Windows
Analysis Report
kGSZ4dCqYh.exe
Overview
General Information
Sample name: | kGSZ4dCqYh.exerenamed because original name is a hash value |
Original sample name: | bab1912f10355b913050217669acc322.exe |
Analysis ID: | 1541371 |
MD5: | bab1912f10355b913050217669acc322 |
SHA1: | 17848e8aa5e443c06d495c500e642be0967cabe6 |
SHA256: | 38dc7521a2e99fb4c095f74b51dadf8b10fdf680ecbcecb419e6720e8151096d |
Tags: | exeStealcuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- kGSZ4dCqYh.exe (PID: 6752 cmdline:
"C:\Users\ user\Deskt op\kGSZ4dC qYh.exe" MD5: BAB1912F10355B913050217669ACC322) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- dvjdfvr (PID: 5164 cmdline:
C:\Users\u ser\AppDat a\Roaming\ dvjdfvr MD5: BAB1912F10355B913050217669ACC322)
- dvjdfvr (PID: 1404 cmdline:
C:\Users\u ser\AppDat a\Roaming\ dvjdfvr MD5: BAB1912F10355B913050217669ACC322)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://tnc-corp.ru/tmp/index.php", "http://volisc.biz/tmp/index.php", "http://livbev.online/tmp/index.php", "http://liverds.at/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-24T18:37:39.640493+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49736 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:38:58.525736+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50003 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:39:12.106292+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50004 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:39:31.867272+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 53258 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:39:51.793152+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 58682 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:40:12.354239+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 58683 | 201.124.145.196 | 80 | TCP |
2024-10-24T18:40:27.315155+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 58684 | 201.124.145.196 | 80 | TCP |
2024-10-24T18:40:45.531760+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 58685 | 201.124.145.196 | 80 | TCP |
2024-10-24T18:41:03.377372+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 58686 | 201.124.145.196 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Code function: | 7_2_00402780 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00403054 | |
Source: | Code function: | 0_2_00401583 | |
Source: | Code function: | 0_2_00402721 | |
Source: | Code function: | 0_2_0040158E | |
Source: | Code function: | 0_2_004015BC | |
Source: | Code function: | 5_2_00403054 | |
Source: | Code function: | 5_2_00401583 | |
Source: | Code function: | 5_2_00402721 | |
Source: | Code function: | 5_2_0040158E | |
Source: | Code function: | 5_2_004015BC |
Source: | Code function: | 0_2_00401A28 | |
Source: | Code function: | 5_2_00401A28 | |
Source: | Code function: | 7_2_0040FC4F | |
Source: | Code function: | 7_2_0040E038 | |
Source: | Code function: | 7_2_0040D5B0 | |
Source: | Code function: | 7_2_00404E2D | |
Source: | Code function: | 7_2_00403ECD | |
Source: | Code function: | 7_2_0040DAF4 | |
Source: | Code function: | 7_2_0040E730 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_006019D7 |
Source: | File created: | Jump to behavior |
Source: | Command line argument: | 7_2_00402DF0 | |
Source: | Command line argument: | 7_2_00402DF0 |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Code function: | 7_2_00409B95 |
Source: | Code function: | 0_2_00402957 | |
Source: | Code function: | 0_2_00402926 | |
Source: | Code function: | 0_2_00402942 | |
Source: | Code function: | 0_2_00608F78 | |
Source: | Code function: | 0_2_00609332 | |
Source: | Code function: | 0_2_00609332 | |
Source: | Code function: | 0_2_00603114 | |
Source: | Code function: | 0_2_006229BE | |
Source: | Code function: | 0_2_0062298D | |
Source: | Code function: | 0_2_006229A9 | |
Source: | Code function: | 5_2_00402957 | |
Source: | Code function: | 5_2_00402926 | |
Source: | Code function: | 5_2_00402942 | |
Source: | Code function: | 5_2_00538F78 | |
Source: | Code function: | 5_2_00533114 | |
Source: | Code function: | 5_2_00539332 | |
Source: | Code function: | 5_2_00539332 | |
Source: | Code function: | 5_2_005529A9 | |
Source: | Code function: | 5_2_0055298D | |
Source: | Code function: | 5_2_005529BE | |
Source: | Code function: | 7_2_0040544C |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Evasive API call chain: | graph_7-6562 |
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 7_2_00402780 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_7-6564 |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 7_2_0040841C |
Source: | Code function: | 7_2_00409B95 |
Source: | Code function: | 0_2_006012B4 | |
Source: | Code function: | 0_2_0062092B | |
Source: | Code function: | 0_2_00620D90 | |
Source: | Code function: | 5_2_005312B4 | |
Source: | Code function: | 5_2_0055092B | |
Source: | Code function: | 5_2_00550D90 |
Source: | Code function: | 7_2_0040841C | |
Source: | Code function: | 7_2_00406DBA | |
Source: | Code function: | 7_2_0040BE4E | |
Source: | Code function: | 7_2_00407345 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 7_2_0040F4CC |
Source: | Code function: | 7_2_004029B0 |
Source: | Code function: | 7_2_00408071 |
Source: | Code function: | 7_2_00402780 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 DLL Side-Loading | 33 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 2 Native API | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 521 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 33 Process Injection | Security Account Manager | 12 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 112 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Software Packing | Cached Domain Credentials | 2 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 114 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Win32.Dropper.Generic | ||
100% | Avira | HEUR/AGEN.1306978 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1306978 | ||
100% | Joe Sandbox ML | |||
39% | ReversingLabs | Win32.Trojan.Generic |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
tnc-corp.ru | 189.164.127.217 | true | true | unknown | |
volisc.biz | unknown | unknown | true | unknown | |
liverds.at | unknown | unknown | true | unknown | |
livbev.online | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
201.124.145.196 | unknown | Mexico | 8151 | UninetSAdeCVMX | true | |
189.164.127.217 | tnc-corp.ru | Mexico | 8151 | UninetSAdeCVMX | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1541371 |
Start date and time: | 2024-10-24 18:36:08 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | kGSZ4dCqYh.exerenamed because original name is a hash value |
Original Sample Name: | bab1912f10355b913050217669acc322.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@3/2@83/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 20.190.159.2, 40.126.31.67, 40.126.31.71, 20.190.159.0, 40.126.31.69, 20.190.159.4, 20.190.159.71, 20.190.159.75
- Excluded domains from analysis (whitelisted): prdv4a.aadg.msidentity.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, login.live.com, www.tm.v4.a.prd.aadg.akadns.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, www.tm.lg.prod.aadmsa.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: kGSZ4dCqYh.exe
Time | Type | Description |
---|---|---|
12:37:33 | API Interceptor | |
17:37:35 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
tnc-corp.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UninetSAdeCVMX | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
UninetSAdeCVMX | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 399360 |
Entropy (8bit): | 6.446097347649339 |
Encrypted: | false |
SSDEEP: | 6144:StLH/6zftGuIHMvxZ8NQhrOjAx99iqyyvw9R81aPFhbpxA5HcH/kWTW:SqfIu2GmOssxyyIL81aPFhtGuj |
MD5: | BAB1912F10355B913050217669ACC322 |
SHA1: | 17848E8AA5E443C06D495C500E642BE0967CABE6 |
SHA-256: | 38DC7521A2E99FB4C095F74B51DADF8B10FDF680ECBCECB419E6720E8151096D |
SHA-512: | A96A1B0190A97E1D61AE00D82E85AB720A80C976D0F450EEAA4A9237EA337DC674746E23C458AA3023044CB7F9B6AD9D39A73C4401875876192D14FC437D012A |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 6.446097347649339 |
TrID: |
|
File name: | kGSZ4dCqYh.exe |
File size: | 399'360 bytes |
MD5: | bab1912f10355b913050217669acc322 |
SHA1: | 17848e8aa5e443c06d495c500e642be0967cabe6 |
