Windows
Analysis Report
rMT103_126021720924.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- rMT103_126021720924.exe (PID: 2828 cmdline:
"C:\Users\ user\Deskt op\rMT103_ 1260217209 24.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB) - rMT103_126021720924.exe (PID: 6860 cmdline:
"C:\Users\ user\Deskt op\rMT103_ 1260217209 24.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB)
- sgxIb.exe (PID: 7248 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB) - sgxIb.exe (PID: 7304 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB) - sgxIb.exe (PID: 7312 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB) - sgxIb.exe (PID: 7320 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB)
- sgxIb.exe (PID: 7644 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB) - sgxIb.exe (PID: 7704 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 06EF3895BF1C5878463C502A7F1554EB)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "FTP", "Host": "ftp://ftp.haliza.com.my", "Username": "origin@haliza.com.my", "Password": "JesusChrist007$"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
Click to see the 18 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
MALWARE_Win_AgentTeslaV2 | AgenetTesla Type 2 Keylogger payload | ditekSHen |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 17 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T17:03:17.555574+0100 | 2022930 | 1 | A Network Trojan was detected | 172.202.163.200 | 443 | 192.168.2.4 | 49742 | TCP |
2024-10-31T17:03:44.496265+0100 | 2022930 | 1 | A Network Trojan was detected | 172.202.163.200 | 443 | 192.168.2.4 | 63429 | TCP |
2024-10-31T17:03:45.837991+0100 | 2022930 | 1 | A Network Trojan was detected | 172.202.163.200 | 443 | 192.168.2.4 | 63430 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T17:03:18.695850+0100 | 2029927 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 110.4.45.197 | 21 | TCP |
2024-10-31T17:03:26.610863+0100 | 2029927 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 110.4.45.197 | 21 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T17:03:19.796759+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 110.4.45.197 | 59700 | TCP |
2024-10-31T17:03:20.095892+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 110.4.45.197 | 59700 | TCP |
2024-10-31T17:03:27.637706+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 110.4.45.197 | 60611 | TCP |
2024-10-31T17:03:27.651556+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 110.4.45.197 | 60611 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | FTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
Source: | Code function: | 2_2_0685C628 |
Source: | Windows user hook set: | Jump to behavior | ||
Source: | Windows user hook set: |
Source: | Window created: | Jump to behavior | ||
Source: | Window created: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_01393E34 | |
Source: | Code function: | 0_2_0139E04C | |
Source: | Code function: | 0_2_0139703A | |
Source: | Code function: | 0_2_01397000 | |
Source: | Code function: | 0_2_058AC680 | |
Source: | Code function: | 0_2_058A5603 | |
Source: | Code function: | 0_2_058A4600 | |
Source: | Code function: | 0_2_058A5610 | |
Source: | Code function: | 0_2_058AE1E9 | |
Source: | Code function: | 0_2_058AE1F8 | |
Source: | Code function: | 0_2_058A1069 | |
Source: | Code function: | 0_2_058A1078 | |
Source: | Code function: | 0_2_058A2338 | |
Source: | Code function: | 0_2_058A2348 | |
Source: | Code function: | 0_2_058AC238 | |
Source: | Code function: | 0_2_058AC248 | |
Source: | Code function: | 0_2_058ABE10 | |
Source: | Code function: | 0_2_058AD920 | |
Source: | Code function: | 0_2_058A5897 | |
Source: | Code function: | 0_2_058A58A8 | |
Source: | Code function: | 0_2_07841A70 | |
Source: | Code function: | 0_2_07D3E7E0 | |
Source: | Code function: | 0_2_07D3B47A | |
Source: | Code function: | 0_2_07D32106 | |
Source: | Code function: | 0_2_07D36CE8 | |
Source: | Code function: | 0_2_07D36CD8 | |
Source: | Code function: | 0_2_07D38C00 | |
Source: | Code function: | 0_2_07D32C38 | |
Source: | Code function: | 2_2_02974198 | |
Source: | Code function: | 2_2_0297EA08 | |
Source: | Code function: | 2_2_02974A68 | |
Source: | Code function: | 2_2_02973E50 | |
Source: | Code function: | 2_2_0297AF37 | |
Source: | Code function: | 2_2_0297ADA0 | |
Source: | Code function: | 2_2_0685C76C | |
Source: | Code function: | 2_2_068539B4 | |
Source: | Code function: | 2_2_068562D7 | |
Source: | Code function: | 2_2_068555E3 | |
Source: | Code function: | 2_2_068555E8 | |
Source: | Code function: | 2_2_06867E90 | |
Source: | Code function: | 2_2_068656A8 | |
Source: | Code function: | 2_2_06866700 | |
Source: | Code function: | 2_2_06862758 | |
Source: | Code function: | 2_2_06865E08 | |
Source: | Code function: | 2_2_068677B0 | |
Source: | Code function: | 2_2_0686E4C8 | |
Source: | Code function: | 2_2_06860040 | |
Source: | Code function: | 2_2_0686003E | |
Source: | Code function: | 3_2_018D3E34 | |
Source: | Code function: | 3_2_018DE04C | |
Source: | Code function: | 3_2_018D703B | |
Source: | Code function: | 3_2_077BE7E0 | |
Source: | Code function: | 3_2_077B2106 | |
Source: | Code function: | 3_2_077B6CE8 | |
Source: | Code function: | 3_2_077B2C38 | |
Source: | Code function: | 3_2_077B8C00 | |
Source: | Code function: | 3_2_077B6CD8 | |
Source: | Code function: | 3_2_07C01BC0 | |
Source: | Code function: | 6_2_00E14198 | |
Source: | Code function: | 6_2_00E1E8D8 | |
Source: | Code function: | 6_2_00E14A68 | |
Source: | Code function: | 6_2_00E13E50 | |
Source: | Code function: | 6_2_06567E98 | |
Source: | Code function: | 6_2_065656B0 | |
Source: | Code function: | 6_2_06566708 | |
Source: | Code function: | 6_2_06563580 | |
Source: | Code function: | 6_2_06560040 | |
Source: | Code function: | 6_2_065677B8 | |
Source: | Code function: | 6_2_0656E4D0 | |
Source: | Code function: | 6_2_06565DFF | |
Source: | Code function: | 6_2_06560006 | |
Source: | Code function: | 10_2_00EF3E34 | |
Source: | Code function: | 10_2_00EFE04C | |
Source: | Code function: | 10_2_00EF703B | |
Source: | Code function: | 10_2_06BC21B0 | |
Source: | Code function: | 10_2_06BCAEF8 | |
Source: | Code function: | 10_2_06BCB6B8 | |
Source: | Code function: | 10_2_06BC7289 | |
Source: | Code function: | 10_2_06BC7210 | |
Source: | Code function: | 10_2_06BC23F0 | |
Source: | Code function: | 10_2_06E92338 | |
Source: | Code function: | 10_2_06E91069 | |
Source: | Code function: | 10_2_06E9C680 | |
Source: | Code function: | 10_2_06E95602 | |
Source: | Code function: | 10_2_06E95610 | |
Source: | Code function: | 10_2_06E945F0 | |
Source: | Code function: | 10_2_06E9C248 | |
Source: | Code function: | 10_2_06E9C238 | |
Source: | Code function: | 10_2_06E9E1E9 | |
Source: | Code function: | 10_2_06E9E1F8 | |
Source: | Code function: | 10_2_06E9BE10 | |
Source: | Code function: | 10_2_06E958A8 | |
Source: | Code function: | 10_2_06E95897 | |
Source: | Code function: | 10_2_06E9D920 | |
Source: | Code function: | 10_2_073D1A70 | |
Source: | Code function: | 10_2_073D2D78 | |
Source: | Code function: | 10_2_0745E7E0 | |
Source: | Code function: | 10_2_07452106 | |
Source: | Code function: | 10_2_07456CE8 | |
Source: | Code function: | 10_2_07458C00 | |
Source: | Code function: | 10_2_07456CD8 | |
Source: | Code function: | 11_2_00DCA4B0 | |
Source: | Code function: | 11_2_00DCE8A0 | |
Source: | Code function: | 11_2_00DC4A68 | |
Source: | Code function: | 11_2_00DCAC80 | |
Source: | Code function: | 11_2_00DC3E50 | |
Source: | Code function: | 11_2_00DC4198 | |
Source: | Code function: | 11_2_063EC3FC | |
Source: | Code function: | 11_2_063E52A8 | |
Source: | Code function: | 11_2_063E52A2 | |
Source: | Code function: | 11_2_063E1800 | |
Source: | Code function: | 11_2_06407E98 | |
Source: | Code function: | 11_2_064056B0 | |
Source: | Code function: | 11_2_06406708 | |
Source: | Code function: | 11_2_06403580 | |
Source: | Code function: | 11_2_06400040 | |
Source: | Code function: | 11_2_06405E10 | |
Source: | Code function: | 11_2_064077B8 | |
Source: | Code function: | 11_2_0640E4D0 | |
Source: | Code function: | 11_2_0640001E |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_07843107 | |
Source: | Code function: | 0_2_078428AD | |
Source: | Code function: | 0_2_07D37BFB | |
Source: | Code function: | 2_2_02970C7A | |
Source: | Code function: | 3_2_07C02DC5 | |
Source: | Code function: | 3_2_07C0321F | |
Source: | Code function: | 6_2_00E1F7D1 | |
Source: | Code function: | 10_2_06BC3DC9 | |
Source: | Code function: | 10_2_06BC0890 | |
Source: | Code function: | 10_2_073D28AD | |
Source: | Code function: | 11_2_00DCF7D1 | |
Source: | Code function: | 11_2_00DC6A1B | |
Source: | Code function: | 11_2_0640001C |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | |||
Source: | Window / User API: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: |
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: |
Source: | File opened: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | File opened: | |||
Source: | File opened: | |||
Source: | Key opened: | |||
Source: | Key opened: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 1 File and Directory Discovery | Remote Services | 11 Archive Collected Data | 1 Ingress Tool Transfer | 1 Exfiltration Over Alternative Protocol | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 112 Process Injection | 1 Deobfuscate/Decode Files or Information | 31 Input Capture | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 Registry Run Keys / Startup Folder | 2 Obfuscated Files or Information | 1 Credentials in Registry | 1 Query Registry | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 12 Software Packing | NTDS | 211 Security Software Discovery | Distributed Component Object Model | 31 Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 2 Process Discovery | SSH | 1 Clipboard Data | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 141 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 141 Virtualization/Sandbox Evasion | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 112 Process Injection | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Hidden Files and Directories | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
32% | ReversingLabs | |||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
32% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.ipify.org | 104.26.12.205 | true | false | unknown | |
ftp.haliza.com.my | 110.4.45.197 | true | true | unknown | |
15.164.165.52.in-addr.arpa | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.26.12.205 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false | |
110.4.45.197 | ftp.haliza.com.my | Malaysia | 46015 | EXABYTES-AS-APExaBytesNetworkSdnBhdMY | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1546259 |
Start date and time: | 2024-10-31 17:02:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | rMT103_126021720924.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@13/4@4/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: rMT103_126021720924.exe
Time | Type | Description |
---|---|---|
12:02:59 | API Interceptor | |
12:03:11 | API Interceptor | |
16:03:02 | Autostart | |
16:03:11 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.26.12.205 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
110.4.45.197 | Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse | ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.ipify.org | Get hash | malicious | AgentTesla, GuLoader | Browse |
| |
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
ftp.haliza.com.my | Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| |
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | NetSupport RAT | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, XWorm | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
EXABYTES-AS-APExaBytesNetworkSdnBhdMY | Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| |
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, Stealc, Vidar | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, Stealc, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
|
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\rMT103_126021720924.exe.log
Download File
Process: | C:\Users\user\Desktop\rMT103_126021720924.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\rMT103_126021720924.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 818176 |
Entropy (8bit): | 7.709635714155993 |
Encrypted: | false |
SSDEEP: | 12288:Xn9InteJjOMwfut0+ehcQ7vGruUWvRlthXBTHXLQU8Mr8zLXXIO2/Q4AyrrRPd4:XlI0TIcQ7Gr6DT3LQZsoIO2o4JPd |
MD5: | 06EF3895BF1C5878463C502A7F1554EB |
SHA1: | 9BB43516CA18892A0AACD7E1B0AEC0666FE2C735 |
SHA-256: | C68AC751C2B84E31BD64A9D318FD5CDE9C1FA7F9F9090940808FEF7989B3ADE9 |
SHA-512: | CF3226F8069068E7100738DEB5263793D510B50BD20CE82DF43825A983D360530C0100E45A718C3B9FAB091454C2C8FB7F6F817DDFDE31E8FC63CE54A985BA9E |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rMT103_126021720924.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.709635714155993 |
TrID: |
|
File name: | rMT103_126021720924.exe |
File size: | 818'176 bytes |
MD5: | 06ef3895bf1c5878463c502a7f1554eb |
SHA1: | 9bb43516ca18892a0aacd7e1b0aec0666fe2c735 |
SHA256: | c68ac751c2b84e31bd64a9d318fd5cde9c1fa7f9f9090940808fef7989b3ade9 |
SHA512: | cf3226f8069068e7100738deb5263793d510b50bd20ce82df43825a983d360530c0100e45a718c3b9fab091454c2c8fb7f6f817ddfde31e8fc63ce54a985ba9e |
SSDEEP: | 12288:Xn9InteJjOMwfut0+ehcQ7vGruUWvRlthXBTHXLQU8Mr8zLXXIO2/Q4AyrrRPd4:XlI0TIcQ7Gr6DT3LQZsoIO2o4JPd |
TLSH: | CF05BDD03A76671ADE6A4AB5D168DDB547F62928B001FAE61DCD3BCB349C3109E18F03 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....#g..............0..R...(.......p... ........@.. ....................................@................................ |
Icon Hash: | cd7050787870e4d2 |
Entrypoint: | 0x4c7012 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67238F08 [Thu Oct 31 14:07:04 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
push ebx |
add byte ptr [ecx+00h], bh |
jnc 00007F531C6BFC62h |
je 00007F531C6BFC62h |
add byte ptr [ebp+00h], ch |
add byte ptr [ecx+00h], al |
arpl word ptr [eax], ax |
je 00007F531C6BFC62h |
imul eax, dword ptr [eax], 00610076h |
je 00007F531C6BFC62h |
outsd |
add byte ptr [edx+00h], dh |
inc edx |
add byte ptr [ecx+00h], ah |
jc 00007F531C6BFC62h |
bound eax, dword ptr [eax] |
add byte ptr [edx+00h], dh |
jnc 00007F531C6BFC62h |
push 70006F00h |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xc6fc0 | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc8000 | 0x25a4 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xcc000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xc5050 | 0xc5200 | 40dab49800c8d490fc54e3e62a3dafa1 | False | 0.8492613546290425 | data | 7.713016398013977 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc8000 | 0x25a4 | 0x2600 | dc140597501a7d1afd2d1c89db9c666e | False | 0.8832236842105263 | data | 7.563697310200336 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xcc000 | 0xc | 0x200 | 4770d7c7624d34fc3c378358d722bebe | False | 0.044921875 | data | 0.09800417566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xc80c8 | 0x2185 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9455774385269782 | ||
RT_GROUP_ICON | 0xca260 | 0x14 | data | 1.05 | ||
RT_VERSION | 0xca284 | 0x31c | data | 0.44597989949748745 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T17:03:17.555574+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 172.202.163.200 | 443 | 192.168.2.4 | 49742 | TCP |
2024-10-31T17:03:18.695850+0100 | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 1 | 192.168.2.4 | 49741 | 110.4.45.197 | 21 | TCP |
2024-10-31T17:03:19.796759+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49746 | 110.4.45.197 | 59700 | TCP |
2024-10-31T17:03:20.095892+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49746 | 110.4.45.197 | 59700 | TCP |
2024-10-31T17:03:26.610863+0100 | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 1 | 192.168.2.4 | 49751 | 110.4.45.197 | 21 | TCP |
2024-10-31T17:03:27.637706+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49752 | 110.4.45.197 | 60611 | TCP |
2024-10-31T17:03:27.651556+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49752 | 110.4.45.197 | 60611 | TCP |
2024-10-31T17:03:44.496265+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 172.202.163.200 | 443 | 192.168.2.4 | 63429 | TCP |
