Windows
Analysis Report
LMm6yxQtcf.exe
Overview
General Information
Sample name: | LMm6yxQtcf.exerenamed because original name is a hash value |
Original sample name: | f8323b929f41ccf03233ed133d14d3b8d4e44ce842db4abf744f7cc96dd8d841.exe |
Analysis ID: | 1569362 |
MD5: | 49e51c7694ea172c357db1cabd2300b7 |
SHA1: | ec874a5836119b7b82aa8ba50e0410bed0e51a8f |
SHA256: | f8323b929f41ccf03233ed133d14d3b8d4e44ce842db4abf744f7cc96dd8d841 |
Tags: | exeuser-adrian__luca |
Infos: | |
Detection
PureLog Stealer, zgRAT
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Detected unpacking (changes PE section rights)
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected PureLog Stealer
Yara detected UAC Bypass using CMSTP
Yara detected zgRAT
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Machine Learning detection for sample
PE file contains section with special chars
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to harvest and steal browser information (history, passwords, etc)
Yara detected Generic Downloader
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Entry point lies outside standard sections
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match
Classification
- System is w10x64
LMm6yxQtcf.exe (PID: 7956 cmdline:
"C:\Users\ user\Deskt op\LMm6yxQ tcf.exe" MD5: 49E51C7694EA172C357DB1CABD2300B7)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
zgRAT | zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. | No Attribution |
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_UACBypassusingCMSTP | Yara detected UAC Bypass using CMSTP | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
|
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Exploits |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | File source: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | DNS query: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 5_2_040002C8 | |
Source: | Code function: | 5_2_040023D1 | |
Source: | Code function: | 5_2_040023E0 | |
Source: | Code function: | 5_2_04008DE3 | |
Source: | Code function: | 5_2_04008DF0 | |
Source: | Code function: | 5_2_04092291 | |
Source: | Code function: | 5_2_04093380 | |
Source: | Code function: | 5_2_04090878 | |
Source: | Code function: | 5_2_04090888 | |
Source: | Code function: | 5_2_063A66C0 | |
Source: | Code function: | 5_2_063AC338 | |
Source: | Code function: | 5_2_063AB1F0 | |
Source: | Code function: | 5_2_063A0ED8 | |
Source: | Code function: | 5_2_063A666F | |
Source: | Code function: | 5_2_063A12FD | |
Source: | Code function: | 5_2_063A0EC8 | |
Source: | Code function: | 5_2_06955448 | |
Source: | Code function: | 5_2_069515C0 | |
Source: | Code function: | 5_2_0695515A | |
Source: | Code function: | 5_2_0695EB70 |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static file information: |
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Binary string: |
Data Obfuscation |
---|
Source: | Unpacked PE file: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 5_2_010F413B | |
Source: | Code function: | 5_2_010F1916 | |
Source: | Code function: | 5_2_010F8129 | |
Source: | Code function: | 5_2_010F819E | |
Source: | Code function: | 5_2_010F857C | |
Source: | Code function: | 5_2_010F8591 | |
Source: | Code function: | 5_2_010F656B | |
Source: | Code function: | 5_2_010F7D9D | |
Source: | Code function: | 5_2_010F4176 | |
Source: | Code function: | 5_2_010F41B3 | |
Source: | Code function: | 5_2_010F498B | |
Source: | Code function: | 5_2_0110D6CB | |
Source: | Code function: | 5_2_010F75C4 | |
Source: | Code function: | 5_2_010F76B1 | |
Source: | Code function: | 5_2_010F31BF | |
Source: | Code function: | 5_2_010F45D4 | |
Source: | Code function: | 5_2_010F45E8 | |
Source: | Code function: | 5_2_010F4609 | |
Source: | Code function: | 5_2_010F7DFE | |
Source: | Code function: | 5_2_010F29D5 | |
Source: | Code function: | 5_2_010F2A0A | |
Source: | Code function: | 5_2_010F41D8 | |
Source: | Code function: | 5_2_010F41DF | |
Source: | Code function: | 5_2_010F41F6 | |
Source: | Code function: | 5_2_010F4213 | |
Source: | Code function: | 5_2_010F66A0 | |
Source: | Code function: | 5_2_010F81F7 | |
Source: | Code function: | 5_2_010F8211 | |
Source: | Code function: | 5_2_010F822A | |
Source: | Code function: | 5_2_010F1C49 | |
Source: | Code function: | 5_2_010F77D4 |
Boot Survival |
---|
Source: | Window searched: | Jump to behavior | ||
Source: | Window searched: | Jump to behavior | ||
Source: | Window searched: | Jump to behavior | ||
Source: | Window searched: | Jump to behavior | ||
Source: | Window searched: | Jump to behavior | ||
Source: | Window searched: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | System information queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Registry key queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | Thread information set: | Jump to behavior |
Source: | Open window title or class name: | ||
Source: | Open window title or class name: | ||
Source: | Open window title or class name: | ||
Source: | Open window title or class name: | ||
Source: | Open window title or class name: | ||
Source: | Open window title or class name: |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: |
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 131 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Masquerading | 1 OS Credential Dumping | 761 Security Software Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Disable or Modify Tools | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | 2 Data from Local System | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 471 Virtualization/Sandbox Evasion | Security Account Manager | 471 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Software Packing | LSA Secrets | 1 System Network Configuration Discovery | SSH | Keylogging | 2 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Timestomp | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 24 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
66% | ReversingLabs | Win32.Infostealer.Tinba | ||
100% | Avira | HEUR/AGEN.1323826 | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ip-api.com | 208.95.112.1 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
208.95.112.1 | ip-api.com | United States | 53334 | TUT-ASUS | false | |
5.42.92.0 | unknown | Russian Federation | 39493 | RU-KSTVKolomnaGroupofcompaniesGuarantee-tvRU | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1569362 |
Start date and time: | 2024-12-05 18:17:50 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | LMm6yxQtcf.exerenamed because original name is a hash value |
Original Sample Name: | f8323b929f41ccf03233ed133d14d3b8d4e44ce842db4abf744f7cc96dd8d841.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.expl.evad.winEXE@1/1@1/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, Sgrmuserer.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: LMm6yxQtcf.exe
Time | Type | Description |
---|---|---|
12:18:49 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
208.95.112.1 | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | XWorm | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ip-api.com | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | XWorm | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
RU-KSTVKolomnaGroupofcompaniesGuarantee-tvRU | Get hash | malicious | GCleaner | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, XWorm | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