SHA256: | 38dc7521a2e99fb4c095f74b51dadf8b10fdf680ecbcecb419e6720e8151096d |
SHA512: | a96a1b0190a97e1d61ae00d82e85ab720a80c976d0f450eeaa4a9237ea337dc674746e23c458aa3023044cb7f9b6ad9d39a73c4401875876192d14fc437d012a |
SSDEEP: | 6144:StLH/6zftGuIHMvxZ8NQhrOjAx99iqyyvw9R81aPFhbpxA5HcH/kWTW:SqfIu2GmOssxyyIL81aPFhtGuj |
TLSH: | 4C84E1113AA0F870C5520E304D28D3E97ABEFC729A64598B371C7F5F7C39391A6A6706 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Z...Z...Z...D...z...D...B...D.......}3.._...Z...'...D...[...D...[...D...[...RichZ...................PE..L....z.d........... |
Icon Hash: | 63796de971436e0f |
Entrypoint: | 0x403a18 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x64F07A8F [Thu Aug 31 11:33:35 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | 60292dd185c67d0ddd8dc10e8ecfb2bb |
Instruction |
---|
call 00007F1F98815669h |
jmp 00007F1F98810E8Eh |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
call 00007F1F9881104Ch |
xchg cl, ch |
jmp 00007F1F98811034h |
call 00007F1F98811043h |
fxch st(0), st(1) |
jmp 00007F1F9881102Bh |
fabs |
fld1 |
mov ch, cl |
xor cl, cl |
jmp 00007F1F98811021h |
mov byte ptr [ebp-00000090h], FFFFFFFEh |
fabs |
fxch st(0), st(1) |
fabs |
fxch st(0), st(1) |
fpatan |
or cl, cl |
je 00007F1F98811016h |
fldpi |
fsubrp st(1), st(0) |
or ch, ch |
je 00007F1F98811014h |
fchs |
ret |
fabs |
fld st(0), st(0) |
fld st(0), st(0) |
fld1 |
fsubrp st(1), st(0) |
fxch st(0), st(1) |
fld1 |
faddp st(1), st(0) |
fmulp st(1), st(0) |
ftst |
wait |
fstsw word ptr [ebp-000000A0h] |
wait |
test byte ptr [ebp-0000009Fh], 00000001h |
jne 00007F1F98811017h |
xor ch, ch |
fsqrt |
ret |
pop eax |
jmp 00007F1F9881582Fh |
fstp st(0) |
fld tbyte ptr [004497EAh] |
ret |
fstp st(0) |
or cl, cl |
je 00007F1F9881101Dh |
fstp st(0) |
fldpi |
or ch, ch |
je 00007F1F98811014h |
fchs |
ret |
fstp st(0) |
fldz |
or ch, ch |
je 00007F1F98811009h |
fchs |
ret |
fstp st(0) |
jmp 00007F1F98815805h |
fstp st(0) |
mov cl, ch |
jmp 00007F1F98811012h |
call 00007F1F98810FDEh |
jmp 00007F1F98815810h |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x47774 | 0x3c | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x5b000 | 0x12b58 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6e000 | 0xa48 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x2690 | 0x40 | .text |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x1000 | 0x19c | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x470d4 | 0x47200 | fdfc02f95441d5de39fe3ca16d404bde | False | 0.7339939861599297 | OpenPGP Secret Key Version 4 | 7.014294223606666 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.data | 0x49000 | 0x1185c | 0x6000 | 27249428db74ea0fe3ff506f8860ff3d | False | 0.07784016927083333 | Matlab v4 mat-file (little endian) n2, sparse, rows 0, columns 0 | 0.9053342754782987 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x5b000 | 0x12b58 | 0x12c00 | e8d4a5e3d5fb7eafd6df3aa7ac23f8f5 | False | 0.40013020833333335 | data | 5.021811724306864 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x6e000 | 0x14be | 0x1600 | 7ce203f0c14ffae82977c4b4b95d3fda | False | 0.4053622159090909 | data | 3.9742437726842943 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
XUBONAVEGUCIZAKUFAMABAWADUJATA | 0x65130 | 0x1e31 | ASCII text, with very long lines (7729), with no line terminators | Tamil | India | 0.5879156423858196 |
XUBONAVEGUCIZAKUFAMABAWADUJATA | 0x65130 | 0x1e31 | ASCII text, with very long lines (7729), with no line terminators | Tamil | Sri Lanka | 0.5879156423858196 |
RT_CURSOR | 0x66fc0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.2953091684434968 | ||
RT_CURSOR | 0x67e68 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | 0.46705776173285196 | ||
RT_CURSOR | 0x68710 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | 0.5361271676300579 | ||
RT_CURSOR | 0x68ca8 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.4375 | ||
RT_CURSOR | 0x68dd8 | 0xb0 | Device independent bitmap graphic, 16 x 32 x 1, image size 0 | 0.44886363636363635 | ||
RT_CURSOR | 0x68eb0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.27238805970149255 | ||
RT_CURSOR | 0x69d58 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | 0.375 | ||
RT_CURSOR | 0x6a600 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | 0.5057803468208093 | ||
RT_CURSOR | 0x6ab98 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.30943496801705755 | ||
RT_CURSOR | 0x6ba40 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | 0.427797833935018 | ||
RT_CURSOR | 0x6c2e8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | 0.5469653179190751 | ||
RT_ICON | 0x5b7f0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | India | 0.5351382488479263 |
RT_ICON | 0x5b7f0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | Sri Lanka | 0.5351382488479263 |
RT_ICON | 0x5beb8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.41151452282157674 |
RT_ICON | 0x5beb8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.41151452282157674 |
RT_ICON | 0x5e460 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.44680851063829785 |
RT_ICON | 0x5e460 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.44680851063829785 |
RT_ICON | 0x5e8f8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | India | 0.36886993603411516 |
RT_ICON | 0x5e8f8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | Sri Lanka | 0.36886993603411516 |
RT_ICON | 0x5f7a0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | India | 0.5130866425992779 |
RT_ICON | 0x5f7a0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | Sri Lanka | 0.5130866425992779 |
RT_ICON | 0x60048 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | India | 0.5841013824884793 |
RT_ICON | 0x60048 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | Sri Lanka | 0.5841013824884793 |
RT_ICON | 0x60710 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | India | 0.6502890173410405 |
RT_ICON | 0x60710 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | Sri Lanka | 0.6502890173410405 |
RT_ICON | 0x60c78 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | India | 0.462448132780083 |
RT_ICON | 0x60c78 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | Sri Lanka | 0.462448132780083 |
RT_ICON | 0x63220 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | India | 0.475375234521576 |
RT_ICON | 0x63220 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | Sri Lanka | 0.475375234521576 |
RT_ICON | 0x642c8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | India | 0.45778688524590166 |
RT_ICON | 0x642c8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | Sri Lanka | 0.45778688524590166 |
RT_ICON | 0x64c50 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | India | 0.5106382978723404 |
RT_ICON | 0x64c50 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | Sri Lanka | 0.5106382978723404 |
RT_DIALOG | 0x6cad8 | 0x58 | data | 0.8977272727272727 | ||
RT_STRING | 0x6cb30 | 0x374 | data | Tamil | India | 0.46945701357466063 |
RT_STRING | 0x6cb30 | 0x374 | data | Tamil | Sri Lanka | 0.46945701357466063 |
RT_STRING | 0x6cea8 | 0x2ae | data | Tamil | India | 0.478134110787172 |
RT_STRING | 0x6cea8 | 0x2ae | data | Tamil | Sri Lanka | 0.478134110787172 |
RT_STRING | 0x6d158 | 0x4e8 | data | Tamil | India | 0.4434713375796178 |
RT_STRING | 0x6d158 | 0x4e8 | data | Tamil | Sri Lanka | 0.4434713375796178 |
RT_STRING | 0x6d640 | 0x514 | data | Tamil | India | 0.4276923076923077 |
RT_STRING | 0x6d640 | 0x514 | data | Tamil | Sri Lanka | 0.4276923076923077 |
RT_ACCELERATOR | 0x66f68 | 0x58 | data | Tamil | India | 0.7954545454545454 |
RT_ACCELERATOR | 0x66f68 | 0x58 | data | Tamil | Sri Lanka | 0.7954545454545454 |
RT_GROUP_CURSOR | 0x68c78 | 0x30 | data | 0.9375 | ||
RT_GROUP_CURSOR | 0x68e88 | 0x22 | data | 1.0588235294117647 | ||
RT_GROUP_CURSOR | 0x6ab68 | 0x30 | data | 0.9375 | ||
RT_GROUP_CURSOR | 0x6c850 | 0x30 | data | 0.9375 | ||
RT_GROUP_ICON | 0x5e8c8 | 0x30 | data | Tamil | India | 0.9375 |
RT_GROUP_ICON | 0x5e8c8 | 0x30 | data | Tamil | Sri Lanka | 0.9375 |
RT_GROUP_ICON | 0x650b8 | 0x76 | data | Tamil | India | 0.6694915254237288 |
RT_GROUP_ICON | 0x650b8 | 0x76 | data | Tamil | Sri Lanka | 0.6694915254237288 |
RT_VERSION | 0x6c880 | 0x254 | data | 0.535234899328859 |
DLL | Import |
---|---|