2024-10-31T17:03:45.837991+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 172.202.163.200 | 443 | 192.168.2.4 | 63430 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 31, 2024 17:03:01.563787937 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:01.563829899 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:01.563932896 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:01.570525885 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:01.570540905 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:02.181651115 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:02.181735039 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:02.185736895 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:02.185755014 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:02.185969114 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:02.241041899 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:02.241430044 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:02.287334919 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:02.478743076 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:02.478806019 CET | 443 | 49732 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:02.479173899 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:02.484972000 CET | 49732 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:03.289181948 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:03.294203997 CET | 21 | 49734 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:03.294281006 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:03.298964024 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:03.304038048 CET | 21 | 49734 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:03.304086924 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:03.363944054 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:03.369522095 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:03.369580984 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:04.288233042 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:04.288408041 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:04.293308973 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:04.631843090 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:04.631961107 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:04.638286114 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:05.012732029 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:05.012851000 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:05.019371986 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:05.357796907 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:05.358058929 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:05.362967968 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:05.703283072 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:05.703422070 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:05.708416939 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:06.081101894 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:06.131696939 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:06.141598940 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:06.148088932 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:06.486332893 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:06.486830950 CET | 49738 | 52695 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:06.493325949 CET | 52695 | 49738 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:06.493402958 CET | 49738 | 52695 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:06.493453026 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:06.499572992 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:07.451021910 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:07.454772949 CET | 49738 | 52695 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:07.454772949 CET | 49738 | 52695 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:07.459901094 CET | 52695 | 49738 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:07.459918022 CET | 52695 | 49738 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:07.459929943 CET | 52695 | 49738 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:07.460756063 CET | 52695 | 49738 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:07.460810900 CET | 49738 | 52695 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:07.506763935 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:07.795377016 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:07.795977116 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:07.801170111 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:08.142056942 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:08.142481089 CET | 49739 | 49882 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:08.147547960 CET | 49882 | 49739 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:08.147615910 CET | 49739 | 49882 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:08.147679090 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:08.152719021 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:09.053281069 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:09.053463936 CET | 49739 | 49882 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:09.058801889 CET | 49882 | 49739 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:09.059101105 CET | 49882 | 49739 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:09.059151888 CET | 49739 | 49882 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:09.100425959 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:09.630758047 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:09.630774021 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:09.630841970 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:13.541992903 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:13.542074919 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:13.542146921 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:13.545012951 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:13.545032024 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:14.163503885 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:14.163610935 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:14.165512085 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:14.165539026 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:14.165812969 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:14.209925890 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:14.241842031 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:14.283373117 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:14.438739061 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:14.438813925 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:14.439085960 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:14.441760063 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:14.951239109 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:14.956288099 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:14.956415892 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:16.086189985 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:16.086504936 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:16.091492891 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:16.467320919 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:16.479521990 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:16.484489918 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:17.254580021 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:17.254707098 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:17.255176067 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:17.255229950 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:17.260451078 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:17.611933947 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:17.612101078 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:17.616935968 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:17.973476887 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:17.973634958 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:17.978513956 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:18.330504894 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:18.331142902 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:18.336133957 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:18.688329935 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:18.688868999 CET | 49746 | 59700 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:18.694797993 CET | 59700 | 49746 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:18.694884062 CET | 49746 | 59700 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:18.695849895 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:18.700992107 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:19.796546936 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:19.796758890 CET | 49746 | 59700 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:19.796799898 CET | 49746 | 59700 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:19.841425896 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.079937935 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.079988956 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.081404924 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.081445932 CET | 59700 | 49746 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.081450939 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.095777988 CET | 59700 | 49746 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.095891953 CET | 49746 | 59700 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.478665113 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.501667976 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.506556034 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.859992981 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.860850096 CET | 49748 | 55079 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.865762949 CET | 55079 | 49748 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:20.865871906 CET | 49748 | 55079 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.865871906 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:20.870852947 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:21.757776976 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:21.757806063 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:21.757879972 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:21.762408018 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:21.762422085 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:21.792996883 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:21.834847927 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:22.060389996 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:22.060476065 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:22.370229959 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:22.370316982 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:22.374033928 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:22.374046087 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:22.374418974 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:22.423156023 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:22.467323065 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:22.637828112 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:22.638009071 CET | 49748 | 55079 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:22.645109892 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:22.645220041 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Oct 31, 2024 17:03:22.645510912 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:22.649725914 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 31, 2024 17:03:23.127978086 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:23.132934093 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:23.135977983 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:24.058864117 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:24.065326929 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:24.070239067 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:24.406502008 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:24.406656027 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:24.411552906 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:24.772254944 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:24.772437096 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:24.777374029 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:25.116749048 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:25.116878033 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:25.129585981 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:25.484019995 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:25.484165907 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:25.489141941 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.006067991 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.006278992 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:26.225032091 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:26.264818907 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.264869928 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:26.267910004 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.267957926 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:26.268579960 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.268589973 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.604429960 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.605091095 CET | 49752 | 60611 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:26.610747099 CET | 60611 | 49752 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:26.610817909 CET | 49752 | 60611 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:26.610862970 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:26.615808010 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:27.637490988 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:27.637706041 CET | 49752 | 60611 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:27.637773991 CET | 49752 | 60611 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:27.645462036 CET | 60611 | 49752 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:27.651477098 CET | 60611 | 49752 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:27.651556015 CET | 49752 | 60611 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:27.678579092 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:27.988135099 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:28.010612011 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:28.017772913 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:28.352710009 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:28.353094101 CET | 49753 | 58830 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:28.358802080 CET | 58830 | 49753 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:28.358881950 CET | 49753 | 58830 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:28.358917952 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:28.364804983 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.270622969 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.284713030 CET | 49753 | 58830 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.284713030 CET | 49753 | 58830 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.289907932 CET | 58830 | 49753 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.289921045 CET | 58830 | 49753 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.289931059 CET | 58830 | 49753 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.290724039 CET | 58830 | 49753 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.293580055 CET | 49753 | 58830 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.319225073 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.623159885 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.623670101 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.628648043 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.966567039 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.966964960 CET | 49754 | 53913 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.971815109 CET | 53913 | 49754 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:29.971882105 CET | 49754 | 53913 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.971963882 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:29.977011919 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:31.271491051 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:31.271893024 CET | 49754 | 53913 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:31.274662018 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:31.274725914 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:31.584971905 CET | 49754 | 53913 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:31.606643915 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:31.609571934 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:31.612060070 CET | 53913 | 49754 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:31.612104893 CET | 53913 | 49754 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:31.612277031 CET | 49754 | 53913 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:03:31.948292017 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:03:31.991096020 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.740777969 CET | 63696 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.740932941 CET | 63697 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.745610952 CET | 21 | 63696 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:04:57.745834112 CET | 63696 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.745994091 CET | 63696 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.746226072 CET | 21 | 63697 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:04:57.746290922 CET | 63697 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.746550083 CET | 63697 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.751663923 CET | 21 | 63696 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:04:57.751761913 CET | 63696 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:04:57.751780033 CET | 21 | 63697 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:04:57.755799055 CET | 63697 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:21.010380983 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:21.015438080 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:21.015497923 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:21.953092098 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:21.953917027 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:21.960035086 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:22.299539089 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:22.300188065 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:22.305010080 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:22.670706034 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:22.671897888 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:22.676775932 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:23.017580986 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:23.017726898 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:23.022547007 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:23.314280987 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:23.319403887 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:23.319473028 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:23.361634970 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:23.361752987 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:23.366621971 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:23.706084967 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:23.706178904 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:23.711261988 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.049906015 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.050579071 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.055579901 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.055772066 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.055854082 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.060782909 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.235661983 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.236637115 