TUT-ASUS | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | XWorm | Browse |
|
⊘No context
⊘No context
Process: | C:\Users\user\Desktop\LMm6yxQtcf.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1795 |
Entropy (8bit): | 5.332236526324957 |
Encrypted: | false |
SSDEEP: | 48:MxHKiHKYHmYHKh3ogLHitHo6hAHKzebHqHG1qHDJHTHKMHA:iqiqYGYqh3ogLCtI6eqzsKmwVzqMg |
MD5: | F23AEC62DD40C37DA462CA3E4D8C86E6 |
SHA1: | 44A3989CB3C32A602670851EF6DE2109A089938B |
SHA-256: | 4EE82BCC43E258BAD24289463C2163C28A6F982A41AC50751E11A9E78EF34818 |
SHA-512: | 8B622E94A1B6D08978914E6F246449B6CBEC2EE76AE8DF821075B18431404F62B6521D36B0577FFE425AE960645DDC30B1AE2403C0C41717630372E16E09AE32 |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.880753879295548 |
TrID: |
|
File name: | LMm6yxQtcf.exe |
File size: | 5'013'292 bytes |
MD5: | 49e51c7694ea172c357db1cabd2300b7 |
SHA1: | ec874a5836119b7b82aa8ba50e0410bed0e51a8f |
SHA256: | f8323b929f41ccf03233ed133d14d3b8d4e44ce842db4abf744f7cc96dd8d841 |
SHA512: | dd4602c1ed61cc3ac183c2f3a5c9ca953d07743dd55712538354d8ad320a26a9b2caaffa4a180f3bebbd3d711af192c27c54bafca1def6d86dcdd01d45bb3c0c |
SSDEEP: | 98304:As7M0OgNgIIrtBYkogenta2XPDnjHb/CCYm976hRH+2oDhs8AvFEm0y:v7lOcvQt7ogeV7nHCJml6HH5qE9c |
TLSH: | BA36231BBA168941C2946B37C59F51045778DB81236BEB0D78C927EA08633BFE84F64F |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...#.t...............0.................. ...@....@.. ....................... ........L...`................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0xf0e000 |
Entrypoint Section: | .taggant |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, TERMINAL_SERVER_AWARE |
Time Stamp: | 0xBF741A23 [Wed Oct 14 14:05:23 2071 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 4328f7206db519cd4e82283211d98e83 |
Signature Valid: | false |
Signature Issuer: | CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US |
Signature Validation Error: | The digital signature of the object did not verify |
Error Number: | -2146869232 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | D03E1ED3E72F64CC6C5A636BE32C29AD |
Thumbprint SHA-1: | 97221B97098F37A135DCC212E2B41E452BCE51F2 |
Thumbprint SHA-256: | AAE358FD90D5500110EE8BF3BD2C668F834559710DA7D75C266018BB9506F2F6 |
Serial: | 33000002CDF364BFF8D44C5D510000000002CD |
Instruction |
---|
jmp 00007EFFC07E05EAh |
wrmsr |
dec esp |
add byte ptr [eax], al |
add byte ptr [eax], al |
add cl, ch |
add byte ptr [eax], ah |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [edi], cl |
sub eax, 01000000h |
add byte ptr [eax], al |
add byte ptr [eax], cl |
add dword ptr [eax], eax |
add byte ptr [eax], al |
or eax, dword ptr [ebx+00h] |
add dword ptr [eax], eax |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x6803a | 0x50 | .imports |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6a000 | 0xa80 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x4c5014 | 0x2f18 | .themida |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x62000 | 0x60600 | ab6f98e07e44bc34c4dda69368dc80e1 | False | 0.4584827942607004 | SysEx File - | 5.931039177166276 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
0x64000 | 0x590 | 0x288 | eca90b3c03b067ca15aa0cf3f8e991fc | False | 1.0169753086419753 | data | 7.585830734854682 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | |
0x66000 | 0xc | 0xf | dcec01ac5a13f93c73da7e4c95983a67 | False | 1.6 | data | 3.906890595608518 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | |
.imports | 0x68000 | 0x2000 | 0x200 | c59a21b8569552638f4f2a8d846fbe57 | False | 0.16796875 | data | 1.1405531534676816 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x6a000 | 0x2000 | 0xc00 | d6ba8a6642cb692968346f00b3efb802 | False | 0.3463541666666667 | data | 4.673291671683264 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.themida | 0x6c000 | 0x640000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.boot | 0x6ac000 | 0x461200 | 0x461200 | 8f70613658d40772bd311a5f526638cb | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.taggant | 0xb0e000 | 0x2200 | 0x2014 | a6bb36a27ce1383ed48f73ac7263ee4c | False | 0.09072089624939113 | DOS executable (COM) | 0.9676940379095681 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x6a0b0 | 0x304 | data | 0.4339378238341969 | ||
RT_MANIFEST | 0x6a3c4 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | English | United States | 0.5489795918367347 |
RT_MANIFEST | 0x6a5c0 | 0x4c0 | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1156), with CRLF line terminators | English | United States | 0.47368421052631576 |
DLL | Import |
---|---|
kernel32.dll | GetModuleHandleA |
mscoree.dll | _CorExeMain |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 5, 2024 18:18:49.231070995 CET | 49715 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:49.350866079 CET | 80 | 49715 | 208.95.112.1 | 192.168.2.10 |
Dec 5, 2024 18:18:49.351017952 CET | 49715 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:49.351361036 CET | 49715 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:49.471987963 CET | 80 | 49715 | 208.95.112.1 | 192.168.2.10 |
Dec 5, 2024 18:18:50.447510958 CET | 80 | 49715 | 208.95.112.1 | 192.168.2.10 |
Dec 5, 2024 18:18:50.497365952 CET | 49715 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:52.233573914 CET | 49721 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:52.233875036 CET | 49715 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:52.353261948 CET | 80 | 49721 | 208.95.112.1 | 192.168.2.10 |
Dec 5, 2024 18:18:52.353368044 CET | 49721 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:52.353528023 CET | 49721 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:52.354182959 CET | 80 | 49715 | 208.95.112.1 | 192.168.2.10 |
Dec 5, 2024 18:18:52.354243994 CET | 49715 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:52.473354101 CET | 80 | 49721 | 208.95.112.1 | 192.168.2.10 |
Dec 5, 2024 18:18:53.453075886 CET | 80 | 49721 | 208.95.112.1 | 192.168.2.10 |
Dec 5, 2024 18:18:53.497360945 CET | 49721 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:53.947896957 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.067590952 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.067666054 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.068747997 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.069437027 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.083075047 CET | 49721 | 80 | 192.168.2.10 | 208.95.112.1 |
