Windows
Analysis Report
TLH3anP3lh.exe
Overview
General Information
Sample name: | TLH3anP3lh.exerenamed because original name is a hash value |
Original sample name: | 5a6e0971a54847d4cecc16bf7fa44bca.exe |
Analysis ID: | 1537294 |
MD5: | 5a6e0971a54847d4cecc16bf7fa44bca |
SHA1: | b0b5d4f2cfe7a64addb17796ba41353c57a57f91 |
SHA256: | b44b1273d8b923127c0f5279cb143abf156cda0b03d083f8424c54ec4bbb7223 |
Tags: | exenjratRATuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- TLH3anP3lh.exe (PID: 6692 cmdline:
"C:\Users\ user\Deskt op\TLH3anP 3lh.exe" MD5: 5A6E0971A54847D4CECC16BF7FA44BCA) - yzbekt.exe (PID: 6972 cmdline:
"C:\Users\ user\AppDa ta\Roaming \yzbekt.ex e" MD5: 5A6E0971A54847D4CECC16BF7FA44BCA) - cmd.exe (PID: 7056 cmdline:
"C:\Window s\System32 \cmd.exe" /C choice /C Y /N /D Y /T 5 & Del "C:\Us ers\user\D esktop\TLH 3anP3lh.ex e" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7128 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - choice.exe (PID: 7148 cmdline:
choice /C Y /N /D Y /T 5 MD5: 1A9804F0C374283B094E9E55DC5EE128)
- yzbekt.exe (PID: 5040 cmdline:
"C:\Users\ user\AppDa ta\Roaming \yzbekt.ex e" .. MD5: 5A6E0971A54847D4CECC16BF7FA44BCA)
- yzbekt.exe (PID: 7092 cmdline:
"C:\Users\ user\AppDa ta\Roaming \yzbekt.ex e" .. MD5: 5A6E0971A54847D4CECC16BF7FA44BCA)
- yzbekt.exe (PID: 2828 cmdline:
"C:\Users\ user\AppDa ta\Roaming \yzbekt.ex e" .. MD5: 5A6E0971A54847D4CECC16BF7FA44BCA)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
NjRAT | RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored. |
{"Host": "0.tcp.eu.ngrok.io", "Port": "14026", "Campaign ID": "uzbek", "Version": "Platinum", "Network Seprator": "|Ghost|"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Unknown_Malware_Sample_Jul17_2 | Detects unknown malware sample with pastebin RAW URL | Florian Roth |
| |
Click to see the 19 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Unknown_Malware_Sample_Jul17_2 | Detects unknown malware sample with pastebin RAW URL | Florian Roth |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
Click to see the 12 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-18T19:07:15.744364+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.679168+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.781707+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.845118+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.921400+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.050883+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.011423+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.400162+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.454339+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.505638+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.550476+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.607335+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.651052+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.701024+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.770135+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.814114+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.186838+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.837873+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.701151+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.398899+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:15.968821+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49846 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:18.495940+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:20.935953+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.449524+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:26.936141+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49890 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:30.129957+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49903 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:37.277397+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49920 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:42.628762+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49944 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:49.256579+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.922848+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.267830+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.429435+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:21.357326+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.367668+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.994369+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:41.702877+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50036 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.329293+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.807940+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.733037+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:25.842887+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50040 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:32.950415+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:41.284057+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50042 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.043735+0200 | 2021176 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-18T19:07:15.744364+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.679168+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.781707+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.845118+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.921400+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.050883+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.011423+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.400162+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.454339+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.505638+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.550476+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.607335+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.651052+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.701024+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.770135+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.814114+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.186838+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.837873+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.701151+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.398899+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:15.968821+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49846 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:18.495940+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:20.935953+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.449524+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:26.936141+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49890 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:30.129957+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49903 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:37.277397+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49920 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:42.628762+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49944 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:49.256579+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.922848+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.267830+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.429435+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:21.357326+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.367668+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.994369+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:41.702877+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50036 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.329293+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.807940+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.733037+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:25.842887+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50040 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:32.950415+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:41.284057+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50042 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.043735+0200 | 2033132 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-18T19:07:37.969172+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:53.192086+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:08.439469+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:14.088436+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:18.633871+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:18.750385+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.159261+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.164622+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.301702+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.306975+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.352448+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.357361+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.398500+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.404545+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.440364+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.445259+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:21.060831+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.607647+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.617149+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:10:09.817843+0200 | 2825564 