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.241420984 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.581289053 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.581662893 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.586445093 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.945266008 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.950980902 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.953655005 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.956650972 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.959747076 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962361097 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962379932 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962424994 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962430000 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962450981 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.962491989 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.962527990 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962595940 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962599993 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962651014 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.962676048 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962704897 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.962778091 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.964595079 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.964648962 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.967468023 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.967519999 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.967530966 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.967535019 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.967581034 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.967649937 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.968190908 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.968707085 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.968710899 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.968780994 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:24.969976902 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.973608017 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.973997116 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.973999977 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.974004030 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.974586964 CET | 53280 | 63700 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:24.974884987 CET | 63700 | 53280 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:25.163149118 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:25.335859060 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:25.335943937 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:25.336463928 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:25.336582899 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:25.661079884 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:25.752062082 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:25.752103090 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:25.752496004 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:25.752521992 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:25.752568960 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:25.753807068 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:25.753818035 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:25.866264105 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:26.090719938 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:26.092742920 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:26.097687006 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:26.433299065 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:26.433572054 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:26.438576937 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:26.774559021 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:26.776145935 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:26.781024933 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:26.783852100 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:26.783967972 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:26.788804054 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.924293995 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.924505949 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.924916983 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.924961090 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.929449081 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929476976 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929481983 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929486036 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929513931 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.929534912 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929550886 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.929550886 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929588079 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.929615021 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.929697990 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929745913 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.929774046 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929786921 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929796934 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.929817915 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.929838896 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.934446096 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.934473038 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.934497118 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.934511900 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.934528112 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.934561968 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.934571981 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.934587002 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.934596062 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.934607029 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.934637070 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.934680939 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.934731960 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:27.934932947 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.939373016 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.939799070 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.940813065 CET | 53124 | 63701 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:27.940864086 CET | 63701 | 53124 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:28.706113100 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:28.914628983 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:28.914660931 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:28.915977955 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:29.267884016 CET | 63702 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:29.274209976 CET | 21 | 63702 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:29.274270058 CET | 63702 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:29.274451971 CET | 63702 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:29.282040119 CET | 21 | 63702 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:29.282078028 CET | 63702 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:48.176316023 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:48.181292057 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:48.516638994 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:48.517755032 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:48.522792101 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:48.522852898 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:48.522939920 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:48.527849913 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.436495066 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.436769962 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.441752911 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.441781998 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.441862106 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.441867113 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.441879034 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.441981077 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.441988945 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.441994905 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.442002058 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.442023993 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.442142010 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.442198038 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.442316055 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.446940899 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.446948051 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.447009087 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.447014093 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.447067976 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.447084904 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.447125912 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.447269917 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.447592020 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.450428009 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.452399015 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.452625036 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.455904007 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.457123041 CET | 57283 | 63703 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:49.461798906 CET | 63703 | 57283 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:49.603722095 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:50.186172962 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:05:50.328589916 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:59.932018995 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:05:59.937102079 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:00.461879015 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:00.462409973 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:00.467293978 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:00.467353106 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:00.467493057 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:00.472287893 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.384572029 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.443790913 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.449037075 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449125051 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449130058 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449135065 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449171066 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449204922 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449235916 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.449253082 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449258089 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449299097 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.449326992 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449331999 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.449392080 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.449686050 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.454700947 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.454786062 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.454790115 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.454832077 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.454916000 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.455190897 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.455250978 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.456139088 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.459522963 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.459527969 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.459532022 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.459536076 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.459539890 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.459543943 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.459548950 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.459810019 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.459974051 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.460417986 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.464859962 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.464957952 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.465120077 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.467387915 CET | 62800 | 63704 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:01.468163013 CET | 63704 | 62800 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:01.603991985 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:02.223412037 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:02.267693996 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:04.858093023 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:04.863842010 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.200692892 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.201185942 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.206141949 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.206321955 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.206432104 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.211318016 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.464340925 CET | 63706 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.469815969 CET | 21 | 63706 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.469928980 CET | 63706 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.470101118 CET | 63706 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.475627899 CET | 21 | 63706 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.475765944 CET | 63706 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.557142019 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.562217951 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.909197092 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.909693003 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.914777040 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:05.914872885 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.914978981 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:05.920142889 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.119796038 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.119991064 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.125618935 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.125636101 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.125664949 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.125679016 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.125680923 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.125685930 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.125719070 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.125732899 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.125735998 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.125746012 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.125760078 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.125777960 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.125788927 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.125801086 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.126310110 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.126353025 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.126414061 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.126436949 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.126458883 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.126482010 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.130572081 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130615950 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.130754948 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130768061 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130774021 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130798101 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.130800962 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130820036 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.130835056 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.130862951 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.130904913 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130918980 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130930901 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.130945921 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.130971909 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.131021023 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.131278992 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.131422997 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.131553888 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.135535002 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.135651112 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.135763884 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.135828972 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.136075020 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.138042927 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.138057947 CET | 50153 | 63705 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.138103962 CET | 63705 | 50153 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.188925982 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.854430914 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.863411903 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868483067 