KERNEL32.dll | GlobalCompact, CreateProcessW, InterlockedIncrement, GetCurrentProcess, GetLogicalDriveStringsW, CreateJobObjectW, SetComputerNameW, SetVolumeMountPointW, GetComputerNameW, GetTickCount, GetCommConfig, ClearCommBreak, GetConsoleAliasExesW, EnumTimeFormatsW, TlsSetValue, GetEnvironmentStrings, SetFileShortNameW, ReadConsoleInputA, GetVersionExW, GetFileAttributesA, GlobalMemoryStatus, GetModuleFileNameW, GetShortPathNameA, VerifyVersionInfoW, InterlockedExchange, GetLastError, SetLastError, GetProcAddress, VirtualAlloc, DefineDosDeviceW, CreateNamedPipeA, SetFileAttributesA, LoadLibraryA, GetNumberFormatW, OpenJobObjectW, SetEnvironmentVariableA, GetCurrentDirectoryA, OpenEventW, LCMapStringW, CommConfigDialogW, GetTimeFormatW, GetTempFileNameW, HeapAlloc, HeapReAlloc, GetStartupInfoW, RaiseException, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapFree, VirtualFree, HeapCreate, GetModuleHandleW, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, TlsGetValue, TlsAlloc, TlsFree, GetCurrentThreadId, InterlockedDecrement, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, GetModuleHandleA, InitializeCriticalSectionAndSpinCount, RtlUnwind, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, WideCharToMultiByte, HeapSize, GetLocaleInfoA, LCMapStringA, MultiByteToWideChar, GetStringTypeA, GetStringTypeW, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, CloseHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetStdHandle, CreateFileA |
GDI32.dll | GetCharWidth32A |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Tamil | India | |
Tamil | Sri Lanka |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-24T18:37:39.640493+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49736 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:38:58.525736+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50003 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:39:12.106292+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50004 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:39:31.867272+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 53258 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:39:51.793152+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 58682 | 189.164.127.217 | 80 | TCP |
2024-10-24T18:40:12.354239+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 58683 | 201.124.145.196 | 80 | TCP |
2024-10-24T18:40:27.315155+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 58684 | 201.124.145.196 | 80 | TCP |
2024-10-24T18:40:45.531760+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 58685 | 201.124.145.196 | 80 | TCP |
2024-10-24T18:41:03.377372+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 58686 | 201.124.145.196 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 24, 2024 18:37:38.809153080 CEST | 49736 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:37:38.814568996 CEST | 80 | 49736 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:37:38.814672947 CEST | 49736 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:37:38.814829111 CEST | 49736 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:37:38.814851046 CEST | 49736 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:37:38.820297956 CEST | 80 | 49736 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:37:38.820322990 CEST | 80 | 49736 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:37:39.640352011 CEST | 80 | 49736 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:37:39.640492916 CEST | 49736 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:37:39.646840096 CEST | 49736 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:37:39.652280092 CEST | 80 | 49736 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:38:57.702812910 CEST | 50003 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:38:57.708116055 CEST | 80 | 50003 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:38:57.708194971 CEST | 50003 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:38:57.708359957 CEST | 50003 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:38:57.708403111 CEST | 50003 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:38:57.713778019 CEST | 80 | 50003 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:38:57.713787079 CEST | 80 | 50003 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:38:58.525589943 CEST | 80 | 50003 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:38:58.525736094 CEST | 50003 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:38:58.525759935 CEST | 50003 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:38:58.531079054 CEST | 80 | 50003 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:11.292944908 CEST | 50004 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:11.298408985 CEST | 80 | 50004 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:11.298485041 CEST | 50004 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:11.298638105 CEST | 50004 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:11.298665047 CEST | 50004 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:11.303926945 CEST | 80 | 50004 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:11.303936958 CEST | 80 | 50004 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:12.104166985 CEST | 80 | 50004 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:12.106292009 CEST | 50004 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:12.106292963 CEST | 50004 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:12.111700058 CEST | 80 | 50004 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:31.052088976 CEST | 53258 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:31.057555914 CEST | 80 | 53258 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:31.057660103 CEST | 53258 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:31.057832003 CEST | 53258 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:31.057862043 CEST | 53258 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:31.063290119 CEST | 80 | 53258 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:31.063405991 CEST | 80 | 53258 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:31.867206097 CEST | 80 | 53258 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:31.867271900 CEST | 53258 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:31.867327929 CEST | 53258 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:31.873389959 CEST | 80 | 53258 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:50.970066071 CEST | 58682 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:50.976711988 CEST | 80 | 58682 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:50.976787090 CEST | 58682 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:50.976933956 CEST | 58682 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:50.976965904 CEST | 58682 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:50.982501030 CEST | 80 | 58682 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:50.983058929 CEST | 80 | 58682 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:51.793059111 CEST | 80 | 58682 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:39:51.793152094 CEST | 58682 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:51.793653011 CEST | 58682 | 80 | 192.168.2.4 | 189.164.127.217 |
Oct 24, 2024 18:39:51.799093008 CEST | 80 | 58682 | 189.164.127.217 | 192.168.2.4 |
