114 CEST | 363 | OUT | |
Oct 14, 2024 06:03:13.110871077 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.6 | 50006 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:13.120213985 CEST | 281 | OUT | |
Oct 14, 2024 06:03:13.120213985 CEST | 172 | OUT | |
Oct 14, 2024 06:03:14.871304035 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.6 | 50007 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:14.883373976 CEST | 283 | OUT | |
Oct 14, 2024 06:03:14.883388996 CEST | 249 | OUT | |
Oct 14, 2024 06:03:16.441132069 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.6 | 50008 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:16.449224949 CEST | 281 | OUT | |
Oct 14, 2024 06:03:16.449242115 CEST | 188 | OUT | |
Oct 14, 2024 06:03:18.047068119 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.6 | 50009 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:18.059562922 CEST | 278 | OUT | |
Oct 14, 2024 06:03:18.059576035 CEST | 295 | OUT | |
Oct 14, 2024 06:03:19.642184973 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.6 | 50010 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:19.653225899 CEST | 279 | OUT | |
Oct 14, 2024 06:03:19.653278112 CEST | 159 | OUT | |
Oct 14, 2024 06:03:21.149692059 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.6 | 50011 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:21.158194065 CEST | 280 | OUT | |
Oct 14, 2024 06:03:21.158229113 CEST | 287 | OUT | |
Oct 14, 2024 06:03:22.762264013 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.6 | 50012 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:22.773956060 CEST | 282 | OUT | |
Oct 14, 2024 06:03:22.773974895 CEST | 154 | OUT | |
Oct 14, 2024 06:03:24.251450062 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.6 | 50013 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:24.270028114 CEST | 283 | OUT | |
Oct 14, 2024 06:03:24.270092964 CEST | 321 | OUT | |
Oct 14, 2024 06:03:25.849334002 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.6 | 50014 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:25.858557940 CEST | 282 | OUT | |
Oct 14, 2024 06:03:25.858557940 CEST | 219 | OUT | |
Oct 14, 2024 06:03:27.421068907 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.6 | 50015 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:27.430206060 CEST | 281 | OUT | |
Oct 14, 2024 06:03:27.430206060 CEST | 131 | OUT | |
Oct 14, 2024 06:03:29.192805052 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.6 | 50016 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:29.203883886 CEST | 279 | OUT | |
Oct 14, 2024 06:03:29.204062939 CEST | 182 | OUT | |
Oct 14, 2024 06:03:30.817409039 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.6 | 50017 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:30.826036930 CEST | 283 | OUT | |
Oct 14, 2024 06:03:30.826054096 CEST | 298 | OUT | |
Oct 14, 2024 06:03:32.304296970 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.6 | 50018 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:32.312530994 CEST | 283 | OUT | |
Oct 14, 2024 06:03:32.312586069 CEST | 223 | OUT | |
Oct 14, 2024 06:03:34.246735096 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.6 | 50019 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:03:34.564255953 CEST | 281 | OUT | |
Oct 14, 2024 06:03:34.564279079 CEST | 187 | OUT | |
Oct 14, 2024 06:03:36.144678116 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.6 | 50023 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:04:43.891976118 CEST | 279 | OUT | |
Oct 14, 2024 06:04:43.891976118 CEST | 213 | OUT | |
Oct 14, 2024 06:04:45.418653011 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.6 | 50024 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:04:49.589613914 CEST | 283 | OUT | |
Oct 14, 2024 06:04:49.589648962 CEST | 192 | OUT | |
Oct 14, 2024 06:04:51.149257898 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.6 | 50025 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:04:56.730218887 CEST | 283 | OUT | |
Oct 14, 2024 06:04:56.730258942 CEST | 358 | OUT | |
Oct 14, 2024 06:04:58.244179964 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.6 | 50026 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:02.506752014 CEST | 282 | OUT | |
Oct 14, 2024 06:05:02.506829977 CEST | 295 | OUT | |
Oct 14, 2024 06:05:04.062722921 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.6 | 50027 | 125.7.253.10 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:08.613362074 CEST | 282 | OUT | |
Oct 14, 2024 06:05:08.613362074 CEST | 178 | OUT | |
Oct 14, 2024 06:05:10.088608027 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.6 | 50028 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:16.547518969 CEST | 278 | OUT | |
Oct 14, 2024 06:05:16.547554970 CEST | 151 | OUT | |
Oct 14, 2024 06:05:18.034732103 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.6 | 50030 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:22.429583073 CEST | 279 | OUT | |
Oct 14, 2024 06:05:22.429619074 CEST | 188 | OUT | |