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868498087 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868510962 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868535042 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868547916 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868566990 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868571997 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868597031 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868613005 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868619919 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868627071 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868657112 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868660927 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868673086 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868674994 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868689060 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.868705988 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868719101 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.868742943 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.873430014 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.873478889 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.873545885 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.873588085 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.873615980 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.873634100 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.873648882 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.873661995 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.873668909 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.873681068 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.873708963 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.873945951 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.874002934 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.874428988 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.874680996 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.878381968 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.878555059 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.878648996 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.878736973 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.878884077 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.878981113 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.880441904 CET | 49704 | 63707 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.880522013 CET | 63707 | 49704 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:06.896873951 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:06.960082054 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:07.006954908 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:07.276645899 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:07.283081055 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:07.618874073 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:07.619357109 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:07.710155010 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:07.888056040 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:07.888298988 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:07.888305902 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:07.888360023 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:07.893486977 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:07.918616056 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:07.918728113 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.803329945 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.803518057 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808476925 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808506966 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808525085 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808528900 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808546066 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808547974 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808561087 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808574915 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808574915 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808585882 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808621883 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808792114 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808842897 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808855057 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808867931 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.808908939 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.808938026 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.809016943 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.813585997 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813600063 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813612938 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813626051 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813631058 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.813643932 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813649893 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.813659906 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.813663006 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813688993 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813690901 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.813704967 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.813714981 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.813739061 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.813813925 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.818181992 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.818623066 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.818747044 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.818923950 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.819710016 CET | 64321 | 63708 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:08.819758892 CET | 63708 | 64321 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:08.861494064 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:09.591100931 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:09.710113049 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.011640072 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.016798973 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:14.017817974 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.500375032 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.505249977 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:14.846425056 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:14.846892118 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.852890015 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:14.852946043 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.853027105 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.858540058 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:14.935453892 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:14.935595036 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:14.941385984 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.283582926 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.283921003 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.288769960 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.652872086 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.653072119 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.657926083 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.773735046 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.774264097 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.779200077 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779232025 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779237986 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779251099 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779280901 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779392958 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779407024 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779434919 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779441118 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779443026 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.779447079 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.779501915 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.784321070 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784348011 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784354925 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784410000 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784529924 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784537077 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784550905 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.784648895 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784749031 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784755945 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784794092 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784801960 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.784810066 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.789493084 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.789733887 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.789783001 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.789902925 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.789942980 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.790366888 CET | 52009 | 63710 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.794002056 CET | 63710 | 52009 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.869716883 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.994519949 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:15.994956970 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:15.999799013 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:16.337506056 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:16.337655067 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:16.342538118 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:16.563080072 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:16.663216114 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:16.680018902 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:16.680120945 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:16.685125113 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:17.147088051 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:17.157756090 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:17.164956093 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:17.165848017 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:17.165854931 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:17.170754910 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:17.995249987 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.000114918 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.077034950 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.077317953 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.082262993 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082268000 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082370996 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.082423925 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082427979 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082457066 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082461119 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082514048 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.082591057 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082647085 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082650900 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082653999 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.082669020 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.082715034 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.087246895 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087265015 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087306023 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.087390900 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087395906 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087399006 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087424994 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087450981 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.087472916 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.087515116 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087544918 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087610960 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.087635994 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087640047 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087666988 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.087872028 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.088232040 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.093213081 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.093861103 CET | 49938 | 63711 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.093904018 CET | 63711 | 49938 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.179188013 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.339585066 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.340130091 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.345190048 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.345273972 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.345312119 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:18.350241899 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:18.859827042 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.006967068 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.285250902 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.285928965 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.290940046 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.290957928 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.290963888 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291003942 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291065931 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.291074991 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291081905 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291090012 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291142941 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291148901 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.291150093 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291182995 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.291296959 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.295943022 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.295969963 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296013117 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296046019 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296082020 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296087980 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296093941 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296132088 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.296190023 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.296477079 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296574116 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296600103 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296680927 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.296757936 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.296763897 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.302932024 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.305125952 CET | 49662 | 63712 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:19.305284977 CET | 63712 | 49662 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:19.353780031 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:20.088002920 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:20.164963007 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:26.736078978 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:26.741019011 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:27.080883026 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:27.081568003 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:27.087169886 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:27.089860916 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:27.089862108 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:27.094945908 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:27.996221066 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:27.997991085 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.002995014 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003043890 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003047943 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003070116 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003108978 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.003154039 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003186941 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003190994 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003217936 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003221035 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003287077 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.003307104 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.003612995 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.003750086 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.008024931 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008074045 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008078098 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008089066 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008094072 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008097887 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008105040 