Oct 24, 2024 18:40:11.614111900 CEST | 58683 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:11.619623899 CEST | 80 | 58683 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:11.619712114 CEST | 58683 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:11.621645927 CEST | 58683 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:11.621646881 CEST | 58683 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:11.627052069 CEST | 80 | 58683 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:11.627221107 CEST | 80 | 58683 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:12.353992939 CEST | 80 | 58683 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:12.354238987 CEST | 58683 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:12.354238987 CEST | 58683 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:12.359880924 CEST | 80 | 58683 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:26.488370895 CEST | 58684 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:26.494388103 CEST | 80 | 58684 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:26.494493961 CEST | 58684 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:26.494584084 CEST | 58684 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:26.494601011 CEST | 58684 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:26.499955893 CEST | 80 | 58684 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:26.500116110 CEST | 80 | 58684 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:27.315067053 CEST | 80 | 58684 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:27.315155029 CEST | 58684 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:27.315222025 CEST | 58684 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:27.320749044 CEST | 80 | 58684 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:44.707995892 CEST | 58685 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:44.713737011 CEST | 80 | 58685 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:44.713851929 CEST | 58685 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:44.713968992 CEST | 58685 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:44.714004040 CEST | 58685 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:44.719439983 CEST | 80 | 58685 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:44.719499111 CEST | 80 | 58685 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:45.531666994 CEST | 80 | 58685 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:40:45.531759977 CEST | 58685 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:45.533857107 CEST | 58685 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:40:45.539627075 CEST | 80 | 58685 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:41:02.543734074 CEST | 58686 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:41:02.565335035 CEST | 80 | 58686 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:41:02.565501928 CEST | 58686 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:41:02.565610886 CEST | 58686 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:41:02.565638065 CEST | 58686 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:41:02.571108103 CEST | 80 | 58686 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:41:02.571614027 CEST | 80 | 58686 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:41:03.377175093 CEST | 80 | 58686 | 201.124.145.196 | 192.168.2.4 |
Oct 24, 2024 18:41:03.377372026 CEST | 58686 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:41:03.380084991 CEST | 58686 | 80 | 192.168.2.4 | 201.124.145.196 |
Oct 24, 2024 18:41:03.385701895 CEST | 80 | 58686 | 201.124.145.196 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 24, 2024 18:37:36.562937975 CEST | 62460 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:37.560062885 CEST | 62460 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:38.575629950 CEST | 62460 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:38.807322979 CEST | 53 | 62460 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:38.807343960 CEST | 53 | 62460 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:38.807356119 CEST | 53 | 62460 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:39.708722115 CEST | 54685 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:40.700933933 CEST | 54685 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:41.716922045 CEST | 54685 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:43.731969118 CEST | 54685 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:45.982157946 CEST | 53 | 54685 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:45.982176065 CEST | 53 | 54685 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:45.982188940 CEST | 53 | 54685 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:45.982542992 CEST | 53 | 54685 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:45.990561962 CEST | 63838 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:46.001085043 CEST | 53 | 63838 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:46.004443884 CEST | 59949 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:46.997514009 CEST | 59949 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:48.013371944 CEST | 59949 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:50.043087006 CEST | 59949 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:37:52.265104055 CEST | 53 | 59949 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:52.265126944 CEST | 53 | 59949 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:52.265140057 CEST | 53 | 59949 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:37:52.265301943 CEST | 53 | 59949 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:38:58.528233051 CEST | 51766 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:38:59.517595053 CEST | 51766 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:00.532829046 CEST | 51766 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:02.544687986 CEST | 51766 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:04.717839956 CEST | 53 | 51766 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:04.717888117 CEST | 53 | 51766 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:04.717899084 CEST | 53 | 51766 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:04.717907906 CEST | 53 | 51766 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:04.782851934 CEST | 57447 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:04.793390036 CEST | 53 | 57447 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:04.871172905 CEST | 61679 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:05.873804092 CEST | 61679 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:06.894021034 CEST | 61679 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:08.894138098 CEST | 61679 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:11.105513096 CEST | 53 | 61679 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:11.105526924 CEST | 53 | 61679 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:11.105535030 CEST | 53 | 61679 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:11.105869055 CEST | 53 | 61679 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:12.166372061 CEST | 51673 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:13.153822899 CEST | 51673 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:13.161305904 CEST | 53 | 51673 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:18.460525036 CEST | 53 | 51673 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:20.863650084 CEST | 64363 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:20.873910904 CEST | 53 | 64363 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:20.897675037 CEST | 65165 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:21.888170958 CEST | 65165 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:22.904638052 CEST | 65165 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:24.919538021 CEST | 65165 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:27.112010002 CEST | 53 | 65165 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:27.112081051 CEST | 53 | 65165 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:27.112111092 CEST | 53 | 65165 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:27.112143040 CEST | 53 | 65165 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:31.873675108 CEST | 52537 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:32.872932911 CEST | 52537 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:32.880987883 CEST | 53 | 52537 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:38.116784096 CEST | 53 | 52537 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:40.589396954 CEST | 59400 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:40.602171898 CEST | 53 | 59400 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:40.604391098 CEST | 56105 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:41.592582941 CEST | 56105 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:42.609253883 CEST | 56105 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:44.624702930 CEST | 56105 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:46.820019007 CEST | 53 | 56105 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:46.820038080 CEST | 53 | 56105 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:46.820044041 CEST | 53 | 56105 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:46.820339918 CEST | 53 | 56105 