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-18T19:07:15.749369+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.684543+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.786741+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.850250+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.926515+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.055901+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.016850+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.405237+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.459218+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.510768+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.555706+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.612369+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.656003+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.705935+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.775105+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.819025+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.191628+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.843288+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.706356+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.403861+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:49.261642+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.927892+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.273002+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.434594+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:21.362846+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.375605+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.999574+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.334487+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.812930+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.740089+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:32.955336+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.048777+0200 | 2825563 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-18T19:07:15.749369+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.684543+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.786741+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.850250+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.926515+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.055901+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.016850+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.405237+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.459218+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.510768+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.555706+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.612369+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.656003+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.705935+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.775105+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.819025+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.191628+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.843288+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.706356+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.403861+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:20.941125+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:42.633922+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49944 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:49.261642+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.927892+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.273002+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.434594+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:21.362846+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.375605+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.999574+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.334487+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.812930+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.740089+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:32.955336+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:41.289043+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50042 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.048777+0200 | 2838486 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00007FFD9B8D000A | |
Source: | Code function: | 0_2_00007FFD9B8D0501 | |
Source: | Code function: | 8_2_00007FFD9B8E000A | |
Source: | Code function: | 8_2_00007FFD9B8E0501 | |
Source: | Code function: | 9_2_00007FFD9B8F003C | |
Source: | Code function: | 9_2_00007FFD9B8F0501 | |
Source: | Code function: | 10_2_00007FFD9B8D000A | |
Source: | Code function: | 10_2_00007FFD9B8D0501 |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B | |
Source: | Code function: | 0_2_00007FFD9B8D2B3B |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: |
Source: | Thread register set: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | Registry value created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 112 Process Injection | 1 Masquerading | 1 Input Capture | 221 Security Software Discovery | Remote Services | 1 Input Capture | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 Registry Run Keys / Startup Folder | 11 Disable or Modify Tools | LSASS Memory | 2 Process Discovery | Remote Desktop Protocol | 1 Archive Collected Data | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 112 Process Injection | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 1 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 11 Software Packing | Cached Domain Credentials | 12 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
76% | ReversingLabs | ByteCode-MSIL.Trojan.KillMbr | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML | |||
76% | ReversingLabs | ByteCode-MSIL.Trojan.KillMbr |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
0.tcp.eu.ngrok.io | 52.57.120.10 | true | true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
3.78.28.71 | unknown | United States | 16509 | AMAZON-02US | true | |
3.74.27.83 | unknown | United States | 16509 | AMAZON-02US | true | |
18.153.198.123 | unknown | United States | 16509 | AMAZON-02US | true | |
52.57.120.10 | 0.tcp.eu.ngrok.io | United States | 16509 | AMAZON-02US | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1537294 |
Start date and time: | 2024-10-18 19:06:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 11s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 12 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | TLH3anP3lh.exerenamed because original name is a hash value |
Original Sample Name: | 5a6e0971a54847d4cecc16bf7fa44bca.exe |
Detection: | MAL |
Classification: | mal100.phis.troj.spyw.evad.winEXE@11/3@4/4 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target TLH3anP3lh.exe, PID 6692 because it is empty
- Execution Graph export aborted for target yzbekt.exe, PID 2828 because it is empty
- Execution Graph export aborted for target yzbekt.exe, PID 5040 because it is empty
- Execution Graph export aborted for target yzbekt.exe, PID 7092 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtSetInformationFile calls found.
- VT rate limit hit for: TLH3anP3lh.exe
Time | Type | Description |
---|---|---|
13:07:15 | API Interceptor | |
18:07:14 | Autostart | |
18:07:22 | Autostart | |
18:07:30 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3.78.28.71 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
3.74.27.83 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
18.153.198.123 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
52.57.120.10 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
0.tcp.eu.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| |
Get hash | malicious | Captcha Phish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Exela Stealer, Python Stealer | Browse |
| ||
AMAZON-02US | Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| |
Get hash | malicious | Captcha Phish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Exela Stealer, Python Stealer | Browse |
| ||
AMAZON-02US | Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| |
Get hash | malicious | Captcha Phish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Exela Stealer, Python Stealer | Browse |
| ||
AMAZON-02US | Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| |
Get hash | malicious | Captcha Phish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Exela Stealer, Python Stealer | Browse |
|
Process: | C:\Users\user\Desktop\TLH3anP3lh.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 525 |
Entropy (8bit): | 5.276808582119191 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJVV+0kZs1B01ku9EZv4hk70/92v/l9tv:MLUGuRMOlT |
MD5: | 00F8672018D624935F7310D1C3DA595E |
SHA1: | AC7890A643DF31BC3BB09053B8DE4D9368B672B2 |
SHA-256: | A7092B2AC70BB6E01050F3AE3DE5C1FF9D75A2775A0B07A37387493A2DF84664 |
SHA-512: | E5A2E0F177BFCA6C41054BAF3BFD9AA3287C7385C0DDDC1F942D642B8C232AD2AF1956009B08A822ABF42319BCFCFD163D3EB6CF13466727FCABFE32D2226FBC |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Roaming\yzbekt.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 525 |
Entropy (8bit): | 5.276808582119191 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJVV+0kZs1B01ku9EZv4hk70/92v/l9tv:MLUGuRMOlT |
MD5: | 00F8672018D624935F7310D1C3DA595E |
SHA1: | AC7890A643DF31BC3BB09053B8DE4D9368B672B2 |
SHA-256: | A7092B2AC70BB6E01050F3AE3DE5C1FF9D75A2775A0B07A37387493A2DF84664 |
SHA-512: | E5A2E0F177BFCA6C41054BAF3BFD9AA3287C7385C0DDDC1F942D642B8C232AD2AF1956009B08A822ABF42319BCFCFD163D3EB6CF13466727FCABFE32D2226FBC |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\TLH3anP3lh.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40916 |
Entropy (8bit): | 7.366448665714686 |
Encrypted: | false |
SSDEEP: | 768:VvAl92nMe/UYPlfk4l3QYp6LxybXDIAfjP/m/NyE3NSTM8udmmBDnu:i4DzPlfk4JQm6L47BfbIyzM8udmmFu |
MD5: | 5A6E0971A54847D4CECC16BF7FA44BCA |
SHA1: | B0B5D4F2CFE7A64ADDB17796BA41353C57A57F91 |
SHA-256: | B44B1273D8B923127C0F5279CB143ABF156CDA0B03D083F8424C54EC4BBB7223 |
SHA-512: | 90362F72A78C257EBA31A9BC5089D02DB626A985F78D5EC8F97DADD743EF4C2B9FC434F318FAEA27D0E41E03CDDEEC94536F5BCD29A1FF77F14FE2D44A8B823E |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.366448665714686 |
TrID: |
|
File name: | TLH3anP3lh.exe |
File size: | 40'916 bytes |
MD5: | 5a6e0971a54847d4cecc16bf7fa44bca |
SHA1: | b0b5d4f2cfe7a64addb17796ba41353c57a57f91 |
SHA256: | b44b1273d8b923127c0f5279cb143abf156cda0b03d083f8424c54ec4bbb7223 |
SHA512: | 90362f72a78c257eba31a9bc5089d02db626a985f78d5ec8f97dadd743ef4c2b9fc434f318faea27d0e41e03cddeec94536f5bcd29a1ff77f14fe2d44a8b823e |
SSDEEP: | 768:VvAl92nMe/UYPlfk4l3QYp6LxybXDIAfjP/m/NyE3NSTM8udmmBDnu:i4DzPlfk4JQm6L47BfbIyzM8udmmFu |
TLSH: | E603F11BC74B82B7D025987B4B3392C8E73FE414A5AE5F7D00C85E3D9F53A8006A6A56 |