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.008167028 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008184910 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008196115 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.008264065 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.008454084 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008488894 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.008666039 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.008960962 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.013056040 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.013159037 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.013164997 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.013168097 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.013202906 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.013278961 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.013550997 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.014053106 CET | 50113 | 63713 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.014229059 CET | 63713 | 50113 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.098664045 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:28.778490067 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:28.822398901 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:40.485181093 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:40.490147114 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:40.828809023 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:40.829312086 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:40.834201097 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:40.834263086 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:40.834332943 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:40.839220047 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.783317089 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.783586979 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.788728952 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.788840055 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.788876057 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.788877964 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.788966894 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.788970947 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.788973093 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.789002895 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.789028883 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.789135933 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.789139986 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.789156914 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.789165974 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.789222956 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.789222956 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.789397955 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.793919086 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.793993950 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794008017 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794034958 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794159889 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794163942 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794209957 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.794261932 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794334888 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.794349909 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.794493914 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794497967 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794507980 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794559956 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794564009 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.794658899 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.799464941 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.799607038 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.799638987 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.799819946 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.800383091 CET | 56246 | 63714 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:41.800976992 CET | 63714 | 56246 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:41.866432905 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:42.596257925 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:42.663290024 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:46.828071117 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:46.832971096 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:47.171870947 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:47.174325943 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:47.179197073 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:47.181862116 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:47.182044029 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:47.187273979 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.181260109 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.181453943 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.190447092 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190505028 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.190545082 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190556049 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190579891 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190599918 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.190620899 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.190716982 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190757990 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.190774918 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190784931 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190795898 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190815926 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.190849066 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.190903902 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190922022 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.190967083 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.195583105 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.195591927 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.195666075 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.195673943 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.195688963 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.195708990 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.195723057 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.195740938 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.195775032 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.207775116 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.207823992 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.212826967 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.212836981 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.213098049 CET | 62872 | 63715 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.213162899 CET | 63715 | 62872 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.350817919 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.354692936 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:48.354737997 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:48.947211027 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:49.053946972 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:50.578996897 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:50.584033012 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:50.923458099 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:50.923835993 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:50.928910017 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:50.929088116 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:50.929219961 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:50.934441090 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.842674971 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.844037056 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:51.849030018 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849035978 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849067926 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849078894 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849148035 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849153042 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849158049 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849199057 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849212885 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:51.849240065 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:51.849241972 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849247932 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.849379063 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:51.854147911 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854227066 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854245901 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854249954 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854281902 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854285955 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854345083 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:51.854373932 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:51.854660988 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854871988 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.854995966 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:51.859555006 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.859673023 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.859925985 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.860054970 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.860726118 CET | 54434 | 63716 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:51.860953093 CET | 63716 | 54434 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:52.056823015 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:52.636862993 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:52.850837946 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:58.592609882 CET | 63717 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:58.837789059 CET | 21 | 63717 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:58.837853909 CET | 63717 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:58.838136911 CET | 63717 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:06:58.844438076 CET | 21 | 63717 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:06:58.844485044 CET | 63717 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:10.308928967 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:10.314069033 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:10.323750973 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:10.328783989 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:10.328857899 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:10.654289961 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:10.654613972 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:10.659612894 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:10.659687996 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:10.659734964 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:10.664621115 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.259382010 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.259516954 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.264427900 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.581873894 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.584038019 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.589056015 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589062929 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589067936 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589080095 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589090109 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589126110 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.589149952 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589154959 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589188099 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589209080 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.589330912 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589339018 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.589361906 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.589560032 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.594043970 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594098091 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594104052 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594125986 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594131947 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594139099 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594144106 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594165087 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.594197989 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594206095 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.594230890 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594237089 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594290972 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.594366074 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.594506979 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.599159002 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.599245071 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.599261045 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.599339962 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.599385023 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.599390984 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.599405050 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.600326061 CET | 61776 | 63719 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.600579977 CET | 63719 | 61776 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.605000019 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.607976913 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.612986088 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.633865118 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.969383001 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:11.969516039 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:11.974329948 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:12.318413019 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:12.318557024 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:12.323689938 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:12.364481926 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:12.413419008 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:12.664740086 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:12.664998055 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:12.669954062 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:13.011112928 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:13.011244059 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:13.016138077 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:13.357491016 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:13.357772112 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:13.362725019 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:13.362835884 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:13.362838984 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:13.367765903 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.305254936 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.306050062 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.311084986 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311134100 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311147928 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311175108 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311187983 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311218977 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.311268091 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311280966 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311285973 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.311338902 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311355114 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311368942 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.311412096 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.311430931 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.311583996 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.316701889 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.316716909 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.316728115 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.316740990 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.316778898 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.316792011 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.316792965 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.316869020 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.317116022 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.317950010 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.321749926 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.321916103 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.322874069 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.322946072 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.323039055 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.323141098 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.323721886 CET | 50990 | 63720 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:14.324059963 CET | 63720 | 50990 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:14.353458881 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Oct 31, 2024 17:07:15.123862028 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 |