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:51.826590061 CEST | 49186 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:52.845719099 CEST | 49186 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:53.858628035 CEST | 49186 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:55.876540899 CEST | 49186 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:58.078646898 CEST | 53 | 49186 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:58.078690052 CEST | 53 | 49186 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:58.078747988 CEST | 53 | 49186 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:58.078775883 CEST | 53 | 49186 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:58.101263046 CEST | 62768 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:58.111707926 CEST | 53 | 62768 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:39:58.113786936 CEST | 56440 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:39:59.107065916 CEST | 56440 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:00.125298977 CEST | 56440 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:02.138252020 CEST | 56440 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:04.223443985 CEST | 53 | 56440 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:04.223489046 CEST | 53 | 56440 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:04.223519087 CEST | 53 | 56440 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:04.223643064 CEST | 53 | 56440 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:09.297966003 CEST | 63112 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:10.294504881 CEST | 63112 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:11.310251951 CEST | 63112 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:11.609256029 CEST | 53 | 63112 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:11.609308958 CEST | 53 | 63112 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:11.609339952 CEST | 53 | 63112 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:12.359304905 CEST | 51031 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:13.372755051 CEST | 51031 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:14.388329029 CEST | 51031 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:16.405164957 CEST | 51031 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:18.584759951 CEST | 53 | 51031 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:18.584814072 CEST | 53 | 51031 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:18.584844112 CEST | 53 | 51031 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:18.584871054 CEST | 53 | 51031 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:18.596683025 CEST | 50723 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:18.607841015 CEST | 53 | 50723 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:18.610503912 CEST | 53235 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:19.622826099 CEST | 53235 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:20.622656107 CEST | 53235 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:22.638307095 CEST | 53235 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:22.690511942 CEST | 53 | 53235 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:22.690557003 CEST | 53 | 53235 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:22.690587997 CEST | 53 | 53235 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:22.690624952 CEST | 53 | 53235 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:27.322776079 CEST | 63634 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:28.315013885 CEST | 63634 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:29.332726955 CEST | 63634 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:31.327733994 CEST | 63634 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:33.543411016 CEST | 53 | 63634 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:33.543457985 CEST | 53 | 63634 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:33.543488026 CEST | 53 | 63634 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:33.543524027 CEST | 53 | 63634 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:33.547537088 CEST | 59129 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:33.558007956 CEST | 53 | 59129 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:33.560375929 CEST | 50813 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:34.565747976 CEST | 50813 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:35.564198971 CEST | 50813 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:37.954163074 CEST | 50813 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:39.825125933 CEST | 53 | 50813 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:39.825176001 CEST | 53 | 50813 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:39.825206041 CEST | 53 | 50813 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:39.825730085 CEST | 53 | 50813 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:45.712955952 CEST | 51407 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:46.724524975 CEST | 51407 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:47.736038923 CEST | 51407 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:49.733963013 CEST | 51407 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:51.966073036 CEST | 53 | 51407 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:51.966123104 CEST | 53 | 51407 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:51.966160059 CEST | 53 | 51407 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:51.966187954 CEST | 53 | 51407 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:51.980016947 CEST | 51548 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:51.989211082 CEST | 53 | 51548 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:51.991645098 CEST | 58951 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:53.001231909 CEST | 58951 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:54.016474962 CEST | 58951 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:56.034240961 CEST | 58951 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:40:58.242844105 CEST | 53 | 58951 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:58.242886066 CEST | 53 | 58951 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:58.242913961 CEST | 53 | 58951 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:40:58.243598938 CEST | 53 | 58951 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:03.453121901 CEST | 51713 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:04.451117039 CEST | 51713 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:05.466629982 CEST | 51713 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:07.466615915 CEST | 51713 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:09.679297924 CEST | 53 | 51713 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:09.679366112 CEST | 53 | 51713 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:09.679379940 CEST | 53 | 51713 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:09.679398060 CEST | 53 | 51713 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:09.685657978 CEST | 54716 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:09.694380999 CEST | 53 | 54716 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:09.702735901 CEST | 59762 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:10.718682051 CEST | 59762 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:11.716528893 CEST | 59762 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:13.716519117 CEST | 59762 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 24, 2024 18:41:16.406060934 CEST | 53 | 59762 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:16.406099081 CEST | 53 | 59762 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:16.406109095 CEST | 53 | 59762 | 1.1.1.1 | 192.168.2.4 |
Oct 24, 2024 18:41:16.406213045 CEST | 53 | 59762 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 24, 2024 18:37:36.562937975 CEST | 192.168.2.4 | 1.1.1.1 | 0x4adf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:37.560062885 CEST | 192.168.2.4 | 1.1.1.1 | 0x4adf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:38.575629950 CEST | 192.168.2.4 | 1.1.1.1 | 0x4adf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:39.708722115 CEST | 192.168.2.4 | 1.1.1.1 | 0x7af7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:40.700933933 CEST | 192.168.2.4 | 1.1.1.1 | 0x7af7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:41.716922045 CEST | 192.168.2.4 | 1.1.1.1 | 0x7af7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:43.731969118 CEST | 192.168.2.4 | 1.1.1.1 | 0x7af7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:45.990561962 CEST | 192.168.2.4 | 1.1.1.1 | 0x3612 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:46.004443884 CEST | 192.168.2.4 | 1.1.1.1 | 0xb070 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:46.997514009 CEST | 192.168.2.4 | 1.1.1.1 | 0xb070 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:48.013371944 CEST | 192.168.2.4 | 1.1.1.1 | 0xb070 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:50.043087006 CEST | 192.168.2.4 | 1.1.1.1 | 0xb070 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:38:58.528233051 CEST | 192.168.2.4 | 1.1.1.1 | 0xaea2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:38:59.517595053 CEST | 192.168.2.4 | 1.1.1.1 | 0xaea2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:00.532829046 CEST | 192.168.2.4 | 1.1.1.1 | 0xaea2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:02.544687986 CEST | 192.168.2.4 | 1.1.1.1 | 0xaea2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:04.782851934 CEST | 192.168.2.4 | 1.1.1.1 | 0x1c4e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:04.871172905 CEST | 192.168.2.4 | 1.1.1.1 | 0xed8a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:05.873804092 CEST | 192.168.2.4 | 1.1.1.1 | 0xed8a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:06.894021034 CEST | 192.168.2.4 | 1.1.1.1 | 0xed8a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:08.894138098 CEST | 192.168.2.4 | 1.1.1.1 | 0xed8a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:12.166372061 CEST | 192.168.2.4 | 1.1.1.1 | 0x2e23 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:13.153822899 CEST | 192.168.2.4 | 1.1.1.1 | 0x2e23 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:20.863650084 CEST | 192.168.2.4 | 1.1.1.1 | 0xda34 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:20.897675037 CEST | 192.168.2.4 | 1.1.1.1 | 0x236 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:21.888170958 CEST | 192.168.2.4 | 1.1.1.1 | 0x236 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:22.904638052 CEST | 192.168.2.4 | 1.1.1.1 | 0x236 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:24.919538021 CEST | 192.168.2.4 | 1.1.1.1 | 0x236 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:31.873675108 CEST | 192.168.2.4 | 1.1.1.1 | 0x256b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:32.872932911 CEST | 192.168.2.4 | 1.1.1.1 | 0x256b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:40.589396954 CEST | 192.168.2.4 | 1.1.1.1 | 0x6b8e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:40.604391098 CEST | 192.168.2.4 | 1.1.1.1 | 0xd3a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:41.592582941 CEST | 192.168.2.4 | 1.1.1.1 | 0xd3a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:42.609253883 CEST | 192.168.2.4 | 1.1.1.1 | 0xd3a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:44.624702930 CEST | 192.168.2.4 | 1.1.1.1 | 0xd3a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:51.826590061 CEST | 192.168.2.4 | 1.1.1.1 | 0xe9dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:52.845719099 CEST | 192.168.2.4 | 1.1.1.1 | 0xe9dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:53.858628035 CEST | 192.168.2.4 | 1.1.1.1 | 0xe9dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:55.876540899 CEST | 192.168.2.4 | 1.1.1.1 | 0xe9dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:58.101263046 CEST | 192.168.2.4 | 1.1.1.1 | 0xf7fa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:58.113786936 CEST | 192.168.2.4 | 1.1.1.1 | 0x5143 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:59.107065916 CEST | 192.168.2.4 | 1.1.1.1 | 0x5143 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:00.125298977 CEST | 192.168.2.4 | 1.1.1.1 | 0x5143 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:02.138252020 CEST | 192.168.2.4 | 1.1.1.1 | 0x5143 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:09.297966003 CEST | 192.168.2.4 | 1.1.1.1 | 0xaf62 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:10.294504881 CEST | 192.168.2.4 | 1.1.1.1 | 0xaf62 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:11.310251951 CEST | 192.168.2.4 | 1.1.1.1 | 0xaf62 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:12.359304905 CEST | 192.168.2.4 | 1.1.1.1 | 0xed1f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:13.372755051 CEST | 192.168.2.4 | 1.1.1.1 | 0xed1f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:14.388329029 CEST | 192.168.2.4 | 1.1.1.1 | 0xed1f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:16.405164957 CEST | 192.168.2.4 | 1.1.1.1 | 0xed1f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:18.596683025 CEST | 192.168.2.4 | 1.1.1.1 | 0x647d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:18.610503912 CEST | 192.168.2.4 | 1.1.1.1 | 0x4f05 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:19.622826099 CEST | 192.168.2.4 | 1.1.1.1 | 0x4f05 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:20.622656107 CEST | 192.168.2.4 | 1.1.1.1 | 0x4f05 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:22.638307095 CEST | 192.168.2.4 | 1.1.1.1 | 0x4f05 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:27.322776079 CEST | 192.168.2.4 | 1.1.1.1 | 0xa3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:28.315013885 CEST | 192.168.2.4 | 1.1.1.1 | 0xa3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:29.332726955 CEST | 192.168.2.4 | 1.1.1.1 | 0xa3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:31.327733994 CEST | 192.168.2.4 | 1.1.1.1 | 0xa3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:33.547537088 CEST | 192.168.2.4 | 1.1.1.1 | 0xa1c4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:33.560375929 CEST | 192.168.2.4 | 1.1.1.1 | 0x6fb9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:34.565747976 CEST | 192.168.2.4 | 1.1.1.1 | 0x6fb9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:35.564198971 CEST | 192.168.2.4 | 1.1.1.1 | 0x6fb9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:37.954163074 CEST | 192.168.2.4 | 1.1.1.1 | 0x6fb9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:45.712955952 CEST | 192.168.2.4 | 1.1.1.1 | 0x5737 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:46.724524975 CEST | 192.168.2.4 | 1.1.1.1 | 0x5737 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:47.736038923 CEST | 192.168.2.4 | 1.1.1.1 | 0x5737 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:49.733963013 CEST | 192.168.2.4 | 1.1.1.1 | 0x5737 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:51.980016947 CEST | 192.168.2.4 | 1.1.1.1 | 0xc66d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:51.991645098 CEST | 192.168.2.4 | 1.1.1.1 | 0x1c4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:53.001231909 CEST | 192.168.2.4 | 1.1.1.1 | 0x1c4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:54.016474962 CEST | 192.168.2.4 | 1.1.1.1 | 0x1c4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:56.034240961 CEST | 192.168.2.4 | 1.1.1.1 | 0x1c4b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:03.453121901 CEST | 192.168.2.4 | 1.1.1.1 | 0x61e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:04.451117039 CEST | 192.168.2.4 | 1.1.1.1 | 0x61e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:05.466629982 CEST | 192.168.2.4 | 1.1.1.1 | 0x61e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:07.466615915 CEST | 192.168.2.4 | 1.1.1.1 | 0x61e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:09.685657978 CEST | 192.168.2.4 | 1.1.1.1 | 0x8f3b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:09.702735901 CEST | 192.168.2.4 | 1.1.1.1 | 0x6b31 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:10.718682051 CEST | 192.168.2.4 | 1.1.1.1 | 0x6b31 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:11.716528893 CEST | 192.168.2.4 | 1.1.1.1 | 0x6b31 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:13.716519117 CEST | 192.168.2.4 | 1.1.1.1 | 0x6b31 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 201.233.78.169 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 201.124.145.196 