File Content Preview: | MZ@.....................................!..L.!It's .NET EXE$@...PE..L....&.M............................^.... ...@....@.. ....................................@.....................................O....@..@....................`............................. |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x402e5e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x4D0126CB [Thu Dec 9 18:58:19 2010 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x2e0c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4000 | 0x240 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xe64 | 0x1000 | 67a16ac29b5cad6137f7cde274f36178 | False | 0.545166015625 | data | 5.268030641747023 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x4000 | 0x240 | 0x400 | 79f2d97552a2143b0d4aad15e30e7192 | False | 0.30078125 | data | 3.5362123075490928 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x6000 | 0xc | 0x200 | 54075bb846c0b848677202143f47b50e | False | 0.998046875 | data | 6.526587223751109 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x4058 | 0x1e7 | XML 1.0 document, ASCII text, with CRLF line terminators | 0.5338809034907598 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-18T19:07:15.744364+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:15.744364+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:15.749369+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:15.749369+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49730 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.679168+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.679168+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.684543+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:18.684543+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49733 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.781707+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.781707+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.786741+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:21.786741+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49734 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.845118+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.845118+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.850250+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:24.850250+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49735 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.921400+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.921400+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.926515+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:27.926515+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49736 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.050883+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.050883+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.055901+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:31.055901+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49737 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.011423+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.011423+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.016850+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:34.016850+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49739 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.400162+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.400162+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.405237+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.405237+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:37.969172+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49740 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.454339+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.454339+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.459218+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:40.459218+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49741 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.505638+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.505638+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.510768+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:43.510768+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49742 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.550476+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.550476+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.555706+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:46.555706+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49743 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.607335+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.607335+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.612369+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:49.612369+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49744 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.651052+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.651052+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.656003+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:52.656003+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:53.192086+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49745 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.701024+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.701024+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.705935+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:55.705935+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49746 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.770135+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.770135+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.775105+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:07:58.775105+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49748 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.814114+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.814114+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.819025+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:01.819025+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49764 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.186838+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.186838+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.191628+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:05.191628+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49782 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.837873+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.837873+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.843288+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:07.843288+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:08.439469+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49798 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.701151+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.701151+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.706356+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:10.706356+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49815 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.398899+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.398899+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.403861+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:13.403861+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:14.088436+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49831 | 52.57.120.10 | 14026 | TCP |
2024-10-18T19:08:15.968821+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49846 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:15.968821+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49846 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:18.495940+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:18.495940+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:18.633871+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:18.750385+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.159261+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.164622+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.301702+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.306975+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.352448+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.357361+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.398500+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.404545+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.440364+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:19.445259+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49860 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:20.935953+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:20.935953+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:20.941125+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:21.060831+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49872 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.449524+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.449524+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.607647+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:23.617149+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 49884 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:26.936141+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49890 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:26.936141+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49890 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:30.129957+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49903 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:30.129957+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49903 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:37.277397+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49920 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:37.277397+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49920 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:42.628762+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49944 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:42.628762+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49944 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:42.633922+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49944 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:49.256579+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:49.256579+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:49.261642+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:49.261642+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 49974 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.922848+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.922848+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.927892+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:08:55.927892+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50006 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.267830+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.267830+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.273002+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:08.273002+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50031 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.429435+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.429435+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.434594+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:15.434594+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50032 | 3.74.27.83 | 14026 | TCP |