Oct 31, 2024 17:07:15.179053068 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 31, 2024 17:03:01.551584005 CET | 53769 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 31, 2024 17:03:01.558679104 CET | 53 | 53769 | 1.1.1.1 | 192.168.2.4 |
Oct 31, 2024 17:03:03.027523994 CET | 51592 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 31, 2024 17:03:03.287842035 CET | 53 | 51592 | 1.1.1.1 | 192.168.2.4 |
Oct 31, 2024 17:03:31.826960087 CET | 53 | 57516 | 162.159.36.2 | 192.168.2.4 |
Oct 31, 2024 17:03:32.449031115 CET | 55142 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 31, 2024 17:03:32.460637093 CET | 53 | 55142 | 1.1.1.1 | 192.168.2.4 |
Oct 31, 2024 17:04:57.484378099 CET | 55579 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 31, 2024 17:04:57.740012884 CET | 53 | 55579 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 31, 2024 17:03:01.551584005 CET | 192.168.2.4 | 1.1.1.1 | 0xbb2a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 31, 2024 17:03:03.027523994 CET | 192.168.2.4 | 1.1.1.1 | 0x4d82 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 31, 2024 17:03:32.449031115 CET | 192.168.2.4 | 1.1.1.1 | 0x6e5 | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Oct 31, 2024 17:04:57.484378099 CET | 192.168.2.4 | 1.1.1.1 | 0xcbdc | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 31, 2024 17:03:01.558679104 CET | 1.1.1.1 | 192.168.2.4 | 0xbb2a | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Oct 31, 2024 17:03:01.558679104 CET | 1.1.1.1 | 192.168.2.4 | 0xbb2a | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Oct 31, 2024 17:03:01.558679104 CET | 1.1.1.1 | 192.168.2.4 | 0xbb2a | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Oct 31, 2024 17:03:03.287842035 CET | 1.1.1.1 | 192.168.2.4 | 0x4d82 | No error (0) | 110.4.45.197 | A (IP address) | IN (0x0001) | false | ||
Oct 31, 2024 17:03:32.460637093 CET | 1.1.1.1 | 192.168.2.4 | 0x6e5 | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false | |
Oct 31, 2024 17:04:57.740012884 CET | 1.1.1.1 | 192.168.2.4 | 0xcbdc | No error (0) | 110.4.45.197 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49732 | 104.26.12.205 | 443 | 6860 | C:\Users\user\Desktop\rMT103_126021720924.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-31 16:03:02 UTC | 155 | OUT | |
2024-10-31 16:03:02 UTC | 211 | IN | |
2024-10-31 16:03:02 UTC | 14 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49740 | 104.26.12.205 | 443 | 7320 | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-31 16:03:14 UTC | 155 | OUT | |
2024-10-31 16:03:14 UTC | 211 | IN | |
2024-10-31 16:03:14 UTC | 14 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49750 | 104.26.12.205 | 443 | 7704 | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-31 16:03:22 UTC | 155 | OUT | |
2024-10-31 16:03:22 UTC | 211 | IN | |
2024-10-31 16:03:22 UTC | 14 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Oct 31, 2024 17:03:04.288233042 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 22 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 22 of 50 allowed.220-Local time is now 00:03. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 22 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 22 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 22 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Oct 31, 2024 17:03:04.288408041 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Oct 31, 2024 17:03:04.631843090 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Oct 31, 2024 17:03:04.631961107 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Oct 31, 2024 17:03:05.012732029 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:03:05.357796907 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:03:05.358058929 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:03:05.703283072 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Oct 31, 2024 17:03:05.703422070 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Oct 31, 2024 17:03:06.081101894 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:03:06.141598940 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:06.486332893 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,205,215) |
Oct 31, 2024 17:03:06.493453026 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-494126_2024_10_31_12_23_02.txt |
Oct 31, 2024 17:03:07.451021910 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:07.795377016 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.370 seconds (measured here), 8.85 Kbytes per second |
Oct 31, 2024 17:03:07.795977116 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:08.142056942 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,194,218) |
Oct 31, 2024 17:03:08.147679090 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Firefox_fqs92o4p.default-release.txt_user-494126_2024_10_31_18_31_30.txt |
Oct 31, 2024 17:03:09.053281069 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:09.630758047 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Oct 31, 2024 17:03:09.630774021 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Oct 31, 2024 17:03:16.086189985 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 20 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 20 of 50 allowed.220-Local time is now 00:03. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 20 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 20 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 20 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Oct 31, 2024 17:03:16.086504936 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Oct 31, 2024 17:03:16.467320919 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Oct 31, 2024 17:03:16.479521990 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Oct 31, 2024 17:03:17.254580021 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:03:17.255176067 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:03:17.611933947 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:03:17.612101078 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:03:17.973476887 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Oct 31, 2024 17:03:17.973634958 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Oct 31, 2024 17:03:18.330504894 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:03:18.331142902 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:18.688329935 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,233,52) |
Oct 31, 2024 17:03:18.695849895 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | STOR PW_user-494126_2024_10_31_12_03_14.html |
Oct 31, 2024 17:03:19.796546936 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:20.079937935 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:20.081404924 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:20.478665113 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.825 seconds (measured here), 423.21 bytes per second |
Oct 31, 2024 17:03:20.501667976 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:20.859992981 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,215,39) |
Oct 31, 2024 17:03:20.865871906 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-494126_2024_10_31_19_41_17.txt |
Oct 31, 2024 17:03:21.792996883 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:22.060389996 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:24.058864117 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 17 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 17 of 50 allowed.220-Local time is now 00:03. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 17 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 17 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 17 of 50 allowed.220-Local time is now 00:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Oct 31, 2024 17:03:24.065326929 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Oct 31, 2024 17:03:24.406502008 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Oct 31, 2024 17:03:24.406656027 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Oct 31, 2024 17:03:24.772254944 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:03:25.116749048 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:03:25.116878033 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:03:25.484019995 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Oct 31, 2024 17:03:25.484165907 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Oct 31, 2024 17:03:26.006067991 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:03:26.006278992 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:26.225032091 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:26.264818907 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:03:26.267910004 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:03:26.604429960 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,236,195) |
Oct 31, 2024 17:03:26.610862970 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR PW_user-494126_2024_10_31_12_03_22.html |
Oct 31, 2024 17:03:27.637490988 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:27.988135099 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.469 seconds (measured here), 0.73 Kbytes per second |
Oct 31, 2024 17:03:28.010612011 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:28.352710009 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,229,206) |
Oct 31, 2024 17:03:28.358917952 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-494126_2024_10_31_18_51_47.txt |
Oct 31, 2024 17:03:29.270622969 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:29.623159885 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.352 seconds (measured here), 9.31 Kbytes per second |
Oct 31, 2024 17:03:29.623670101 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:03:29.966567039 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,210,153) |
Oct 31, 2024 17:03:29.971963882 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Firefox_fqs92o4p.default-release.txt_user-494126_2024_10_31_21_00_35.txt |
Oct 31, 2024 17:03:31.271491051 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:31.274662018 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:31.606643915 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:03:31.948292017 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Oct 31, 2024 17:05:21.953092098 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 28 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 28 of 50 allowed.220-Local time is now 00:05. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 28 of 50 allowed.220-Local time is now 00:05. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 28 of 50 allowed.220-Local time is now 00:05. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 28 of 50 allowed.220-Local time is now 00:05. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Oct 31, 2024 17:05:21.953917027 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Oct 31, 2024 17:05:22.299539089 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Oct 31, 2024 17:05:22.300188065 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Oct 31, 2024 17:05:22.670706034 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:05:23.017580986 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:05:23.017726898 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:05:23.361634970 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Oct 31, 2024 17:05:23.361752987 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Oct 31, 2024 17:05:23.706084967 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:05:23.706178904 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:05:24.049906015 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,208,32) |
Oct 31, 2024 17:05:24.055854082 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_11_28_12_11_27.jpeg |
Oct 31, 2024 17:05:24.235661983 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 29 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 29 of 50 allowed.220-Local time is now 00:05. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 29 of 50 allowed.220-Local time is now 00:05. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 29 of 50 allowed.220-Local time is now 00:05. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 29 of 50 allowed.220-Local time is now 00:05. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Oct 31, 2024 17:05:24.236637115 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Oct 31, 2024 17:05:24.581289053 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Oct 31, 2024 17:05:24.581662893 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Oct 31, 2024 17:05:24.945266008 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:05:24.950980902 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:05:25.335859060 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:05:25.336463928 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:05:25.336582899 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:05:25.661079884 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:05:25.752062082 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:05:25.752496004 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.753 seconds (measured here), 73.87 Kbytes per second |
Oct 31, 2024 17:05:25.752521992 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:05:26.090719938 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Oct 31, 2024 17:05:26.092742920 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Oct 31, 2024 17:05:26.433299065 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:05:26.433572054 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:05:26.774559021 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,207,132) |
Oct 31, 2024 17:05:26.783967972 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_12_01_14_22_41.jpeg |
Oct 31, 2024 17:05:27.924293995 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:05:27.924916983 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:05:28.706113100 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 1.002 seconds (measured here), 55.54 Kbytes per second |
Oct 31, 2024 17:05:28.914628983 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 1.002 seconds (measured here), 55.54 Kbytes per second |
Oct 31, 2024 17:05:48.176316023 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:05:48.516638994 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,223,195) |
Oct 31, 2024 17:05:48.522939920 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_12_14_16_26_31.jpeg |
Oct 31, 2024 17:05:49.436495066 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:05:50.186172962 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.749 seconds (measured here), 74.25 Kbytes per second |
Oct 31, 2024 17:05:59.932018995 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:00.461879015 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,245,80) |
Oct 31, 2024 17:06:00.467493057 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_12_21_20_32_59.jpeg |
Oct 31, 2024 17:06:01.384572029 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:02.223412037 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.839 seconds (measured here), 66.31 Kbytes per second |
Oct 31, 2024 17:06:04.858093023 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:05.200692892 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,195,233) |
Oct 31, 2024 17:06:05.206432104 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_12_26_02_07_59.jpeg |
Oct 31, 2024 17:06:05.557142019 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:05.909197092 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,194,40) |
Oct 31, 2024 17:06:05.914978981 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_12_28_13_12_01.jpeg |
Oct 31, 2024 17:06:06.119796038 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:06.854430914 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:06.896873951 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.777 seconds (measured here), 71.65 Kbytes per second |
Oct 31, 2024 17:06:07.276645899 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:07.618874073 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,251,65) |
Oct 31, 2024 17:06:07.888298988 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.828 seconds (measured here), 67.24 Kbytes per second |
Oct 31, 2024 17:06:07.888360023 CET | 63699 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_12_31_08_18_23.jpeg |
Oct 31, 2024 17:06:07.918616056 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.828 seconds (measured here), 67.24 Kbytes per second |
Oct 31, 2024 17:06:08.803329945 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:09.591100931 CET | 21 | 63699 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.788 seconds (measured here), 70.58 Kbytes per second |
Oct 31, 2024 17:06:14.500375032 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:14.846425056 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,203,41) |
Oct 31, 2024 17:06:14.853027105 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2025_01_05_17_00_19.jpeg |
Oct 31, 2024 17:06:14.935453892 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 38 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 38 of 50 allowed.220-Local time is now 00:06. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 38 of 50 allowed.220-Local time is now 00:06. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 38 of 50 allowed.220-Local time is now 00:06. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 38 of 50 allowed.220-Local time is now 00:06. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Oct 31, 2024 17:06:14.935595036 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Oct 31, 2024 17:06:15.283582926 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Oct 31, 2024 17:06:15.283921003 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Oct 31, 2024 17:06:15.652872086 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:06:15.773735046 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:15.994519949 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:06:15.994956970 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:06:16.337506056 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Oct 31, 2024 17:06:16.337655067 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Oct 31, 2024 17:06:16.563080072 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.788 seconds (measured here), 70.61 Kbytes per second |