Oct 14, 2024 06:05:24.004805088 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.6 | 50031 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:30.250528097 CEST | 280 | OUT | |
Oct 14, 2024 06:05:30.250555038 CEST | 200 | OUT | |
Oct 14, 2024 06:05:31.785276890 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.6 | 50032 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:36.023633003 CEST | 280 | OUT | |
Oct 14, 2024 06:05:36.023652077 CEST | 203 | OUT | |
Oct 14, 2024 06:05:37.619925022 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.6 | 50033 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:42.127414942 CEST | 278 | OUT | |
Oct 14, 2024 06:05:42.127444983 CEST | 126 | OUT | |
Oct 14, 2024 06:05:43.752674103 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.6 | 50034 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:47.919637918 CEST | 279 | OUT | |
Oct 14, 2024 06:05:47.919661045 CEST | 223 | OUT | |
Oct 14, 2024 06:05:49.450983047 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.6 | 50035 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:53.119637966 CEST | 282 | OUT | |
Oct 14, 2024 06:05:53.119656086 CEST | 332 | OUT | |
Oct 14, 2024 06:05:55.638432980 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.6 | 50036 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:05:59.062105894 CEST | 281 | OUT | |
Oct 14, 2024 06:05:59.062125921 CEST | 134 | OUT | |
Oct 14, 2024 06:06:00.592765093 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.6 | 50037 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:06:04.583408117 CEST | 278 | OUT | |
Oct 14, 2024 06:06:04.583408117 CEST | 199 | OUT | |
Oct 14, 2024 06:06:06.826704979 CEST | 151 | IN | |
Oct 14, 2024 06:06:06.826754093 CEST | 151 | IN | |
Oct 14, 2024 06:06:06.826762915 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.6 | 50038 | 211.171.233.129 | 80 | 4004 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 06:06:11.776343107 CEST | 283 | OUT | |
Oct 14, 2024 06:06:11.776376009 CEST | 178 | OUT | |
Oct 14, 2024 06:06:13.269507885 CEST | 151 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 00:02:07 |
Start date: | 14/10/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 274'944 bytes |
MD5 hash: | 29EAF4B051758C9946539B6BA8AA475F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 00:02:17 |
Start date: | 14/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff609140000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 4 |
Start time: | 00:02:35 |
Start date: | 14/10/2024 |
Path: | C:\Users\user\AppData\Roaming\fbtdajh |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 274'944 bytes |
MD5 hash: | 29EAF4B051758C9946539B6BA8AA475F |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 9.5% |
Dynamic/Decrypted Code Coverage: | 28.2% |
Signature Coverage: | 41.8% |
Total number of Nodes: | 170 |
Total number of Limit Nodes: | 6 |
Graph
Function 004173E0 Relevance: 38.8, APIs: 20, Strings: 2, Instructions: 269filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C200B4 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0479003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004176A3 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417050 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04790E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C1FD73 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417020 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0479092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040324F Relevance: 1.3, Strings: 1, Instructions: 41COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403256 Relevance: 1.3, Strings: 1, Instructions: 39COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: 1.3, Strings: 1, Instructions: 37COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: 1.3, Strings: 1, Instructions: 32COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403290 Relevance: 1.3, Strings: 1, Instructions: 29COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040327D Relevance: 1.3, Strings: 1, Instructions: 26COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C1F991 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 04790D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417340 Relevance: 6.0, APIs: 4, Instructions: 43memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 8.9% |
Dynamic/Decrypted Code Coverage: | 28.2% |
Signature Coverage: | 0% |
Total number of Nodes: | 170 |
Total number of Limit Nodes: | 6 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004173E0 Relevance: 38.8, APIs: 20, Strings: 2, Instructions: 269filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CF003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004176A3 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417050 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C108B4 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02CF0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C10573 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417020 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417340 Relevance: 6.0, APIs: 4, Instructions: 43memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|