Dec 5, 2024 18:18:54.188672066 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.188723087 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189446926 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.189486980 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.189517975 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189549923 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189641953 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.189686060 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.189686060 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189728975 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189802885 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.189841032 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.189848900 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189879894 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189929008 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.189971924 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.189979076 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.190025091 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.190053940 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.190097094 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.310349941 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.310451031 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.311346054 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.311357021 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.311410904 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.311420918 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.311511993 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.311558962 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.311714888 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.311784983 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.354311943 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.354410887 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.479813099 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.479938984 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.526319981 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.642250061 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.645044088 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:54.846282959 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:54.847855091 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:55.090317011 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:55.091044903 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:55.334352016 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:55.334408045 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:55.578294039 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:55.578396082 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:55.826396942 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:55.826513052 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:56.071310997 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:56.071372032 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:56.314352989 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:56.314630985 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:56.558309078 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:56.559655905 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:56.802331924 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:56.802453995 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:57.046286106 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:57.046466112 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:57.294260979 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:57.294979095 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:57.542236090 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:57.542285919 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:57.782223940 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:57.782275915 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:58.026252985 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:58.026318073 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:58.266247988 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:58.266345024 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:58.506370068 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:58.506582022 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:58.750267982 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:58.750322104 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:58.994568110 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:58.994618893 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:59.242234945 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:59.242305040 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:59.544265985 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:59.557988882 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:59.558063984 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:59.768733025 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:59.775381088 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:59.775450945 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:18:59.978343964 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:18:59.978410006 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:00.218410015 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:00.218486071 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:00.462266922 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:00.462337017 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:00.706237078 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:00.706717014 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:00.950345993 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:00.950453043 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:01.194556952 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:01.194633007 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:01.438338995 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:01.438427925 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:01.682384014 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:01.682558060 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:01.926198006 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:01.926286936 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:02.166333914 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:02.167104959 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:02.410538912 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:02.410595894 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:02.658267975 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:02.658322096 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:02.902295113 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:02.902354956 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:03.146298885 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:03.146359921 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:03.386276960 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:03.386413097 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:03.630314112 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:03.632245064 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:03.874280930 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:03.874488115 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:04.118304968 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:04.121097088 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:04.362333059 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:04.362493992 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:04.606287003 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:04.606395006 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:04.846282005 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:04.846455097 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:05.094301939 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:05.094368935 