Oct 31, 2024 17:06:16.680018902 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:06:16.680120945 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:17.147088051 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,195,18) |
Oct 31, 2024 17:06:17.165848017 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2025_01_12_10_54_19.jpeg |
Oct 31, 2024 17:06:17.995249987 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:18.077034950 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:18.339585066 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,193,254) |
Oct 31, 2024 17:06:18.345312119 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2025_01_09_10_10_02.jpeg |
Oct 31, 2024 17:06:18.859827042 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.786 seconds (measured here), 76.27 Kbytes per second |
Oct 31, 2024 17:06:19.285250902 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:20.088002920 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.803 seconds (measured here), 69.31 Kbytes per second |
Oct 31, 2024 17:06:26.736078978 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:27.080883026 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,195,193) |
Oct 31, 2024 17:06:27.089862108 CET | 63709 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2025_01_20_03_44_03.jpeg |
Oct 31, 2024 17:06:27.996221066 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:28.778490067 CET | 21 | 63709 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.783 seconds (measured here), 71.08 Kbytes per second |
Oct 31, 2024 17:06:40.485181093 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:40.828809023 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,219,182) |
Oct 31, 2024 17:06:40.834332943 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2025_01_21_00_30_37.jpeg |
Oct 31, 2024 17:06:41.783317089 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:42.596257925 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.813 seconds (measured here), 68.44 Kbytes per second |
Oct 31, 2024 17:06:46.828071117 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:47.171870947 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,245,152) |
Oct 31, 2024 17:06:47.182044029 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2025_01_25_21_36_43.jpeg |
Oct 31, 2024 17:06:48.181260109 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:48.354692936 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:48.947211027 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.848 seconds (measured here), 65.60 Kbytes per second |
Oct 31, 2024 17:06:50.578996897 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:06:50.923458099 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,212,162) |
Oct 31, 2024 17:06:50.929219961 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2025_01_29_20_27_16.jpeg |
Oct 31, 2024 17:06:51.842674971 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:06:52.636862993 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.775 seconds (measured here), 71.84 Kbytes per second |
Oct 31, 2024 17:07:10.308928967 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:07:10.654289961 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,241,80) |
Oct 31, 2024 17:07:10.659734964 CET | 63698 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_10_31_12_07_09.jpeg |
Oct 31, 2024 17:07:11.259382010 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 41 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 41 of 50 allowed.220-Local time is now 00:07. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 41 of 50 allowed.220-Local time is now 00:07. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 41 of 50 allowed.220-Local time is now 00:07. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 41 of 50 allowed.220-Local time is now 00:07. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Oct 31, 2024 17:07:11.259516954 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Oct 31, 2024 17:07:11.581873894 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:07:11.605000019 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Oct 31, 2024 17:07:11.607976913 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Oct 31, 2024 17:07:11.969383001 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Oct 31, 2024 17:07:12.318413019 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Oct 31, 2024 17:07:12.318557024 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Oct 31, 2024 17:07:12.364481926 CET | 21 | 63698 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.782 seconds (measured here), 75.04 Kbytes per second |
Oct 31, 2024 17:07:12.664740086 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Oct 31, 2024 17:07:12.664998055 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Oct 31, 2024 17:07:13.011112928 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Oct 31, 2024 17:07:13.011244059 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Oct 31, 2024 17:07:13.357491016 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,199,46) |
Oct 31, 2024 17:07:13.362838984 CET | 63718 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-494126_2024_10_31_12_07_09.jpeg |
Oct 31, 2024 17:07:14.305254936 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Oct 31, 2024 17:07:15.123862028 CET | 21 | 63718 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.818 seconds (measured here), 71.75 Kbytes per second |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:02:58 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\Desktop\rMT103_126021720924.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x890000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 12:03:00 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\Desktop\rMT103_126021720924.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x7e0000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 12:03:11 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfd0000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 12:03:12 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x180000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 12:03:12 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x10000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 12:03:12 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x600000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 10 |
Start time: | 12:03:19 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x470000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 11 |
Start time: | 12:03:20 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x4a0000 |
File size: | 818'176 bytes |
MD5 hash: | 06EF3895BF1C5878463C502A7F1554EB |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 6.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 1.3% |
Total number of Nodes: | 234 |
Total number of Limit Nodes: | 13 |
Graph
Function 07D3E7E0 Relevance: 11.0, Strings: 8, Instructions: 970COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3B47A Relevance: 1.8, Strings: 1, Instructions: 592COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D32106 Relevance: 1.8, Strings: 1, Instructions: 562COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D36CE8 Relevance: .7, Instructions: 668COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D36CD8 Relevance: .3, Instructions: 291COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01397000 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139703A Relevance: .2, Instructions: 190COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01393E34 Relevance: .2, Instructions: 187COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139D530 Relevance: 6.1, APIs: 4, Instructions: 135threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139D540 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3D570 Relevance: 2.8, Strings: 2, Instructions: 299COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139B298 Relevance: 1.7, APIs: 1, Instructions: 200COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01394508 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139592D Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE628 Relevance: 1.6, APIs: 1, Instructions: 68threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE8B1 Relevance: 1.6, APIs: 1, Instructions: 67COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139D780 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE630 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE8B8 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139D788 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE700 Relevance: 1.6, APIs: 1, Instructions: 56memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE142 Relevance: 1.6, APIs: 1, Instructions: 55threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE708 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE148 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139B498 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07842488 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07842490 Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3E7B0 Relevance: 1.4, Strings: 1, Instructions: 150COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3E9AC Relevance: 1.4, Strings: 1, Instructions: 101COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D354D8 Relevance: 1.3, Strings: 1, Instructions: 37COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D354E8 Relevance: 1.3, Strings: 1, Instructions: 32COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3892C Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D33528 Relevance: .2, Instructions: 167COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D33518 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3C140 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D35DE8 Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3C130 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D38A70 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D38A80 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3CCE0 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3FD38 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3FD48 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D37ED8 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3D2C0 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D36589 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D34528 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D37EC8 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3CFC0 Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3DBB8 Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3D875 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D34ED1 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0100D3D8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3CD24 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3D460 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3DBA7 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0101D1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0101D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D37DA4 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3D218 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3DA2A Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0100D3D3 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0101D017 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0101D1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3D208 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D34100 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0100D745 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D34110 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D35DD7 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D37DB0 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0100D744 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3DB40 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3DB32 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D356C9 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D35DC1 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3503A Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D356D8 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D37E70 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D37E80 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D35680 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D34C6C Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3A37F Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D33C30 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D34C7C Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D34FFE Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D33C40 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D342E0 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3A3B2 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D3A3B8 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D342F0 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D32C38 Relevance: 8.0, Strings: 6, Instructions: 501COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07841A70 Relevance: 3.1, Strings: 2, Instructions: 556COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A2348 Relevance: .5, Instructions: 506COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A1078 Relevance: .5, Instructions: 482COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07D38C00 Relevance: .3, Instructions: 318COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AC680 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A4600 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE1F8 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AC248 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058ABE10 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AD920 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0139E04C Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A58A8 Relevance: .2, Instructions: 169COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A2338 Relevance: .2, Instructions: 150COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A5897 Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A5610 Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AC238 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058AE1E9 Relevance: .1, Instructions: 136COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A1069 Relevance: .1, Instructions: 105COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058A5603 Relevance: .1, Instructions: 99COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 13.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 1.4% |
Total number of Nodes: | 222 |
Total number of Limit Nodes: | 28 |
Graph
Function 06862758 Relevance: 9.0, Strings: 6, Instructions: 1529COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06867E90 Relevance: 3.0, Strings: 2, Instructions: 471COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068656A8 Relevance: 1.8, Strings: 1, Instructions: 587COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685C628 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06866700 Relevance: .8, Instructions: 812COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686ADE0 Relevance: 10.4, Strings: 8, Instructions: 389COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06869260 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686D068 Relevance: 4.5, Strings: 3, Instructions: 798COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06864C78 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06869252 Relevance: 2.7, Strings: 2, Instructions: 167COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06864C69 Relevance: 2.6, Strings: 2, Instructions: 137COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0297EEA0 Relevance: 1.6, APIs: 1, Instructions: 130COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06855FD3 Relevance: 1.6, APIs: 1, Instructions: 117COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06855FD8 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06859AB4 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685D6A9 Relevance: 1.6, APIs: 1, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06859ED8 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06859ED0 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02978038 Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685D5E8 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B098 Relevance: 1.6, APIs: 1, Instructions: 58COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02978040 Relevance: 1.6, APIs: 1, Instructions: 56fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0297EF70 Relevance: 1.6, APIs: 1, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853864 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854F2B Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B961 Relevance: 1.5, APIs: 1, Instructions: 48comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B3B4 Relevance: 1.5, APIs: 1, Instructions: 47comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B3B8 Relevance: 1.5, APIs: 1, Instructions: 46comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06859B0C Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686DBDD Relevance: 1.4, Strings: 1, Instructions: 118COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686DBF0 Relevance: 1.4, Strings: 1, Instructions: 117COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068621BD Relevance: 1.4, Strings: 1, Instructions: 108COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068621D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068683E0 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06864B61 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686C2A8 Relevance: .6, Instructions: 632COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686B3DF Relevance: .6, Instructions: 556COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06866300 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068643B2 Relevance: .2, Instructions: 221COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068643C0 Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068646CC Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068646E0 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686F031 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686F040 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686FA70 Relevance: .2, Instructions: 172COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686FCD0 Relevance: .2, Instructions: 171COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686FA80 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06865530 Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686DA90 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06862081 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06862090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686A418 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06863FC8 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06863FB9 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D1F8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D3A8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D006 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D118 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068640D8 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686F2B0 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06864310 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D1F3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D3A3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06863D92 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06863578 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0292D113 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06863D98 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06864320 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686F2C0 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068640C9 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686A428 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686FCC1 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686C900 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06866580 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06866590 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068677B0 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686AA48 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068671B0 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686BB28 Relevance: 7.7, Strings: 6, Instructions: 197COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068684E8 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0686ADD0 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06868900 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 7.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 38 |