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.46.236.4 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.101.193.110 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807322979 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 187.204.82.117 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 201.233.78.169 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 201.124.145.196 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.46.236.4 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.101.193.110 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807343960 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 187.204.82.117 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 201.233.78.169 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 201.124.145.196 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.46.236.4 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 186.101.193.110 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:38.807356119 CEST | 1.1.1.1 | 192.168.2.4 | 0x4adf | No error (0) | 187.204.82.117 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:37:45.982157946 CEST | 1.1.1.1 | 192.168.2.4 | 0x7af7 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:45.982176065 CEST | 1.1.1.1 | 192.168.2.4 | 0x7af7 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:45.982188940 CEST | 1.1.1.1 | 192.168.2.4 | 0x7af7 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:45.982542992 CEST | 1.1.1.1 | 192.168.2.4 | 0x7af7 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:46.001085043 CEST | 1.1.1.1 | 192.168.2.4 | 0x3612 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:52.265104055 CEST | 1.1.1.1 | 192.168.2.4 | 0xb070 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:52.265126944 CEST | 1.1.1.1 | 192.168.2.4 | 0xb070 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:52.265140057 CEST | 1.1.1.1 | 192.168.2.4 | 0xb070 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:37:52.265301943 CEST | 1.1.1.1 | 192.168.2.4 | 0xb070 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:04.717839956 CEST | 1.1.1.1 | 192.168.2.4 | 0xaea2 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:04.717888117 CEST | 1.1.1.1 | 192.168.2.4 | 0xaea2 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:04.717899084 CEST | 1.1.1.1 | 192.168.2.4 | 0xaea2 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:04.717907906 CEST | 1.1.1.1 | 192.168.2.4 | 0xaea2 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:04.793390036 CEST | 1.1.1.1 | 192.168.2.4 | 0x1c4e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:11.105513096 CEST | 1.1.1.1 | 192.168.2.4 | 0xed8a | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:11.105526924 CEST | 1.1.1.1 | 192.168.2.4 | 0xed8a | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:11.105535030 CEST | 1.1.1.1 | 192.168.2.4 | 0xed8a | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:11.105869055 CEST | 1.1.1.1 | 192.168.2.4 | 0xed8a | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:18.460525036 CEST | 1.1.1.1 | 192.168.2.4 | 0x2e23 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:20.873910904 CEST | 1.1.1.1 | 192.168.2.4 | 0xda34 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:27.112010002 CEST | 1.1.1.1 | 192.168.2.4 | 0x236 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:27.112081051 CEST | 1.1.1.1 | 192.168.2.4 | 0x236 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:27.112111092 CEST | 1.1.1.1 | 192.168.2.4 | 0x236 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:27.112143040 CEST | 1.1.1.1 | 192.168.2.4 | 0x236 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:38.116784096 CEST | 1.1.1.1 | 192.168.2.4 | 0x256b | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:40.602171898 CEST | 1.1.1.1 | 192.168.2.4 | 0x6b8e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:46.820019007 CEST | 1.1.1.1 | 192.168.2.4 | 0xd3a0 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:46.820038080 CEST | 1.1.1.1 | 192.168.2.4 | 0xd3a0 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:46.820044041 CEST | 1.1.1.1 | 192.168.2.4 | 0xd3a0 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:46.820339918 CEST | 1.1.1.1 | 192.168.2.4 | 0xd3a0 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:58.078646898 CEST | 1.1.1.1 | 192.168.2.4 | 0xe9dc | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:58.078690052 CEST | 1.1.1.1 | 192.168.2.4 | 0xe9dc | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:58.078747988 CEST | 1.1.1.1 | 192.168.2.4 | 0xe9dc | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:58.078775883 CEST | 1.1.1.1 | 192.168.2.4 | 0xe9dc | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:39:58.111707926 CEST | 1.1.1.1 | 192.168.2.4 | 0xf7fa | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:04.223443985 CEST | 1.1.1.1 | 192.168.2.4 | 0x5143 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:04.223489046 CEST | 1.1.1.1 | 192.168.2.4 | 0x5143 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:04.223519087 CEST | 1.1.1.1 | 192.168.2.4 | 0x5143 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:04.223643064 CEST | 1.1.1.1 | 192.168.2.4 | 0x5143 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 201.124.145.196 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.46.236.4 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.101.193.110 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 187.204.82.117 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 201.233.78.169 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609256029 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 201.124.145.196 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.46.236.4 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.101.193.110 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 187.204.82.117 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 201.233.78.169 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609308958 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 201.124.145.196 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.46.236.4 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.101.193.110 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 187.204.82.117 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 201.233.78.169 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:11.609339952 CEST | 1.1.1.1 | 192.168.2.4 | 0xaf62 | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 24, 2024 18:40:18.584759951 CEST | 1.1.1.1 | 192.168.2.4 | 0xed1f | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:18.584814072 CEST | 1.1.1.1 | 192.168.2.4 | 0xed1f | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:18.584844112 CEST | 1.1.1.1 | 192.168.2.4 | 0xed1f | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:18.584871054 CEST | 1.1.1.1 | 192.168.2.4 | 0xed1f | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:18.607841015 CEST | 1.1.1.1 | 192.168.2.4 | 0x647d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:22.690511942 CEST | 1.1.1.1 | 192.168.2.4 | 0x4f05 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:22.690557003 CEST | 1.1.1.1 | 192.168.2.4 | 0x4f05 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:22.690587997 CEST | 1.1.1.1 | 192.168.2.4 | 0x4f05 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:22.690624952 CEST | 1.1.1.1 | 192.168.2.4 | 0x4f05 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:33.543411016 CEST | 1.1.1.1 | 192.168.2.4 | 0xa3 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:33.543457985 CEST | 1.1.1.1 | 192.168.2.4 | 0xa3 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:33.543488026 CEST | 1.1.1.1 | 192.168.2.4 | 0xa3 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:33.543524027 CEST | 1.1.1.1 | 192.168.2.4 | 0xa3 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:33.558007956 CEST | 1.1.1.1 | 192.168.2.4 | 0xa1c4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:39.825125933 CEST | 1.1.1.1 | 192.168.2.4 | 0x6fb9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:39.825176001 CEST | 1.1.1.1 | 192.168.2.4 | 0x6fb9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:39.825206041 CEST | 1.1.1.1 | 192.168.2.4 | 0x6fb9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:39.825730085 CEST | 1.1.1.1 | 192.168.2.4 | 0x6fb9 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:51.966073036 CEST | 1.1.1.1 | 192.168.2.4 | 0x5737 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:51.966123104 CEST | 1.1.1.1 | 192.168.2.4 | 0x5737 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:51.966160059 CEST | 1.1.1.1 | 192.168.2.4 | 0x5737 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:51.966187954 CEST | 1.1.1.1 | 192.168.2.4 | 0x5737 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:51.989211082 CEST | 1.1.1.1 | 192.168.2.4 | 0xc66d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:58.242844105 CEST | 1.1.1.1 | 192.168.2.4 | 0x1c4b | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:58.242886066 CEST | 1.1.1.1 | 192.168.2.4 | 0x1c4b | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:58.242913961 CEST | 1.1.1.1 | 192.168.2.4 | 0x1c4b | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:40:58.243598938 CEST | 1.1.1.1 | 192.168.2.4 | 0x1c4b | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:09.679297924 CEST | 1.1.1.1 | 192.168.2.4 | 0x61e5 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:09.679366112 CEST | 1.1.1.1 | 192.168.2.4 | 0x61e5 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:09.679379940 CEST | 1.1.1.1 | 192.168.2.4 | 0x61e5 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:09.679398060 CEST | 1.1.1.1 | 192.168.2.4 | 0x61e5 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:09.694380999 CEST | 1.1.1.1 | 192.168.2.4 | 0x8f3b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:16.406060934 CEST | 1.1.1.1 | 192.168.2.4 | 0x6b31 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:16.406099081 CEST | 1.1.1.1 | 192.168.2.4 | 0x6b31 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:16.406109095 CEST | 1.1.1.1 | 192.168.2.4 | 0x6b31 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 24, 2024 18:41:16.406213045 CEST | 1.1.1.1 | 192.168.2.4 | 0x6b31 | Server failure (2) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 189.164.127.217 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:37:38.814829111 CEST | 281 | OUT | |
Oct 24, 2024 18:37:38.814851046 CEST | 344 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 50003 | 189.164.127.217 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:38:57.708359957 CEST | 281 | OUT | |
Oct 24, 2024 18:38:57.708403111 CEST | 128 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 50004 | 189.164.127.217 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:39:11.298638105 CEST | 284 | OUT | |
Oct 24, 2024 18:39:11.298665047 CEST | 362 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 53258 | 189.164.127.217 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:39:31.057832003 CEST | 285 | OUT | |
Oct 24, 2024 18:39:31.057862043 CEST | 129 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 58682 | 189.164.127.217 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:39:50.976933956 CEST | 280 | OUT | |
Oct 24, 2024 18:39:50.976965904 CEST | 187 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 58683 | 201.124.145.196 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:40:11.621645927 CEST | 284 | OUT | |
Oct 24, 2024 18:40:11.621646881 CEST | 228 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 58684 | 201.124.145.196 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:40:26.494584084 CEST | 281 | OUT | |
Oct 24, 2024 18:40:26.494601011 CEST | 119 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 58685 | 201.124.145.196 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:40:44.713968992 CEST | 281 | OUT | |
Oct 24, 2024 18:40:44.714004040 CEST | 365 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 58686 | 201.124.145.196 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 24, 2024 18:41:02.565610886 CEST | 282 | OUT | |
Oct 24, 2024 18:41:02.565638065 CEST | 295 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:37:10 |
Start date: | 24/10/2024 |
Path: | C:\Users\user\Desktop\kGSZ4dCqYh.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 399'360 bytes |
MD5 hash: | BAB1912F10355B913050217669ACC322 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 12:37:16 |
Start date: | 24/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 12:37:35 |
Start date: | 24/10/2024 |
Path: | C:\Users\user\AppData\Roaming\dvjdfvr |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 399'360 bytes |
MD5 hash: | BAB1912F10355B913050217669ACC322 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 12:40:01 |
Start date: | 24/10/2024 |
Path: | C:\Users\user\AppData\Roaming\dvjdfvr |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 399'360 bytes |
MD5 hash: | BAB1912F10355B913050217669ACC322 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 8.9% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 37% |
Total number of Nodes: | 108 |
Total number of Limit Nodes: | 2 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 006019D7 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0062003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00620E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401919 Relevance: 1.3, APIs: 1, Instructions: 79sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401959 Relevance: 1.3, APIs: 1, Instructions: 66sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401970 Relevance: 1.3, APIs: 1, Instructions: 56sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401977 Relevance: 1.3, APIs: 1, Instructions: 56sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401987 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040198A Relevance: 1.3, APIs: 1, Instructions: 50sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00601696 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0062092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00402721 Relevance: 1.4, Strings: 1, Instructions: 151COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A28 Relevance: .3, Instructions: 258COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 006012B4 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00620D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Execution Graph
Execution Coverage: | 8.9% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 108 |
Total number of Limit Nodes: | 2 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0055003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 005319D7 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00550E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401919 Relevance: 1.3, APIs: 1, Instructions: 79sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401959 Relevance: 1.3, APIs: 1, Instructions: 66sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401970 Relevance: 1.3, APIs: 1, Instructions: 56sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401977 Relevance: 1.3, APIs: 1, Instructions: 56sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401987 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040198A Relevance: 1.3, APIs: 1, Instructions: 50sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00531696 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Execution Graph
Execution Coverage: | 0.2% |
Dynamic/Decrypted Code Coverage: | 16.3% |
Signature Coverage: | 4.2% |
Total number of Nodes: | 1745 |
Total number of Limit Nodes: | 0 |
Graph
Function 004038CA Relevance: 21.1, APIs: 14, Instructions: 86COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004055DC Relevance: 1.5, APIs: 1, Instructions: 20memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402780 Relevance: 33.4, APIs: 17, Strings: 2, Instructions: 161timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004029B0 Relevance: 18.1, APIs: 12, Instructions: 99timeprocesspipeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407345 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402AE0 Relevance: 54.5, APIs: 24, Strings: 7, Instructions: 219librarymemoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403194 Relevance: 13.7, APIs: 9, Instructions: 159COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407275 Relevance: 7.5, APIs: 5, Instructions: 44memoryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040904F Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 38libraryloaderCOMMONLIBRARYCODE
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406000 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 20COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|