2024-10-18T19:09:21.357326+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:21.357326+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:21.362846+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:21.362846+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50033 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.367668+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.367668+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.375605+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:27.375605+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50034 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.994369+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.994369+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.999574+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:32.999574+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50035 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:41.702877+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50036 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:41.702877+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50036 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.329293+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.329293+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.334487+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:09:47.334487+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50037 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.807940+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.807940+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.812930+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.812930+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:09.817843+0200 | 2825564 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (act) | 1 | 192.168.2.4 | 50038 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.733037+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.733037+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.740089+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:17.740089+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50039 | 18.153.198.123 | 14026 | TCP |
2024-10-18T19:10:25.842887+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50040 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:25.842887+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50040 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:32.950415+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:32.950415+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:32.955336+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:32.955336+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50041 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:41.284057+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50042 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:41.284057+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50042 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:41.289043+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50042 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.043735+0200 | 2033132 | ET MALWARE Generic njRAT/Bladabindi CnC Activity (ll) | 1 | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.043735+0200 | 2021176 | ET MALWARE Bladabindi/njRAT CnC Command (ll) | 1 | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.048777+0200 | 2825563 | ETPRO MALWARE Generic njRAT/Bladabindi CnC Activity (inf) | 1 | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
2024-10-18T19:10:57.048777+0200 | 2838486 | ETPRO MALWARE njRAT/Bladabindi Variant CnC Activity (inf) | 1 | 192.168.2.4 | 50043 | 3.78.28.71 | 14026 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 18, 2024 19:07:15.525288105 CEST | 49730 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:15.530383110 CEST | 14026 | 49730 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:15.530457973 CEST | 49730 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:15.744364023 CEST | 49730 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:15.749300957 CEST | 14026 | 49730 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:15.749368906 CEST | 49730 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:15.754273891 CEST | 14026 | 49730 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:16.613874912 CEST | 14026 | 49730 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:16.613991976 CEST | 49730 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:18.625660896 CEST | 49730 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:18.627044916 CEST | 49733 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:18.644897938 CEST | 14026 | 49730 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:18.644954920 CEST | 14026 | 49733 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:18.645148039 CEST | 49733 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:18.679167986 CEST | 49733 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:18.684453011 CEST | 14026 | 49733 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:18.684542894 CEST | 49733 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:18.690376043 CEST | 14026 | 49733 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:19.723984003 CEST | 14026 | 49733 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:19.725331068 CEST | 49733 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:21.734536886 CEST | 49733 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:21.735604048 CEST | 49734 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:21.739733934 CEST | 14026 | 49733 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:21.740597963 CEST | 14026 | 49734 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:21.740731955 CEST | 49734 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:21.781707048 CEST | 49734 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:21.786580086 CEST | 14026 | 49734 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:21.786741018 CEST | 49734 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:21.791542053 CEST | 14026 | 49734 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:22.782145977 CEST | 14026 | 49734 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:22.782229900 CEST | 49734 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:24.797185898 CEST | 49734 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:24.798541069 CEST | 49735 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:24.802349091 CEST | 14026 | 49734 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:24.803704977 CEST | 14026 | 49735 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:24.803778887 CEST | 49735 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:24.845118046 CEST | 49735 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:24.850173950 CEST | 14026 | 49735 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:24.850250006 CEST | 49735 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:24.855110884 CEST | 14026 | 49735 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:25.838392973 CEST | 14026 | 49735 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:25.839479923 CEST | 49735 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:27.844549894 CEST | 49735 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:27.845747948 CEST | 49736 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:27.849680901 CEST | 14026 | 49735 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:27.850749016 CEST | 14026 | 49736 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:27.850850105 CEST | 49736 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:27.921400070 CEST | 49736 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:27.926426888 CEST | 14026 | 49736 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:27.926515102 CEST | 49736 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:27.932400942 CEST | 14026 | 49736 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:28.895534992 CEST | 14026 | 49736 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:28.897393942 CEST | 49736 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:30.924223900 CEST | 49736 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:30.925064087 CEST | 49737 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:30.929590940 CEST | 14026 | 49736 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:30.930001020 CEST | 14026 | 49737 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:30.930092096 CEST | 49737 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:31.050883055 CEST | 49737 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:31.055838108 CEST | 14026 | 49737 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:31.055901051 CEST | 49737 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:31.060781002 CEST | 14026 | 49737 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:31.952408075 CEST | 14026 | 49737 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:31.952549934 CEST | 49737 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:33.953491926 CEST | 49737 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:33.954622984 CEST | 49739 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:33.958846092 CEST | 14026 | 49737 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:33.959599972 CEST | 14026 | 49739 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:33.959708929 CEST | 49739 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:34.011423111 CEST | 49739 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:34.016748905 CEST | 14026 | 49739 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:34.016849995 CEST | 49739 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:34.021775007 CEST | 14026 | 49739 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:35.344702959 CEST | 14026 | 49739 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:35.344774008 CEST | 49739 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:37.359761953 CEST | 49739 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:37.361260891 CEST | 49740 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:37.365055084 CEST | 14026 | 49739 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:37.366188049 CEST | 14026 | 49740 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:37.366262913 CEST | 49740 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:37.400161982 CEST | 49740 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:37.405143976 CEST | 14026 | 49740 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:37.405236959 CEST | 49740 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:37.410130978 CEST | 14026 | 49740 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:37.969172001 CEST | 49740 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:37.974231958 CEST | 14026 | 49740 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:38.415518999 CEST | 14026 | 49740 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:38.415580034 CEST | 49740 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:40.422005892 CEST | 49740 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:40.422770977 CEST | 49741 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:40.427027941 CEST | 14026 | 49740 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:40.427719116 CEST | 14026 | 49741 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:40.427798033 CEST | 49741 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:40.454339027 CEST | 49741 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:40.459172964 CEST | 14026 | 49741 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:40.459218025 CEST | 49741 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:40.464137077 CEST | 14026 | 49741 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:41.457425117 CEST | 14026 | 49741 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:41.457571030 CEST | 49741 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:43.469080925 CEST | 49741 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:43.470036030 CEST | 49742 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:43.474462986 CEST | 14026 | 49741 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:43.474870920 CEST | 14026 | 49742 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:43.474931955 CEST | 49742 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:43.505637884 CEST | 49742 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:43.510689974 CEST | 14026 | 49742 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:43.510767937 CEST | 49742 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:43.515887976 CEST | 14026 | 49742 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:44.511960983 CEST | 14026 | 49742 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:44.512042999 CEST | 49742 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:46.515996933 CEST | 49742 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:46.516551018 CEST | 49743 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:46.521061897 CEST | 14026 | 49742 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:46.521660089 CEST | 14026 | 49743 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:46.521737099 CEST | 49743 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:46.550476074 CEST | 49743 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:46.555413961 CEST | 14026 | 49743 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:46.555706024 CEST | 49743 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:46.560589075 CEST | 14026 | 49743 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:47.565320015 CEST | 14026 | 49743 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:47.565418959 CEST | 49743 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:49.578377008 CEST | 49743 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:49.579163074 CEST | 49744 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:49.583533049 CEST | 14026 | 49743 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:49.584296942 CEST | 14026 | 49744 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:49.584392071 CEST | 49744 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:49.607335091 CEST | 49744 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:49.612282991 CEST | 14026 | 49744 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:49.612369061 CEST | 49744 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:49.617259979 CEST | 14026 | 49744 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:50.604723930 CEST | 14026 | 49744 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:50.607479095 CEST | 49744 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:52.609875917 CEST | 49744 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:52.610995054 CEST | 49745 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:52.614927053 CEST | 14026 | 49744 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:52.616411924 CEST | 14026 | 49745 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:52.616507053 CEST | 49745 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:52.651051998 CEST | 49745 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:52.655916929 CEST | 14026 | 49745 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:52.656002998 CEST | 49745 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:52.661020994 CEST | 14026 | 49745 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:53.192085981 CEST | 49745 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:53.197567940 CEST | 14026 | 49745 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:53.647603989 CEST | 14026 | 49745 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:53.647773981 CEST | 49745 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:55.656613111 CEST | 49745 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:55.657812119 CEST | 49746 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:55.661758900 CEST | 14026 | 49745 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:55.662898064 CEST | 14026 | 49746 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:55.662987947 CEST | 49746 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:55.701024055 CEST | 49746 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:55.705881119 CEST | 14026 | 49746 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:55.705935001 CEST | 49746 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:55.711092949 CEST | 14026 | 49746 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:56.687979937 CEST | 14026 | 49746 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:56.688138962 CEST | 49746 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:58.703466892 CEST | 49746 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:58.705270052 CEST | 49748 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:58.708389044 CEST | 14026 | 49746 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:58.710282087 CEST | 14026 | 49748 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:58.710376024 CEST | 49748 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:58.770134926 CEST | 49748 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:58.775017023 CEST | 14026 | 49748 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:58.775105000 CEST | 49748 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:07:58.779936075 CEST | 14026 | 49748 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:59.739116907 CEST | 14026 | 49748 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:07:59.741414070 CEST | 49748 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:01.750610113 CEST | 49748 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:01.752302885 CEST | 49764 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:01.755702972 CEST | 14026 | 49748 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:01.757158041 CEST | 14026 | 49764 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:01.757222891 CEST | 49764 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:01.814114094 CEST | 49764 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:01.818948984 CEST | 14026 | 49764 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:01.819025040 CEST | 49764 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:01.823802948 CEST | 14026 | 49764 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:02.830606937 CEST | 14026 | 49764 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:02.830725908 CEST | 49764 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:04.853099108 CEST | 49764 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:04.858073950 CEST | 14026 | 49764 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:04.865379095 CEST | 49782 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:04.870220900 CEST | 14026 | 49782 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:04.870304108 CEST | 49782 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:05.186837912 CEST | 49782 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:05.191585064 CEST | 14026 | 49782 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:05.191627979 CEST | 49782 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:05.196465969 CEST | 14026 | 49782 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:05.915913105 CEST | 14026 | 49782 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:05.915975094 CEST | 49782 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:07.798516035 CEST | 49782 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:07.799904108 CEST | 49798 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:07.803565025 CEST | 14026 | 49782 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:07.804775000 CEST | 14026 | 49798 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:07.804855108 CEST | 49798 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:07.837872982 CEST | 49798 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:07.843178988 CEST | 14026 | 49798 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:07.843287945 CEST | 49798 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:07.848124027 CEST | 14026 | 49798 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:08.439469099 CEST | 49798 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:08.444323063 CEST | 14026 | 49798 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:08.899010897 CEST | 14026 | 49798 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:08.899264097 CEST | 49798 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:10.656578064 CEST | 49798 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:10.657661915 CEST | 49815 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:10.661609888 CEST | 14026 | 49798 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:10.662652016 CEST | 14026 | 49815 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:10.662770033 CEST | 49815 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:10.701150894 CEST | 49815 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:10.706235886 CEST | 14026 | 49815 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:10.706356049 CEST | 49815 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:10.711390018 CEST | 14026 | 49815 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:11.705440044 CEST | 14026 | 49815 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:11.707568884 CEST | 49815 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:13.355679035 CEST | 49815 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:13.356735945 CEST | 49831 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:13.360652924 CEST | 14026 | 49815 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:13.361702919 CEST | 14026 | 49831 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:13.361772060 CEST | 49831 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:13.398899078 CEST | 49831 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:13.403795004 CEST | 14026 | 49831 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:13.403861046 CEST | 49831 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:13.408690929 CEST | 14026 | 49831 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:14.088435888 CEST | 49831 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:14.093333006 CEST | 14026 | 49831 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:14.390849113 CEST | 14026 | 49831 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:14.390909910 CEST | 49831 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:15.922261953 CEST | 49831 | 14026 | 192.168.2.4 | 52.57.120.10 |
Oct 18, 2024 19:08:15.927329063 CEST | 14026 | 49831 | 52.57.120.10 | 192.168.2.4 |
Oct 18, 2024 19:08:15.936317921 CEST | 49846 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:15.941520929 CEST | 14026 | 49846 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:15.941596985 CEST | 49846 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:15.968821049 CEST | 49846 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:15.973910093 CEST | 14026 | 49846 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:15.973982096 CEST | 49846 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:15.978919983 CEST | 14026 | 49846 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:16.989491940 CEST | 14026 | 49846 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:16.991554976 CEST | 49846 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.422359943 CEST | 49846 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.423224926 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.427238941 CEST | 14026 | 49846 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:18.428194046 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:18.428272009 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.495939970 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.501069069 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:18.501163006 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.506063938 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:18.633871078 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.639480114 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:18.750385046 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:18.755603075 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.159260988 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.164565086 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.164622068 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.169528961 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.301702023 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.306907892 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.306974888 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.312735081 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.352447987 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.357306957 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.357361078 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.362345934 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.398499966 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.404453993 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.404545069 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.409908056 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.440363884 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.445199013 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.445259094 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:19.450176001 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.478544950 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:19.478595018 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:20.813507080 CEST | 49860 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:20.815366983 CEST | 49872 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:20.818479061 CEST | 14026 | 49860 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:20.820360899 CEST | 14026 | 49872 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:20.820548058 CEST | 49872 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:20.935952902 CEST | 49872 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:20.941066980 CEST | 14026 | 49872 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:20.941124916 CEST | 49872 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:20.945911884 CEST | 14026 | 49872 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:21.060831070 CEST | 49872 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:21.065819979 CEST | 14026 | 49872 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:21.877163887 CEST | 14026 | 49872 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:21.877228975 CEST | 49872 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.170260906 CEST | 49872 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.171700001 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.175462008 CEST | 14026 | 49872 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:23.176899910 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:23.176990032 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.449523926 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.454504013 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:23.455455065 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.460285902 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:23.607646942 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.612510920 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:23.617149115 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:23.621968985 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:24.199165106 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:24.200098038 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:25.400696993 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:25.407042980 CEST | 49890 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:25.765785933 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:26.089914083 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:26.089939117 CEST | 14026 | 49890 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:26.089962006 CEST | 14026 | 49884 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:26.090034962 CEST | 49890 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:26.090064049 CEST | 49884 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:26.936141014 CEST | 49890 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:26.941320896 CEST | 14026 | 49890 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:26.941414118 CEST | 49890 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:26.946902990 CEST | 14026 | 49890 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:27.393974066 CEST | 14026 | 49890 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:27.394042015 CEST | 49890 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:28.512926102 CEST | 49890 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:28.513803959 CEST | 49903 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:28.517824888 CEST | 14026 | 49890 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:28.518681049 CEST | 14026 | 49903 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:28.518759966 CEST | 49903 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:30.129956961 CEST | 49903 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:30.135468006 CEST | 14026 | 49903 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:30.135524988 CEST | 49903 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:30.141051054 CEST | 14026 | 49903 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:30.569190979 CEST | 14026 | 49903 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:30.569292068 CEST | 49903 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:32.578499079 CEST | 49903 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:32.579485893 CEST | 49920 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:32.583507061 CEST | 14026 | 49903 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:32.584428072 CEST | 14026 | 49920 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:32.584531069 CEST | 49920 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:37.277396917 CEST | 49920 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:37.282501936 CEST | 14026 | 49920 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:37.282562971 CEST | 49920 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:37.287422895 CEST | 14026 | 49920 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:37.715010881 CEST | 14026 | 49920 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:37.715085030 CEST | 49920 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:39.719178915 CEST | 49920 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:39.724188089 CEST | 14026 | 49920 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:39.728373051 CEST | 49944 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:39.733659983 CEST | 14026 | 49944 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:39.733747959 CEST | 49944 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:42.628762007 CEST | 49944 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:42.633853912 CEST | 14026 | 49944 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:42.633922100 CEST | 49944 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:42.638788939 CEST | 14026 | 49944 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:43.093528986 CEST | 14026 | 49944 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:43.093585968 CEST | 49944 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:45.288119078 CEST | 49944 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:45.288779974 CEST | 49974 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:45.293081999 CEST | 14026 | 49944 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:45.293726921 CEST | 14026 | 49974 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:45.293817043 CEST | 49974 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:49.256578922 CEST | 49974 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:49.261568069 CEST | 14026 | 49974 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:49.261641979 CEST | 49974 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:49.266546965 CEST | 14026 | 49974 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:49.725610018 CEST | 14026 | 49974 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:49.725882053 CEST | 49974 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:51.961035013 CEST | 49974 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:51.966134071 CEST | 14026 | 49974 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:51.991168976 CEST | 50006 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:51.996395111 CEST | 14026 | 50006 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:51.996510029 CEST | 50006 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:55.922847986 CEST | 50006 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:55.927817106 CEST | 14026 | 50006 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:55.927891970 CEST | 50006 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:55.932796001 CEST | 14026 | 50006 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:56.357131004 CEST | 14026 | 50006 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:56.357333899 CEST | 50006 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:58.364798069 CEST | 50006 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:58.370022058 CEST | 14026 | 50006 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:59.797281027 CEST | 50031 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:08:59.802531004 CEST | 14026 | 50031 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:08:59.802639961 CEST | 50031 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:08.267829895 CEST | 50031 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:08.272897959 CEST | 14026 | 50031 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:08.273001909 CEST | 50031 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:08.277817965 CEST | 14026 | 50031 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:08.739123106 CEST | 14026 | 50031 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:08.739200115 CEST | 50031 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:11.234735966 CEST | 50031 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:11.239820004 CEST | 14026 | 50031 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:11.432837009 CEST | 50032 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:11.437908888 CEST | 14026 | 50032 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:11.437998056 CEST | 50032 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:15.429435015 CEST | 50032 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:15.434500933 CEST | 14026 | 50032 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:15.434593916 CEST | 50032 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:15.439493895 CEST | 14026 | 50032 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:15.894285917 CEST | 14026 | 50032 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:15.897253990 CEST | 50032 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:17.937875986 CEST | 50032 | 14026 | 192.168.2.4 | 3.74.27.83 |
Oct 18, 2024 19:09:17.942959070 CEST | 14026 | 50032 | 3.74.27.83 | 192.168.2.4 |
Oct 18, 2024 19:09:17.967665911 CEST | 50033 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:17.972775936 CEST | 14026 | 50033 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:17.972872019 CEST | 50033 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:21.357326031 CEST | 50033 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:21.362679958 CEST | 14026 | 50033 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:21.362845898 CEST | 50033 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:21.367691994 CEST | 14026 | 50033 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:21.796854973 CEST | 14026 | 50033 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:21.796931982 CEST | 50033 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:23.870142937 CEST | 50033 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:23.875178099 CEST | 14026 | 50033 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:23.881675005 CEST | 50034 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:23.887839079 CEST | 14026 | 50034 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:23.887983084 CEST | 50034 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:27.367667913 CEST | 50034 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:27.372844934 CEST | 14026 | 50034 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:27.375605106 CEST | 50034 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:27.380599022 CEST | 14026 | 50034 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:27.805718899 CEST | 14026 | 50034 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:27.808264017 CEST | 50034 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:29.819554090 CEST | 50034 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:29.824758053 CEST | 14026 | 50034 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:29.842776060 CEST | 50035 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:29.848117113 CEST | 14026 | 50035 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:29.848232985 CEST | 50035 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:32.994369030 CEST | 50035 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:32.999499083 CEST | 14026 | 50035 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:32.999573946 CEST | 50035 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:33.004525900 CEST | 14026 | 50035 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:33.437756062 CEST | 14026 | 50035 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:33.437824965 CEST | 50035 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:35.796904087 CEST | 50035 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:35.801858902 CEST | 14026 | 50035 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:35.804539919 CEST | 50036 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:35.809509993 CEST | 14026 | 50036 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:35.809632063 CEST | 50036 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:41.702877045 CEST | 50036 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:41.707928896 CEST | 14026 | 50036 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:41.708018064 CEST | 50036 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:41.712862968 CEST | 14026 | 50036 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:42.143074036 CEST | 14026 | 50036 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:42.143147945 CEST | 50036 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:44.256753922 CEST | 50036 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:44.265522003 CEST | 14026 | 50036 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:44.268138885 CEST | 50037 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:44.273401976 CEST | 14026 | 50037 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:44.273549080 CEST | 50037 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:47.329293013 CEST | 50037 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:47.334382057 CEST | 14026 | 50037 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:47.334486961 CEST | 50037 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:47.339624882 CEST | 14026 | 50037 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:47.766386032 CEST | 14026 | 50037 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:47.766499043 CEST | 50037 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:49.966965914 CEST | 50037 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:49.972362041 CEST | 14026 | 50037 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:50.120429039 CEST | 50038 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:09:50.125468016 CEST | 14026 | 50038 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:09:50.125555992 CEST | 50038 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:09.807940006 CEST | 50038 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:09.812838078 CEST | 14026 | 50038 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:09.812930107 CEST | 50038 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:09.817779064 CEST | 14026 | 50038 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:09.817842960 CEST | 50038 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:09.822685957 CEST | 14026 | 50038 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:10.242516041 CEST | 14026 | 50038 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:10.242594004 CEST | 50038 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:12.297100067 CEST | 50038 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:12.312154055 CEST | 14026 | 50038 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:12.315434933 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:12.320439100 CEST | 14026 | 50039 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:12.320534945 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:17.733036995 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:17.740010977 CEST | 14026 | 50039 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:17.740088940 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:17.744976997 CEST | 14026 | 50039 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:18.204699993 CEST | 14026 | 50039 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:18.204955101 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:20.578859091 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:20.984829903 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:21.162946939 CEST | 14026 | 50039 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:21.162964106 CEST | 14026 | 50039 | 18.153.198.123 | 192.168.2.4 |
Oct 18, 2024 19:10:21.163034916 CEST | 50039 | 14026 | 192.168.2.4 | 18.153.198.123 |
Oct 18, 2024 19:10:21.258199930 CEST | 50040 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:21.263354063 CEST | 14026 | 50040 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:21.263485909 CEST | 50040 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:25.842886925 CEST | 50040 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:25.847843885 CEST | 14026 | 50040 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:25.847912073 CEST | 50040 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:25.852787971 CEST | 14026 | 50040 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:26.304572105 CEST | 14026 | 50040 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:26.304855108 CEST | 50040 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:28.316533089 CEST | 50040 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:28.321393013 CEST | 14026 | 50040 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:28.345798016 CEST | 50041 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:28.350662947 CEST | 14026 | 50041 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:28.350754023 CEST | 50041 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:32.950414896 CEST | 50041 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:32.955260038 CEST | 14026 | 50041 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:32.955336094 CEST | 50041 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:32.960248947 CEST | 14026 | 50041 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:33.409006119 CEST | 14026 | 50041 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:33.409070969 CEST | 50041 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:35.425784111 CEST | 50041 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:35.431271076 CEST | 14026 | 50041 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:35.444148064 CEST | 50042 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:35.449220896 CEST | 14026 | 50042 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:35.449295998 CEST | 50042 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:41.284056902 CEST | 50042 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:41.288969994 CEST | 14026 | 50042 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:41.289042950 CEST | 50042 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:41.294074059 CEST | 14026 | 50042 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:41.727189064 CEST | 14026 | 50042 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:41.727361917 CEST | 50042 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:43.794467926 CEST | 50042 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:43.799650908 CEST | 14026 | 50042 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:43.829348087 CEST | 50043 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:44.089603901 CEST | 14026 | 50043 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:44.089689970 CEST | 50043 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:57.043735027 CEST | 50043 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:57.048713923 CEST | 14026 | 50043 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:57.048777103 CEST | 50043 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:57.053632021 CEST | 14026 | 50043 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:57.878757954 CEST | 14026 | 50043 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:57.878861904 CEST | 50043 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:59.892391920 CEST | 50043 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:59.898041010 CEST | 14026 | 50043 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:59.901253939 CEST | 50044 | 14026 | 192.168.2.4 | 3.78.28.71 |
Oct 18, 2024 19:10:59.906415939 CEST | 14026 | 50044 | 3.78.28.71 | 192.168.2.4 |
Oct 18, 2024 19:10:59.906497955 CEST | 50044 | 14026 | 192.168.2.4 | 3.78.28.71 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 18, 2024 19:07:15.511804104 CEST | 57423 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 18, 2024 19:07:15.521809101 CEST | 53 | 57423 | 1.1.1.1 | 192.168.2.4 |
Oct 18, 2024 19:08:15.923083067 CEST | 61761 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 18, 2024 19:08:15.932390928 CEST | 53 | 61761 | 1.1.1.1 | 192.168.2.4 |
Oct 18, 2024 19:09:17.938806057 CEST | 54973 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 18, 2024 19:09:17.956926107 CEST | 53 | 54973 | 1.1.1.1 | 192.168.2.4 |
Oct 18, 2024 19:10:20.579768896 CEST | 61651 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 18, 2024 19:10:21.167474031 CEST | 53 | 61651 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 18, 2024 19:07:15.511804104 CEST | 192.168.2.4 | 1.1.1.1 | 0x156f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 18, 2024 19:08:15.923083067 CEST | 192.168.2.4 | 1.1.1.1 | 0x1128 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 18, 2024 19:09:17.938806057 CEST | 192.168.2.4 | 1.1.1.1 | 0xc92a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 18, 2024 19:10:20.579768896 CEST | 192.168.2.4 | 1.1.1.1 | 0x822b | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 18, 2024 19:07:15.521809101 CEST | 1.1.1.1 | 192.168.2.4 | 0x156f | No error (0) | 52.57.120.10 | A (IP address) | IN (0x0001) | false | ||
Oct 18, 2024 19:08:15.932390928 CEST | 1.1.1.1 | 192.168.2.4 | 0x1128 | No error (0) | 3.74.27.83 | A (IP address) | IN (0x0001) | false | ||
Oct 18, 2024 19:09:17.956926107 CEST | 1.1.1.1 | 192.168.2.4 | 0xc92a | No error (0) | 18.153.198.123 | A (IP address) | IN (0x0001) | false | ||
Oct 18, 2024 19:10:21.167474031 CEST | 1.1.1.1 | 192.168.2.4 | 0x822b | No error (0) | 3.78.28.71 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 13:06:58 |
Start date: | 18/10/2024 |
Path: | C:\Users\user\Desktop\TLH3anP3lh.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x420000 |
File size: | 40'916 bytes |
MD5 hash: | 5A6E0971A54847D4CECC16BF7FA44BCA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 13:07:05 |
Start date: | 18/10/2024 |
Path: | C:\Users\user\AppData\Roaming\yzbekt.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xdd0000 |
File size: | 40'916 bytes |
MD5 hash: | 5A6E0971A54847D4CECC16BF7FA44BCA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 13:07:05 |
Start date: | 18/10/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d97a0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 13:07:05 |
Start date: | 18/10/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 13:07:05 |
Start date: | 18/10/2024 |
Path: | C:\Windows\System32\choice.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678a60000 |
File size: | 35'840 bytes |
MD5 hash: | 1A9804F0C374283B094E9E55DC5EE128 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 8 |
Start time: | 13:07:22 |
Start date: | 18/10/2024 |
Path: | C:\Users\user\AppData\Roaming\yzbekt.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x840000 |
File size: | 40'916 bytes |
MD5 hash: | 5A6E0971A54847D4CECC16BF7FA44BCA |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 9 |
Start time: | 13:07:30 |
Start date: | 18/10/2024 |
Path: | C:\Users\user\AppData\Roaming\yzbekt.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f330000 |
File size: | 40'916 bytes |
MD5 hash: | 5A6E0971A54847D4CECC16BF7FA44BCA |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 10 |
Start time: | 13:07:38 |
Start date: | 18/10/2024 |
Path: | C:\Users\user\AppData\Roaming\yzbekt.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x1f0000 |
File size: | 40'916 bytes |
MD5 hash: | 5A6E0971A54847D4CECC16BF7FA44BCA |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Function 00007FFD9B8D0501 Relevance: .7, Instructions: 657COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D000A Relevance: .5, Instructions: 526COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D0B61 Relevance: .5, Instructions: 456COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D2106 Relevance: .4, Instructions: 415COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D0FEE Relevance: .3, Instructions: 323COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D028D Relevance: .3, Instructions: 267COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D23D5 Relevance: .3, Instructions: 251COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D1FAB Relevance: .2, Instructions: 239COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D1F05 Relevance: .2, Instructions: 230COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8E0501 Relevance: .7, Instructions: 658COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8E000A Relevance: .5, Instructions: 524COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8E0BFF Relevance: .4, Instructions: 448COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8E0FEE Relevance: .3, Instructions: 319COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8E028D Relevance: .3, Instructions: 267COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8E0BCE Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8E0B61 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8F0501 Relevance: .7, Instructions: 658COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8F003C Relevance: .5, Instructions: 507COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8F0B61 Relevance: .4, Instructions: 449COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8F0FEE Relevance: .3, Instructions: 320COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8F028D Relevance: .3, Instructions: 267COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D0501 Relevance: .7, Instructions: 657COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D000A Relevance: .5, Instructions: 524COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D0B61 Relevance: .5, Instructions: 456COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D0FEE Relevance: .3, Instructions: 324COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8D028D Relevance: .3, Instructions: 267COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|