Total number of Limit Nodes: | 3 |
Graph
Function 077BE7E0 Relevance: 11.0, Strings: 8, Instructions: 971COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B2106 Relevance: 1.8, Strings: 1, Instructions: 561COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B6CE8 Relevance: .7, Instructions: 668COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B6CD8 Relevance: .3, Instructions: 291COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BD570 Relevance: 2.8, Strings: 2, Instructions: 299COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018DB298 Relevance: 1.7, APIs: 1, Instructions: 199COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018D5AA4 Relevance: 1.6, APIs: 1, Instructions: 107COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018D4508 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018D592D Relevance: 1.6, APIs: 1, Instructions: 95COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018DD2B8 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018DD780 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07C02991 Relevance: 1.6, APIs: 1, Instructions: 50windowCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07C014A4 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018DB498 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BE7D0 Relevance: 1.4, Strings: 1, Instructions: 139COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BE9AC Relevance: 1.4, Strings: 1, Instructions: 101COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B54D8 Relevance: 1.3, Strings: 1, Instructions: 37COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B54E8 Relevance: 1.3, Strings: 1, Instructions: 32COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BB62B Relevance: .4, Instructions: 410COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B3528 Relevance: .2, Instructions: 167COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B3518 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BC140 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B5DE8 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BC130 Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B8A70 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B8A80 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BCCE0 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BFD38 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BFD48 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B7ED8 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BD2C0 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B6589 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B4528 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B7EC8 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BCFC0 Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BDBB8 Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BD875 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B4ED1 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0169D4C4 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0169D3D8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BCD24 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0188D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0188D1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BD460 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BDBA7 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B7DA4 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BB4E0 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BD218 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BDA2B Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0169D4BF Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0169D3D3 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0188D1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0188D017 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BD208 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B4100 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0169D745 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B4110 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B5DD7 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B7DB0 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0169D744 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BDB40 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BDB33 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B56C9 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B5DC3 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B503A Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B56D8 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B7E70 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B7E80 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BA3A7 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B5680 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B4C6C Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B3C30 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B4C7C Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B4FFE Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B3C40 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077BA3B8 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B42EB Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077B42F0 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 14.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 25 |
Total number of Limit Nodes: | 6 |
Graph
Function 06563580 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06567E98 Relevance: 3.0, Strings: 2, Instructions: 478COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06560006 Relevance: 2.0, Instructions: 1981COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06560040 Relevance: 2.0, Instructions: 1965COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065656B0 Relevance: 1.8, Strings: 1, Instructions: 599COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06566708 Relevance: .8, Instructions: 824COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656ADE8 Relevance: 10.4, Strings: 8, Instructions: 390COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06569268 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656D070 Relevance: 4.6, Strings: 3, Instructions: 801COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06564C80 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065408CA Relevance: 2.7, Strings: 2, Instructions: 225COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656925A Relevance: 2.7, Strings: 2, Instructions: 175COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06564C71 Relevance: 2.6, Strings: 2, Instructions: 141COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1ED70 Relevance: 1.6, APIs: 1, Instructions: 138COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1EE58 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540040 Relevance: 1.5, Strings: 1, Instructions: 208COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656DBE5 Relevance: 1.4, Strings: 1, Instructions: 125COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0654264E Relevance: 1.4, Strings: 1, Instructions: 125COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065621BD Relevance: 1.4, Strings: 1, Instructions: 109COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065621D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06564BE1 Relevance: 1.3, Strings: 1, Instructions: 85COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065683E8 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06564B69 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656C2B0 Relevance: .6, Instructions: 648COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656B3E7 Relevance: .6, Instructions: 561COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540E20 Relevance: .3, Instructions: 289COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06566308 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065643BA Relevance: .2, Instructions: 227COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065411F8 Relevance: .2, Instructions: 225COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065646D4 Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065646E8 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656F039 Relevance: .2, Instructions: 207COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656F048 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06542821 Relevance: .2, Instructions: 185COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656FCC9 Relevance: .2, Instructions: 178COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06541500 Relevance: .2, Instructions: 177COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656FA78 Relevance: .2, Instructions: 172COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656FA88 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06542440 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656552A Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06542450 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540FF0 Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06542A91 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656DA98 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06562080 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06542AA0 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06562090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06563508 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06563FC1 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540AB8 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06563FD0 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656B038 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065405DD Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065405E0 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06564318 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065640E0 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656F2B8 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540D62 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06563D9A Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656A420 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065640D1 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540550 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06563DA0 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06564328 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656F2C8 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0654033A Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656A430 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0654026D Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540B28 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06566588 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06540348 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06542A2B Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065677B8 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656AA50 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065671B8 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656BB30 Relevance: 7.7, Strings: 6, Instructions: 197COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 065684F0 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06568908 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0656ADD8 Relevance: 5.2, Strings: 4, Instructions: 163COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 223 |
Total number of Limit Nodes: | 14 |
Graph
Function 0745E7E0 Relevance: 11.0, Strings: 8, Instructions: 971COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07452106 Relevance: 1.8, Strings: 1, Instructions: 561COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EFD530 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 151threadCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EFD540 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745D570 Relevance: 2.8, Strings: 2, Instructions: 300COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745B5D4 Relevance: 1.7, Strings: 1, Instructions: 486COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EFB298 Relevance: 1.7, APIs: 1, Instructions: 205COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EF592D Relevance: 1.6, APIs: 1, Instructions: 100COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EF4508 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06BCBFF0 Relevance: 1.6, APIs: 1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06BCA2B9 Relevance: 1.6, APIs: 1, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06BCA2C0 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E628 Relevance: 1.6, APIs: 1, Instructions: 69threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E8B1 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EFD780 Relevance: 1.6, APIs: 1, Instructions: 67COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E630 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E8B8 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EFD788 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E700 Relevance: 1.6, APIs: 1, Instructions: 57memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06BCAF40 Relevance: 1.6, APIs: 1, Instructions: 56windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E142 Relevance: 1.6, APIs: 1, Instructions: 55threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E708 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E9E148 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073D2488 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EFB498 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073D2490 Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745E7B0 Relevance: 1.4, Strings: 1, Instructions: 151COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06BCD618 Relevance: 1.3, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06BCD644 Relevance: 1.3, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06BCDF00 Relevance: 1.3, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074554D7 Relevance: 1.3, Strings: 1, Instructions: 36COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074554E8 Relevance: 1.3, Strings: 1, Instructions: 32COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07453528 Relevance: .2, Instructions: 167COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07453518 Relevance: .1, Instructions: 131COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745C130 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745C140 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07456589 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745FD48 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745D2C0 Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07457ED8 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07454528 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07457EC8 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745CFC0 Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1D4C4 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1D3D8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745D460 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D005 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745B4E0 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745D218 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1D4BF Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1D3D3 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745D208 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1D745 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07454100 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07454110 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07457E50 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745A3A7 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E1D744 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745503A Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074556D8 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07457E80 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07455680 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07454FFE Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074542E0 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0745A3B8 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074542F0 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|