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:05.338267088 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:05.338324070 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:05.578362942 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:05.578471899 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:05.822288036 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:05.822494984 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:06.070333004 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:06.070437908 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:06.318243980 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:06.318325043 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:06.562340975 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:06.563981056 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:06.810679913 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:06.811472893 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:07.058314085 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:07.058451891 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:07.302463055 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:07.302524090 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:07.546473980 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:07.546658993 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:07.790345907 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:07.790586948 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:08.034408092 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:08.034483910 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:08.278322935 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:08.278434992 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:08.522332907 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:08.522444963 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:08.766329050 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:08.766449928 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:09.006277084 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:09.006455898 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:09.250477076 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:09.250545025 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:09.494426012 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:09.494553089 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:09.738353014 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:09.738418102 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:09.979605913 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:09.979715109 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:10.226677895 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:10.226824999 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:10.470354080 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:10.470535994 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:10.718332052 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:10.718420029 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:10.958317995 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:10.958439112 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:11.198298931 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:11.198450089 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:11.438457012 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:11.438623905 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:11.682786942 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:11.685077906 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:11.926306009 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:11.926537037 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:12.166383028 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:12.169065952 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:12.410569906 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:12.410670042 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:12.658361912 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:12.658621073 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:12.906395912 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:12.906487942 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:13.154439926 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:13.154525042 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:13.415329933 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:13.415487051 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:13.658606052 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:13.658883095 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:13.902414083 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:13.902575970 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:14.146454096 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:14.146560907 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:14.390532970 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:14.390671015 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:14.635385990 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:14.635499954 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:14.884810925 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:14.885070086 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:15.126437902 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:15.126682043 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:15.370378017 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:15.370456934 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:15.614341974 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:15.614521980 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:15.858366013 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:15.858535051 CET | 49727 | 5555 | 192.168.2.10 | 5.42.92.0 |
Dec 5, 2024 18:19:15.957359076 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Dec 5, 2024 18:19:15.978579044 CET | 5555 | 49727 | 5.42.92.0 | 192.168.2.10 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 5, 2024 18:18:49.088661909 CET | 54942 | 53 | 192.168.2.10 | 1.1.1.1 |
Dec 5, 2024 18:18:49.225924969 CET | 53 | 54942 | 1.1.1.1 | 192.168.2.10 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 5, 2024 18:18:49.088661909 CET | 192.168.2.10 | 1.1.1.1 | 0x3cf8 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 5, 2024 18:18:49.225924969 CET | 1.1.1.1 | 192.168.2.10 | 0x3cf8 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.10 | 49715 | 208.95.112.1 | 80 | 7956 | C:\Users\user\Desktop\LMm6yxQtcf.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 18:18:49.351361036 CET | 97 | OUT | |
Dec 5, 2024 18:18:50.447510958 CET | 483 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.10 | 49721 | 208.95.112.1 | 80 | 7956 | C:\Users\user\Desktop\LMm6yxQtcf.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 18:18:52.353528023 CET | 97 | OUT | |
Dec 5, 2024 18:18:53.453075886 CET | 483 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 5 |
Start time: | 12:18:39 |
Start date: | 05/12/2024 |
Path: | C:\Users\user\Desktop\LMm6yxQtcf.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xee0000 |
File size: | 5'013'292 bytes |
MD5 hash: | 49E51C7694EA172C357DB1CABD2300B7 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |