Windows
Analysis Report
GasTechnologyPartnership.pdf
Overview
General Information
Detection
HTMLPhisher
Score: | 72 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
AI detected phishing page
Antivirus detection for URL or domain
Yara detected HtmlPhish10
AI detected landing page (webpage, office document or email)
Phishing site or detected (based on various text indicators)
HTML body contains low number of good links
HTML body contains password input but no form action
HTML title does not match URL
IP address seen in connection with other malware
Invalid T&C link found
Stores files to the Windows start menu directory
Classification
- System is w10x64_ra
Acrobat.exe (PID: 5476 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\G asTechnolo gyPartners hip.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) AcroCEF.exe (PID: 7040 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) AcroCEF.exe (PID: 6196 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=16 12 --field -trial-han dle=1328,i ,693445659 236905266, 1717421823 2691262086 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) chrome.exe (PID: 7936 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// gastechnol ogypartner ship.thesi lkfactoryc loudfilesh ub.click/u cI2u MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 8116 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2112 --fi eld-trial- handle=205 2,i,707301 8099660394 99,1243178 9452607259 477,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security | ||
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security | ||
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | OCR Text: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Directory created: | Jump to behavior |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | Directory created: | Jump to behavior |
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 1 Spearphishing Link | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 3 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
jsdelivr.map.fastly.net | 151.101.1.229 | true | false | high | |
stackpath.bootstrapcdn.com | 104.18.10.207 | true | false | high | |
sgp.file.myqcloud.com | 43.152.64.193 | true | false | high | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
e329293.dscd.akamaiedge.net | 95.101.182.65 | true | false | high | |
e8652.dscx.akamaiedge.net | 92.123.17.129 | true | false | high | |
maxcdn.bootstrapcdn.com | 104.18.11.207 | true | false | high | |
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | high | |
s-part-0017.t-0009.fb-t-msedge.net | 13.107.253.45 | true | false | high | |
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
5320986944.businessapptools.com | 69.49.246.64 | true | false | high | |
code.jquery.com | 151.101.130.137 | true | false | high | |
cdnjs.cloudflare.com | 104.17.25.14 | true | false | high | |
challenges.cloudflare.com | 104.18.94.41 | true | false | high | |
www.google.com | 216.58.206.36 | true | false | high | |
x1.i.lencr.org | unknown | unknown | false | high | |
cdn.jsdelivr.net | unknown | unknown | false | high | |
aadcdn.msftauth.net | unknown | unknown | false | high | |
5320986944-1317754460.cos.ap-singapore.myqcloud.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
true | unknown | ||
false | high | ||
false |
| unknown | |
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
true | unknown | ||
false | high | ||
false |
| unknown | |
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
95.101.182.65 | e329293.dscd.akamaiedge.net | European Union | 20940 | AKAMAI-ASN1EU | false | |
104.18.10.207 | stackpath.bootstrapcdn.com | United States | 13335 | CLOUDFLARENETUS | false | |
104.18.94.41 | challenges.cloudflare.com | United States | 13335 | CLOUDFLARENETUS | false | |
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false | |
43.152.64.193 | sgp.file.myqcloud.com | Japan | 4249 | LILLY-ASUS | false | |
151.101.130.137 | code.jquery.com | United States | 54113 | FASTLYUS | false | |
69.49.246.64 | 5320986944.businessapptools.com | United States | 46606 | UNIFIEDLAYER-AS-1US | false | |
151.101.66.137 | unknown | United States | 54113 | FASTLYUS | false | |
43.153.232.151 | unknown | Japan | 4249 | LILLY-ASUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
151.101.1.229 | jsdelivr.map.fastly.net | United States | 54113 | FASTLYUS | false | |
104.17.24.14 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
104.18.11.207 | maxcdn.bootstrapcdn.com | United States | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
188.114.97.3 | unknown | European Union | 13335 | CLOUDFLARENETUS | false | |
92.123.17.129 | e8652.dscx.akamaiedge.net | European Union | 16625 | AKAMAI-ASUS | false | |
104.17.25.14 | cdnjs.cloudflare.com | United States | 13335 | CLOUDFLARENETUS | false | |
95.101.182.112 | unknown | European Union | 20940 | AKAMAI-ASN1EU | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1615833 |
Start date and time: | 2025-02-15 15:29:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | GasTechnologyPartnership.pdf |
Detection: | MAL |
Classification: | mal72.phis.winPDF@32/103@49/19 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 92.123.16.204, 18.213.11.84, 50.16.47.176, 54.224.241.105, 34.237.241.83, 172.64.41.3, 162.159.61.3, 199.232.214.172, 2.22.242.11, 2.22.242.123, 216.58.212.163, 142.250.185.142, 74.125.71.84, 142.250.185.78, 216.58.206.78, 142.250.185.170, 216.58.212.138, 142.250.184.206, 142.250.181.238, 142.250.186.46, 142.250.186.170, 172.217.18.10, 142.250.184.202, 172.217.23.106, 172.217.16.202, 216.58.206.74, 142.250.186.42, 172.217.16.138, 142.250.186.138, 142.250.186.74, 216.58.212.170, 216.58.206.42, 142.250.181.234, 142.250.184.234, 142.250.186.106, 172.217.18.106, 142.250.185.174, 142.250.185.206, 142.250.184.238, 142.250.186.174, 172.217.16.206, 216.58.206.67, 142.250.185.238, 2.19.106.160, 20.12.23.50, 23.56.162.204, 13.107.246.45, 13.107.253.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, slscr.update.microsoft.com, clientservices.googleapis.com, thesilkfactorycloudfileshub.click, acroipm2.adobe.com, clients2.google.com, redirector.gvt1.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, update.googleapis.com, gastechnologypartnership.thesilkfactorycloudfileshub.click, wu-b-net.trafficmanager.net, clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ajax.googleapis.com, aadcdnoriginwus2.azureedge.net, ctldl.windowsupdate.com, aadcdn.msauth.net, p13n.adobe.io, firstparty-azurefd-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, edgedl.me.gvt1.com, armmf.adobe.com, aadcdnoriginwus2.afd.azureedge.net, clients.l.google.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
09:29:49 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
95.101.182.65 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | TechSupportScam | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
104.18.10.207 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
104.18.94.41 | Get hash | malicious | HTMLPhisher | Browse | ||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
stackpath.bootstrapcdn.com | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | TechSupportScam | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
e329293.dscd.akamaiedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse |
| ||
Get hash | malicious | HTMLPhisher, Tycoon2FA | Browse |
| ||
e8652.dscx.akamaiedge.net | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
jsdelivr.map.fastly.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
sgp.file.myqcloud.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AKAMAI-ASN1EU | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.213220772892281 |
Encrypted: | false |
SSDEEP: | 6:iOXV2UfA19N+q2PRN2nKuAl9OmbnIFUtFV2UfAQmmZmw7V2UfAQmiVkwORN2nKui:7FCP+vaHAahFUtf//R/V5JHAaSJ |
MD5: | 7CFDE420145680E64F4E5A7BB142BECC |
SHA1: | 6F9B43C88F4921E3586CA272451338D8FB358A59 |
SHA-256: | 5CC8763E9030E77C4CA0FDD17E8EBCE123D68BD6C0948B5E22D375DE70A985AE |
SHA-512: | 2203B182260CBE31617A490A43512D916B52457EBCC330312010EF414BA1A1312049CAACD89AC6833686D8F10694CF3AF3ADFBB069767D3EE48C74BC6CBCABE2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.213220772892281 |
Encrypted: | false |
SSDEEP: | 6:iOXV2UfA19N+q2PRN2nKuAl9OmbnIFUtFV2UfAQmmZmw7V2UfAQmiVkwORN2nKui:7FCP+vaHAahFUtf//R/V5JHAaSJ |
MD5: | 7CFDE420145680E64F4E5A7BB142BECC |
SHA1: | 6F9B43C88F4921E3586CA272451338D8FB358A59 |
SHA-256: | 5CC8763E9030E77C4CA0FDD17E8EBCE123D68BD6C0948B5E22D375DE70A985AE |
SHA-512: | 2203B182260CBE31617A490A43512D916B52457EBCC330312010EF414BA1A1312049CAACD89AC6833686D8F10694CF3AF3ADFBB069767D3EE48C74BC6CBCABE2 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.180749728236602 |
Encrypted: | false |
SSDEEP: | 6:iOXV2UfhP4q2PRN2nKuAl9Ombzo2jMGIFUtFV2UfPNJZmw7V2UfPNDkwORN2nKuA:7Fx4vaHAa8uFUtftJ/RtD5JHAa8RJ |
MD5: | 2C2BBC8D8FD9A4515F06F494574D01E1 |
SHA1: | 1D43E26867E742384E9F451DE6609AECB2421834 |
SHA-256: | B970D80EE888628FF7DD6329615F116BB76D81D5F7D47E6FAE123E0775ED379B |
SHA-512: | 34C3A9413E6FEF629D1E0E5EFC02ADB1C8752033A0A182A23E322C14D640BBAEA3ECBAF7C873E8BF99846501BF01CA659AB563AA764DE4FD3AB1B20BB2A9E2EB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.180749728236602 |
Encrypted: | false |
SSDEEP: | 6:iOXV2UfhP4q2PRN2nKuAl9Ombzo2jMGIFUtFV2UfPNJZmw7V2UfPNDkwORN2nKuA:7Fx4vaHAa8uFUtftJ/RtD5JHAa8RJ |
MD5: | 2C2BBC8D8FD9A4515F06F494574D01E1 |
SHA1: | 1D43E26867E742384E9F451DE6609AECB2421834 |
SHA-256: | B970D80EE888628FF7DD6329615F116BB76D81D5F7D47E6FAE123E0775ED379B |
SHA-512: | 34C3A9413E6FEF629D1E0E5EFC02ADB1C8752033A0A182A23E322C14D640BBAEA3ECBAF7C873E8BF99846501BF01CA659AB563AA764DE4FD3AB1B20BB2A9E2EB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\5ea30e9c-6ab6-4f66-9f6c-d3d7b7d6e6ae.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 403 |
Entropy (8bit): | 4.953858338552356 |
Encrypted: | false |
SSDEEP: | 12:YHO8sq/WLksBdOg2H9caq3QYiubrP7E4T3y:YXsRJdMHM3QYhbz7nby |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 403 |
Entropy (8bit): | 4.953858338552356 |
Encrypted: | false |
SSDEEP: | 12:YHO8sq/WLksBdOg2H9caq3QYiubrP7E4T3y:YXsRJdMHM3QYhbz7nby |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF6deb48.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 403 |
Entropy (8bit): | 4.953858338552356 |
Encrypted: | false |
SSDEEP: | 12:YHO8sq/WLksBdOg2H9caq3QYiubrP7E4T3y:YXsRJdMHM3QYhbz7nby |
MD5: | 4C313FE514B5F4E7E89329630909F8DC |
SHA1: | 916EED77EC8C9DC90C64FF1E5CC9D04D4674EE56 |
SHA-256: | 1EE7C151EF264F91FCDCCB6644F62DC33E27A4E829DAAB748DA1DE4426400873 |
SHA-512: | 1726CAFCBA0121691DFA87A7298E6610BC4C7FD900867FD1B1710811E764918585E56788E08B7CA2CEE001F5DFD110E1BE6F6BBD7C2A7B7E2FC87D3DED210205 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\b2b13f84-2dce-41e4-aa35-d8094b8528f9.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 403 |
Entropy (8bit): | 4.981715301590009 |
Encrypted: | false |
SSDEEP: | 12:YHO8sqdcD3sBdOg2Hmcaq3QYiubrP7E4T3y:YXsIJdMHZ3QYhbz7nby |
MD5: | AA910F4E12113452F4B2AF53295C01AB |
SHA1: | 8AFB730D8ABF50E3314AEF1E1AC1EB441B55F0D7 |
SHA-256: | 7771A8A3C377267B1781D07F766DE3F06637AA98BB7CF57F535CB5AA1EF60703 |
SHA-512: | 6F41B8340B9D250E965534CD88626DFAD329F3E442F9BA2634A8DA0E143D34FF39536B3C5B77149287A99DF8539D126FAF7373B3DF4D5F122DF961989E0AE24A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.23756749858778 |
Encrypted: | false |
SSDEEP: | 96:OLSw0bSwIAnrRqLX2rSq1OUxu/0OZ0xRBTxekN8xem+1XH:OLT0bTIeYa51Ogu/0OZARBT8kN88m+13 |
MD5: | 9C4A80C38F19C052206511DEB4B2CDA1 |
SHA1: | 46FC8DE4E09CB798A531A3DD379B2E1DFF21EA8E |
SHA-256: | 68449087D87C119C2E93B226AB07AF798BC08236A6D77AE36A042CFA576E29DB |
SHA-512: | 01752E88605714BF4DD05DCEFE77CD65015CE1C614F31339196853BC0E33C58D4917CC65A63CF851C501230D8B1FC2069D220D933EFA46EE8FEE32126E4A475B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.204116627627693 |
Encrypted: | false |
SSDEEP: | 6:iOXV2UfAcz4q2PRN2nKuAl9OmbzNMxIFUtFV2UfAcwNJZmw7V2UfAcfvDkwORN2v:7Fl4vaHAa8jFUtfyNJ/RxD5JHAa84J |
MD5: | E08A9F7E55C48C8C4C50FCC8F9E96245 |
SHA1: | F05A565AD47381C7E237AA49B10D585778478704 |
SHA-256: | F905857C9E745344637AA791B42E2D681F358484E6283FA4BEF0C8BF003DB22A |
SHA-512: | D6456737AEDB2949D3E0349F47478AADF37F21B1C20AADDE31C65DF4D023CD1215A540646B1C665419FF0FD97A15C35A97DA450C8F8E0D365C799A37C905009C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.204116627627693 |
Encrypted: | false |
SSDEEP: | 6:iOXV2UfAcz4q2PRN2nKuAl9OmbzNMxIFUtFV2UfAcwNJZmw7V2UfAcfvDkwORN2v:7Fl4vaHAa8jFUtfyNJ/RxD5JHAa84J |
MD5: | E08A9F7E55C48C8C4C50FCC8F9E96245 |
SHA1: | F05A565AD47381C7E237AA49B10D585778478704 |
SHA-256: | F905857C9E745344637AA791B42E2D681F358484E6283FA4BEF0C8BF003DB22A |
SHA-512: | D6456737AEDB2949D3E0349F47478AADF37F21B1C20AADDE31C65DF4D023CD1215A540646B1C665419FF0FD97A15C35A97DA450C8F8E0D365C799A37C905009C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-250215142940Z-166.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 1.8268890317354345 |
Encrypted: | false |
SSDEEP: | 192:67DsFcSZKEjHvfm76ukFKNXXbzQJ0wwwwLD9gwwwwwwww+:6nsFcSFjHvfmc8lXw4 |
MD5: | 6A9A6D2AEB176846B1AD58E7113AE958 |
SHA1: | 90D3EE8E5345755CB5BB81AD14993C4813456B7E |
SHA-256: | 2A43E32E73CA039BAB3FEE79E3D6759946AECC7BA5D65D461EA264FC7566D7A0 |
SHA-512: | 91178DCD38A2C29E8A81980777EF0F75FF1BFE8C96E6470BD3867F05677623F19ACA834295190481B0FA3AB9E353749A93E82789AB63B788361F5B03984C40F8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.291927920232006 |
Encrypted: | false |
SSDEEP: | 192:vedRBvVui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:veBci5H5FY+EUUUTTcHqFzqFP |
MD5: | A4D5FECEFE05F21D6F81ACF4D9A788CF |
SHA1: | 1A9AC236C80F2A2809F7DE374072E2FCCA5A775C |
SHA-256: | 83BE4623D80FFB402FBDEC4125671DF532845A3828A1B378D99BD243A4FD8FF2 |
SHA-512: | FF106C6B9E1EA4B1F3E3AB01FAEA21BA24A885E63DDF0C36EB0A8C3C89A9430FE676039C076C50D7C46DC4E809F6A7E35A4BFED64D9033FEBD6121AC547AA5E9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16928 |
Entropy (8bit): | 1.2151444290005073 |
Encrypted: | false |
SSDEEP: | 24:7+tgXqLi+zkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mzm+Zb:7M0qLmFTIF3XmHjBoGGR+jMz+Lhq |
MD5: | 2CCC1A3C085789680093BB5BE42B20EB |
SHA1: | 238CA8508A3AAF5274FBF3B52D3398C69EF0CF8F |
SHA-256: | 976FB60CF2CDD92D0558EA68852ACB28AD83DF27FFE6C33599DD55E46D7B7087 |
SHA-512: | 7336B51C748C9E50014125E422F3288779B281AFA03FCBDF336170F20D2F5AF1857BAB4B6D1683DD2873D04BF67952B8FD5AD4363AEAF06C868259F6A377D61C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7673182398396405 |
Encrypted: | false |
SSDEEP: | 3:kkFklt2NmllXfllXlE/HT8kmRjNNX8RolJuRdxLlGB9lQRYwpDdt:kKPMl2T8jNMa8RdWBwRd |
MD5: | 41749FCF500585ED9D07CBD2CD79E264 |
SHA1: | 920AFD94AD9A7FCCEC7E6CDD546F8736490EEE58 |
SHA-256: | C8ADA348F0FB9AE1B20CC0F9DC64A7391DBE03CFA930558F383944D18F37F32A |
SHA-512: | D31D3DCD73827889EA5CD3AF9C941B4E58D462F14A2D58CC9221CA24ECDF1C99FCF19949DD27DD2D0B447C652ADC93BC56706A359283445D11AECF986A91F321 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.2539954282295116 |
Encrypted: | false |
SSDEEP: | 6:kKTw9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:XDImsLNkPlE99SNxAhUe/3 |
MD5: | 07B5E9A05C2B792F7C428082D5C70502 |
SHA1: | 4449F03542BC7E65A12F1A0575E731FA4CEB4697 |
SHA-256: | 8D419044CF1FF133B3AD403EA6B264ED04D3C3627DDE1A590D7EA4EEE743AF62 |
SHA-512: | DFDBBE06AFB239CAEEE3121C2A9835BEEF5620C58324D246010FBFB05058D498BD65BDF003ADDCDA0665EC983D3FF6502438DB727041EA796F8746D939F59332 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3759757139974935 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJM3g98kUwPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGMbLUkee9 |
MD5: | 410C88EE58A57791BC7CB15078022DA4 |
SHA1: | B5338F2CCD41D907846543EF100E2496AD101BD9 |
SHA-256: | C78FB7FC7DEEECBA530D662F917B2721C9190EC3D04B08D6EB37C937869AE2BA |
SHA-512: | D3B3834C02EFA70BBAE61A38C71AAE4A879884DFA19E6DFBC5C1B8670679135EAA0C9AED3B783935B43C7D91E5DF30142D26D9246826189CB8B3A76FF66D908C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.324967149652162 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfBoTfXpnrPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGWTfXcUkee9 |
MD5: | E0361F550C4A820A0AF6D9A14309BA8D |
SHA1: | B7F3C157098CB30858BE50482A99708C990C73A5 |
SHA-256: | 18DEFC87080ED4B288ACB0A696F12F5D45C9C9C3D690507F4B09E2E521DC3E4C |
SHA-512: | A024382DE5601FADECE588F51283C868E50F4A22A62D3857093DBD1894314262415BD8E4F6FD9E69110754CE4F6BC59E65AFAF04C7B9DB5B8709F8213C65F64C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3028172432292315 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfBD2G6UpnrPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGR22cUkee9 |
MD5: | 0C5B8FF5709B6E94428C86A81077B46E |
SHA1: | 6E095C969550156A3EBFA36411CE562D37692C87 |
SHA-256: | 28C75CCB6BF0FE00541EF0E39764188B059A052F64388F4511F40FE96F486657 |
SHA-512: | 27ABD6A316E0F1DCC3AEBE30EEFFD35BF47C56143AA34372D560946DF9F566094CC95695B399DEF754FD85C49F583E800083D51D01C91F057BF5CD4BB22014EC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.364798440551833 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfPmwrPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGH56Ukee9 |
MD5: | 739C1F5C7A886A375923BA785C727593 |
SHA1: | 48E2143AD8461CA42215A003D15E393B42760339 |
SHA-256: | D93EE1BF8F13D86C6F5CDE6A7D5A8D1BB900A9EB841A68D36C041F6E06C0BEFE |
SHA-512: | 53FAE13D3B4D180F29FB6B5264CD8989045C0CFD593EB8F37F292769E4868A5806918633884ED69B500B5C935608C3D477B1A411F6C6CE12E81656E5061A2B7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2135 |
Entropy (8bit): | 5.8394029913399015 |
Encrypted: | false |
SSDEEP: | 48:YvERUSRU2hgYTUIy48Y/TWCaoIpbTNQDcSmjWAK:GarRUygqUx45/TEp/NQoSmC |
MD5: | C4438DE1E4DF7B5006A6C909394E015C |
SHA1: | 781FCA89970BA98A7890555752ED61360FFCB9F9 |
SHA-256: | 9861B56E1B8896A8290EDB6C46F0C980C30764DDAB9E67EAE02B75D32D2F25DC |
SHA-512: | EBFE2F089B57322C6D9096A8023918352DE5F626CF7D6A809CD711082F6EBE1CD47A195237F54C92E2CC761D26E1CBE2D25041A0D014C42B4C6F1D2C0DDBFB0F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.308992508012483 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJf8dPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGU8Ukee9 |
MD5: | C500E69B51227A44D91796B15BEEABE0 |
SHA1: | 650995A312C0E67F13279085F8CF95E20BA22DC9 |
SHA-256: | 1D637208E9250003A216ACBDAEA5052132F8C60207689AB070BFF7BC256409E8 |
SHA-512: | 9241DE5B57A930ED3ED2918AC90E58C40CF8694B7F4324DCE62210AA77FFB68A2E5B1985A125AD3B3A0095E3D44AB647900547883003EE15984B92438844EF13 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.312133970165112 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfQ1rPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGY16Ukee9 |
MD5: | BF1CBDAE1E6F1B41DAC955C2ED6058A3 |
SHA1: | E3333F8B240C28C3E571A77C3406459BC4BB25F3 |
SHA-256: | B193BDF476D48A5270BB72A7494C1528C2113E647677D35EBF97506F96CDA372 |
SHA-512: | 2139EC4BCE9E01986A4663BA54A390134278F74CD962EACD5D77F0C525816E2E3BEC68A09ACD37BD96D928B0C93B327C317E79B31612E3C594AF521BD8A14A3E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2082 |
Entropy (8bit): | 5.8342467352076675 |
Encrypted: | false |
SSDEEP: | 48:YvERUSRUlogYUIN48l/Giya0Oumi+6yTnK:GarRUWgYU44Y/d3umiZT |
MD5: | 6FBA3385E86C542EF6F643A031DBBCB1 |
SHA1: | 018F6041BA0315315C59AB759D6AA41E9BA8224D |
SHA-256: | 71BAE3DF814CFB59B126AD9E8DDA5AFA5AEF461C809886F79EC4CB967F9A37BC |
SHA-512: | BD02E8CCA222FE9F1CF1A90E99A558FEA26E2DC2F12B8BF944121B1CC207BBD0E5737F3EED27434FF342040A13D06D086A6D58C9620F6927EE7E07F71B369A55 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.334789964129721 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfzdPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGb8Ukee9 |
MD5: | 9C45049C79FB5CBFDB97313B79E71E73 |
SHA1: | 5D9FA187D84BDC10D0D007D14632069CE91045BB |
SHA-256: | 316EC6B668054C89DB3A6F10922614BAEAC5232C973085D9F399C896FA53B477 |
SHA-512: | 26389092C6505124BD5F6BC4D86BB8EC5E8484FA00E418D054157293667E8E9C4968A6D0F819B536A87650F55B683313B3F5785FC37F4B4CC562977454F238D5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.316031454529802 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfYdPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGg8Ukee9 |
MD5: | DC8581091DAF61A00D048E2092F7F141 |
SHA1: | E933790DA816317A03A9BED8930808FFF681478D |
SHA-256: | BBD1CDA67E7756B47FD55683B8BFFC127B3E144C265068B414C1DAD77B8FCBB9 |
SHA-512: | AFEFAF14D0861105F3882AB66368780BD78462EFF2F7953BB4BFD2382CD5C4D4EDB9909676B2751D950B7F609C96398B888870C14FDCE3D2CF8C67650F9B8175 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.3023640712704525 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJf+dPeUkwRe9:YvXKXBROIPMSQWRuUhUyeG28Ukee9 |
MD5: | 16F104B9D30A25AD61731D8C9D5000DC |
SHA1: | BEAA6BC50E5439E882B545867E608CE3AA6DFFB6 |
SHA-256: | 9E34C5B5BB3AEA330EB0BCAFA3EF42DB7C8A57066F5FF73FAF6C30A0351340B5 |
SHA-512: | C8BE1E874F999011B93DCF6226F61D0149B48202DE5BD9536CE6386435FCB462E809546178715A67BEACCF4A8FC65E09E5F872A7CEB0FB4300F4749686A89173 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.299468370385592 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfbPtdPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGDV8Ukee9 |
MD5: | DE376CA60DBAC58E84D85FDB928C8203 |
SHA1: | DC6C4AE6314BE53B96F8D02981B51497E6D36D5D |
SHA-256: | CD7E733454B5AE01F49D026934E5E981E8928ED478006B2C4AFC537B4200DB7F |
SHA-512: | E330DC7CB2589CD3872C22B245292CACA90F3412A7ED26862E729B53988A77840A204870AD2A9476842764DE629165BDCD08C7FBC8E746BABD52B1D16231F8E1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.3033674555573445 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJf21rPeUkwRe9:YvXKXBROIPMSQWRuUhUyeG+16Ukee9 |
MD5: | 2EB421B2114C1A763FC021A6C45FD00C |
SHA1: | B2B1D8BFB7AAB6CF61F7DC53DB43EA99838050E3 |
SHA-256: | 5F4EA379B62C269BF9479D989C0CB157FE43A53E89FA648987D774C9BDBDFA8F |
SHA-512: | E7501708167F7E166AF8A36DD3BDCD48AB6914B6EE640F5AA8DD9C625767A143BC65BC777AF7B10121D84BD07291F6B2F4147C1AF25771889FB43EAC09E4EB07 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2034 |
Entropy (8bit): | 5.838798012991005 |
Encrypted: | false |
SSDEEP: | 48:YvERUSRUkBgnmQUIG48j/SiyaAOumRlQDcSmjWAK:GarRUegnTUb4+/ZrumPQoSmC |
MD5: | 16F6E94E6249642D8BBEAF81D8995658 |
SHA1: | 098531D778B117BEBEA0A1E66140CDB86733F569 |
SHA-256: | A15BCB015AC55F9B8236ED828E6B8916D8CC13B7E2D4E9E6042A4BF631A2C62A |
SHA-512: | 1DA4518F00B1F6A908792668822053A1936E48E5FBB04AA3F905041F6F41A89F208C7CF4C9AA3735D8D77ADFB8BC50FE5875970A43A1EFEF2F9B0B50C5EC3A37 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.276268072780025 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJfshHHrPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGUUUkee9 |
MD5: | 4B6F4C28244AE064CD28C4F4FB330EC0 |
SHA1: | 98C044DF83C7DCE072CD16A59DC4B8745983230F |
SHA-256: | E08E07AC38101BCD21F6BB0F912C9B07FC4CD8ACDE0E04DF03289C1876C99673 |
SHA-512: | A32FF3BA9F8A1798086DBBFD89690A470264E88B64B48ADCA7F79C89DECC82B23C66AAF4BDA52D7EE657D2965FCB8F3E1FB55EFAEC41557CCCB3E0E45D18D4CB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.286548662103999 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBR+PIP1G7+Q5IRR4UhUR0Y2hoAvJTqgFCrPeUkwRe9:YvXKXBROIPMSQWRuUhUyeGTq16Ukee9 |
MD5: | 9BD889A153E13E22ABB896F503794D7F |
SHA1: | 5D106CA7C520C90E9618DB756297C02BF4B1D52E |
SHA-256: | 36F72B32ECC28D3539013E7ABAFAB196E8C0D5216AE0A7B8785B2B6DC36169A6 |
SHA-512: | BCBD2BE411CBA659E367634A70444377BEDE56C256B86D67E1F61F531F743AA5A478FA632F77B9BE2D4097C0CCF13551755508AF5525BE294389944B3E2B2BE8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2815 |
Entropy (8bit): | 5.149906525637883 |
Encrypted: | false |
SSDEEP: | 48:Y5NVFnS9j3d/A1qZYACPyUJ6KDIuP29hj:4NPnS9Dd/AAZiPF6YIuEhj |
MD5: | 6A419D674E56ADAD4AD1D6C14FAD2F68 |
SHA1: | D22E2C053D730B50CD06F0E6167CF9408ABBE387 |
SHA-256: | 6646CE4A78CFAC9F74790C6FEC2902F603AADA2CDD440D5A35C2E957CD0604EE |
SHA-512: | E5A62407083B608385EFAFB3077B061FC94B1C18360FA18E1884CB9402F45825010329467056F3533C1B87F02F852E7694DAC93EEC1609C8CF011D63F2FA1795 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9893807419923418 |
Encrypted: | false |
SSDEEP: | 24:TLHRx/XYKQvGJF7urs67Y9QmQ6QeDgIcLESiAie7gF:TVl2GL7ms67YXtrDvcI8/8 |
MD5: | 79D75DC32A9D121E4C5E40B5F30572B3 |
SHA1: | A382AFE52DA75FE88442CE5323EBC3C5C680E095 |
SHA-256: | D9F78D0F6F7752A0716E55DC82AEB802D57F4F3C67B8122FB653520B36D7CF2B |
SHA-512: | 76BA51F4B0F92870266BC1352C0C007749EA6F7046ADF1A11002AD0FAE8E21AF9DEC41DD83D0793B265C81DC6ABFF34512F43DB1AF1B8556727D0D8F4C0B7479 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3450919096330873 |
Encrypted: | false |
SSDEEP: | 24:7+tAASY9QmQ6QeDg7cLESiAi0mY9Q6qLBx/XYKQvGJF7urse:7MAlYXtrDccI8KYDqll2GL7mse |
MD5: | 16944D7C02318B8A089F4ACFBF9610A1 |
SHA1: | E1EE863118865AD90A0CBFCFEAEA690B00CC61DB |
SHA-256: | 585DD03235A3260C948DF93D6E65D6B84612B61C73F7672BC4455621E5C4A897 |
SHA-512: | 91FC383FAFDF5068A2BCB1643223002AEF3825355A69DC18F801A2A32BBEBAD6EB4D65B9521DB0A35BAEC8139960F2A795350A8251893BC497B2346B2491352E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgeEohnqvQuJHkfH5ewjB0y8JPciYyu:6a6TZ44ADEYqLVkfZewAJciK |
MD5: | FC59A844F9A1933675874406C2762B5B |
SHA1: | 9279BE61785B2E9C86BCB206A777EF7206E6B97F |
SHA-256: | A74F899714AC149CA308A62B7E6001F0BEBBB4866806E23D89F865C8643D539E |
SHA-512: | 0736D9D311CBC20F88077449E955D89B056811982D03D7665C1198C3B197CB0F182BF2D602FC3E279642F71569F3AB0106C9AC79720F7C250213C259DB51CEA5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5213298467083405 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8+24l0ud:Qw946cPbiOxDlbYnuRKGod |
MD5: | 5AE3652156B8C7A08297DE6F72F61E46 |
SHA1: | 8CC09D4E6B8B06AC5932BF8FB87F330618D7A151 |
SHA-256: | 1B297D93028FCC4465C071D636628C2957D9A8306B586E393EA7D8D008B8080F |
SHA-512: | 1715BDC2B0DA6BFAD049FCB264A9ADCCC748718E54B6653D8EA02AC7CD58666CE53A26DC39AE64C7DB08FFBCA131AED78F856CF4FA97465038F8048332379108 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-02-15 09-29-38-746.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.353642815103214 |
Encrypted: | false |
SSDEEP: | 384:tbxtsuP+XEWJJQbnR8L31M7HeltV+KYm3wsa2KjF4ODkr/O8r2IUHUHMWwEyZRN2:aPL |
MD5: | 91F06491552FC977E9E8AF47786EE7C1 |
SHA1: | 8FEB27904897FFCC2BE1A985D479D7F75F11CEFC |
SHA-256: | 06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB |
SHA-512: | A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15070 |
Entropy (8bit): | 5.3830709039002596 |
Encrypted: | false |
SSDEEP: | 384:rauDuuW0kyJ5tDx0yKu1KUS3fUOkPJp8W5jtPHdIBk98SASMMfZtWdWHazJgGVt6:lHB |
MD5: | 68BBF3E25D3BCF3D7CB0E89CA8ED1122 |
SHA1: | 545555A8BB28B033A80281BC31F5F72D39B6992C |
SHA-256: | 54E4C695F06BB33A821DAD5C13CF469E3124A4194715D4B736092D24FCB25046 |
SHA-512: | F22CCB716D336F41E36559CE29633F067A77DCA7277679C4BDEEDC99C756C34792267913FFAAB47BC4F5837839FF678D3A83B1E376F32812CC0AF2C626B8B47E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.425795047419057 |
Encrypted: | false |
SSDEEP: | 192:0cbgIhPcbocbAIlncb2cbwI/RcbNcbQIVvcbNcbiIMicbp:fhWlA/TVPMh |
MD5: | F9CB6ADFF7FB7F77760B56689088CF39 |
SHA1: | 57AE41C37FBC05B77C91F346579A7F759FCD493D |
SHA-256: | F6B97914999614FA0BEA17DE00EDC8DE98F6A6F906C78CDE5509BA051BDCB5C6 |
SHA-512: | C3FB90305600C1A703D6D275D7A2837314DBFF9E0A7DB7A92C57D025C6E5468542BC6636119FFE5192E8ABC2A4DA8ED9907F4E4B14BBFDCEF0E18FA3334B0964 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:rBgI81ReWQ53+sQ3POSTJJJJEQ6T9UkRm1XX/FLYVbxrr/IxktOQZ1mau4yBwsOo:r+Tegs6lTJJJJv+9UZd1ybxrr/IxkB1m |
MD5: | 774036904FF86EB19FCE18B796528E1E |
SHA1: | 2BA0EBF3FC7BEF9EF5BFAD32070BD3C785904E16 |
SHA-256: | D2FC8EA3DDD3F095F7A469927179B408102471627C91275EDB4D7356F8E453AD |
SHA-512: | 9E9662EA15AE3345166C1E51235CDCE3123B27848E4A4651CC4D2173BDD973E4AD2F8994EFF34A221A9F07AA676F52BEB6D90FF374F6CCB0D06FA39C3EFE6B31 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:GP7ouWLaGZkweYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:BuWLaGZkweZGk3mlind9i4ufFXpAXkru |
MD5: | 390E79C9D2486640A3C67751AB478B71 |
SHA1: | C8B6FA71F9854BBAAE9853D3B2CC155792B28A26 |
SHA-256: | BC23B046107611ED7E8DA88E4DD5AE8914312B3881D3DD44CAD43FD5D8189F11 |
SHA-512: | 1013E86CEF72CF64140DB99A9F47F3EDB84F1AE04A9619E0764ED17E91C1BB7C80D405CCB0F4C01428EF7F65F127B19B1D441F7E9F445DA92B751AB934ABD989 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9885588257097133 |
Encrypted: | false |
SSDEEP: | 48:8s8doTMcJHWidAKZdA1FehwiZUklqehSy+3:8sLvm1y |
MD5: | 2DA2A0E6773899C24B4E6A8521B88F18 |
SHA1: | 9E1AF43CEBEAF5CC97E919D0660D0EBDA36FC340 |
SHA-256: | 7ECD4EC063DEAE8394D8879AA95F26AB4084581F117A34FEE22D3EF9F58EAA6A |
SHA-512: | FC40F10B193A0DCEF9C1013367C7294DD1BC2A5A9D3DB27665663CF8E2A90278F39C8E7C8EB35B5C8E2E9271F247D4C55D58E8C23B4800790B72478172CEFD9C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.003212343702335 |
Encrypted: | false |
SSDEEP: | 48:8h8doTMcJHWidAKZdA1seh/iZUkAQkqehly+2:8hLvg9Q4y |
MD5: | F44E0FFC55858BD41B5BD9AE7AA253E3 |
SHA1: | 68BC08310777E0750E274A5C2D074995E793153B |
SHA-256: | 0643F5CB3F7FE2DAA81D7AFD60B8DDF22B3416887C29CD66CB89FCC979EDA9D7 |
SHA-512: | CDABFF8229B0C1A72FE6E96394AE01A7ABA3B670734487B2B72F3E14C55022142E307237CA5ADA97A663E3657833B2765BA06CF8A1832B1D0739A712E8522D06 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.010518165479013 |
Encrypted: | false |
SSDEEP: | 48:8j8doTMcAHWidAKZdA14meh7sFiZUkmgqeh7sry+BX:8jLv3npy |
MD5: | 4E2C2D7FC05ECB816F4817E802777816 |
SHA1: | E6E6E1834043BD9A1B5EE7CE5798E3863E24200A |
SHA-256: | 7820C095979B880D36EBAE3B8E823383765CC575764F41D8B5BE3DF6522DFC7C |
SHA-512: | 70C51F53814B9024C55F05BE52B266AF798D1E85DBE6CCEB9069BFDC985B440CC708119BF5D6EED74BC93AAE56C027E7F611EA4A3CF58AF8B245644720009454 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9999741456054707 |
Encrypted: | false |
SSDEEP: | 48:8X08doTMcJHWidAKZdA1TehDiZUkwqehRy+R:8X0Lv7Ty |
MD5: | 52F403BCB9C5C5F5842E73ABAEE7D751 |
SHA1: | 17FAFA98EF3A8DA9A94D6AD49B466928508928A4 |
SHA-256: | 1BF2638072198FAF037D3A5BBEB2F9EDE50E14B6F3AD1E9F26F59BB9398AABB7 |
SHA-512: | 6EA9F6495185E4AEB1461A02F04F7148BFCCEE0061CD1433F33141C7A4A59F7AA5DC2DD4AE8D020A56C29D18873B81167249C5A85BFD7ED4BE2FF2A2923B0B6B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9876380519285033 |
Encrypted: | false |
SSDEEP: | 48:8p8doTMcJHWidAKZdA1dehBiZUk1W1qehfy+C:8pLv79/y |
MD5: | C7AD6F7217AB354D8623A314D3A98E7B |
SHA1: | CE79CBB5F71CCAFED65B6CF3FEDC8B8DA5157B1F |
SHA-256: | 83AED157256DD4253431555983379428D5785538D7FDC7A6BAF88A55DB52E4EF |
SHA-512: | 607C07467E7905DC60CA76802B973F1B744CD40624D4EC5810700DE1898CEF34368B45B58123ED8F2971420E6E960F12CB1B51E00FC3B16DC468AB274DF659C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.999478584754766 |
Encrypted: | false |
SSDEEP: | 48:8py8doTMcJHWidAKZdA1duTeehOuTbbiZUk5OjqehOuTbpy+yT+:8pyLvfTfTbxWOvTbpy7T |
MD5: | C86914A11E9BA7380AB54AA89AE4139E |
SHA1: | B8F37E0D22736182BF8F0C47D459331893974CF7 |
SHA-256: | 93F1049C4884B3634CB7D94498371E881C2D6C73547EEBC818ED2D128BC977EF |
SHA-512: | 457B122B67D1A929602960CAE5E1570AEA4784DD0CD978E617584CC3A4861DA6700F1278E37B5B3576CDCAE8435D84A3B558274760BC7A2061E2AE31CF86105C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
URL: | https://aadcdn.msauth.net/ests/2.1/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 61 |
Entropy (8bit): | 4.022997040570905 |
Encrypted: | false |
SSDEEP: | 3:yionv//thPlUWoA1xl/k4E08up:6v/lhPpl17Tp |
MD5: | 77E6A7DB9B0326AC29879AB8D0BF20B1 |
SHA1: | E5BD5C2D82463C6DC6DF8AF684DB826450DF845C |
SHA-256: | A47C8E093F0AEC3508ADE029F6A77DC5E1114C0B6A1379F171F728DB1AA6EADB |
SHA-512: | F98AEB454F52A5D666B0EDA52367E7C31908DED181881160F253CA95AE20566E4C41498EB374C970E2A2B90A76866D6767A9EDA1C034AF17324D6696EAFEFC96 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69597 |
Entropy (8bit): | 5.369216080582935 |
Encrypted: | false |
SSDEEP: | 1536:qNhEyjjTikEJO4edXXe9J578go6MWX2xkjVe4c4j2ll2Ac7pK3F71QDU8CuT:Exc2yjq4j2uYnQDU8CuT |
MD5: | 5F48FC77CAC90C4778FA24EC9C57F37D |
SHA1: | 9E89D1515BC4C371B86F4CB1002FD8E377C1829F |
SHA-256: | 9365920887B11B33A3DC4BA28A0F93951F200341263E3B9CEFD384798E4BE398 |
SHA-512: | CAB8C4AFA1D8E3A8B7856EE29AE92566D44CEEAD70C8D533F2C98A976D77D0E1D314719B5C6A473789D8C6B21EBB4B89A6B0EC2E1C9C618FB1437EBC77D3A269 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 85578 |
Entropy (8bit): | 5.366055229017455 |
Encrypted: | false |
SSDEEP: | 1536:EYE1JVoiB9JqZdXXe2pD3PgoIiulrUndZ6a4tfOR7WpfWBZ2BJda4w9W3qG9a986:v4J+OlfOhWppCW6G9a98Hr2 |
MD5: | 2F6B11A7E914718E0290410E85366FE9 |
SHA1: | 69BB69E25CA7D5EF0935317584E6153F3FD9A88C |
SHA-256: | 05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E |
SHA-512: | 0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB |
Malicious: | false |
URL: | https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 19188 |
Entropy (8bit): | 5.212814407014048 |
Encrypted: | false |
SSDEEP: | 384:+CbuG4xGNoDic2UjKPafxwC5b/4xQviOJU7QzxzivDdE3pcGdjkd/9jt3B+Kb964:zb4xGmiJfaf7gxQvVU7eziv+cSjknZ3f |
MD5: | 70D3FDA195602FE8B75E0097EED74DDE |
SHA1: | C3B977AA4B8DFB69D651E07015031D385DED964B |
SHA-256: | A52F7AA54D7BCAAFA056EE0A050262DFC5694AE28DEE8B4CAC3429AF37FF0D66 |
SHA-512: | 51AFFB5A8CFD2F93B473007F6987B19A0A1A0FB970DDD59EF45BD77A355D82ABBBD60468837A09823496411E797F05B1F962AE93C725ED4C00D514BA40269D14 |
Malicious: | false |
URL: | https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 621 |
Entropy (8bit): | 7.673946009263606 |
Encrypted: | false |
SSDEEP: | 12:Xp7fmqfW/e4YC2L0E5DZLB62y/+6lbPa1Gotq8mdd2Xmy2QLBwxD+QkCfBJ:Xp6qf2SCk3LBpy/rtPa1GKq8mOX5jLcD |
MD5: | 4761405717E938D7E7400BB15715DB1E |
SHA1: | 76FED7C229D353A27DB3257F5927C1EAF0AB8DE9 |
SHA-256: | F7ED91A1DAB5BB2802A7A3B3890DF4777588CCBE04903260FBA83E6E64C90DDF |
SHA-512: | E8DAC6F81EB4EBA2722E9F34DAF9B99548E5C40CCA93791FBEDA3DEBD8D6E401975FC1A75986C0E7262AFA1B9D1475E1008A89B92C8A7BEC84D8A917F221B4A2 |
Malicious: | false |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/signin-options_4e48046ce74f4b89d45037c90576bfac.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 61 |
Entropy (8bit): | 4.022997040570905 |
Encrypted: | false |
SSDEEP: | 3:yionv//thPlUWoA1xl/k4E08up:6v/lhPpl17Tp |
MD5: | 77E6A7DB9B0326AC29879AB8D0BF20B1 |
SHA1: | E5BD5C2D82463C6DC6DF8AF684DB826450DF845C |
SHA-256: | A47C8E093F0AEC3508ADE029F6A77DC5E1114C0B6A1379F171F728DB1AA6EADB |
SHA-512: | F98AEB454F52A5D666B0EDA52367E7C31908DED181881160F253CA95AE20566E4C41498EB374C970E2A2B90A76866D6767A9EDA1C034AF17324D6696EAFEFC96 |
Malicious: | false |
URL: | https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/d/9125fe502e1b5e5f/1739629802804/adcRnfq0rV6-Gl_ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48944 |
Entropy (8bit): | 5.272507874206726 |
Encrypted: | false |
SSDEEP: | 768:9VG5R15WbHVKZrycEHSYro34CrSLB6WU/6DqBf4l1B:9VIRuo53XiwWTvl1B |
MD5: | 14D449EB8876FA55E1EF3C2CC52B0C17 |
SHA1: | A9545831803B1359CFEED47E3B4D6BAE68E40E99 |
SHA-256: | E7ED36CEEE5450B4243BBC35188AFABDFB4280C7C57597001DE0ED167299B01B |
SHA-512: | 00D9069B9BD29AD0DAA0503F341D67549CCE28E888E1AFFD1A2A45B64A4C1BC460D81CFC4751857F991F2F4FB3D2572FD97FCA651BA0C2B0255530209B182F22 |
Malicious: | false |
URL: | https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85578 |
Entropy (8bit): | 5.366055229017455 |
Encrypted: | false |
SSDEEP: | 1536:EYE1JVoiB9JqZdXXe2pD3PgoIiulrUndZ6a4tfOR7WpfWBZ2BJda4w9W3qG9a986:v4J+OlfOhWppCW6G9a98Hr2 |
MD5: | 2F6B11A7E914718E0290410E85366FE9 |
SHA1: | 69BB69E25CA7D5EF0935317584E6153F3FD9A88C |
SHA-256: | 05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E |
SHA-512: | 0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5890 |
Entropy (8bit): | 5.829159167793922 |
Encrypted: | false |
SSDEEP: | 96:IilizH6666HwvjwDJy/BRODOJ/P/2dDIgK2UIj4rt/DjCezBbHPEP2GyRqYah4iT:jcH6666QkDmDO+GhLj4NjNlbvEOuN4od |
MD5: | E402C4CF1322F5FADAAC69B42E20BEF5 |
SHA1: | 9A6A88E90A8AC82676DDC282ECA28986ED4C92B3 |
SHA-256: | FE0C167F54FEA70E1EA00884A265C9A99D053400B9CA4E34954B521D1773178B |
SHA-512: | 75BC81728FD816C0F07FA59EC48331629CEA190C1B4A8240B93B888E58D2AAE321D5DE1E4CD1F4CA88640208950381E4704A2AD4C42CCC5141619D3976518C36 |
Malicious: | false |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 51039 |
Entropy (8bit): | 5.247253437401007 |
Encrypted: | false |
SSDEEP: | 768:E9Yw7GuJM+HV0cen/7Kh5rM7V4RxCKg8FW/xsXQUd+FiID65r48Hgp5HRl+:E9X7PMIM7V4R5LFAxTWyuHHgp5HRl+ |
MD5: | 67176C242E1BDC20603C878DEE836DF3 |
SHA1: | 27A71B00383D61EF3C489326B3564D698FC1227C |
SHA-256: | 56C12A125B021D21A69E61D7190CEFA168D6C28CE715265CEA1B3B0112D169C4 |
SHA-512: | 9FA75814E1B9F7DB38FE61A503A13E60B82D83DB8F4CE30351BD08A6B48C0D854BAF472D891AF23C443C8293380C2325C7B3361B708AF9971AA0EA09A25CDD0A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 553316 |
Entropy (8bit): | 4.912196464984696 |
Encrypted: | false |
SSDEEP: | 6144:TTWsY1akh5JWPJurgWLNW6VF7YlNbx1eX8jumoHL4owSKrthO4bQVw:Kay8oLLc6VF7eNyMjumoHL4owSKrcw |
MD5: | 722DEBEFD083ED4F4C27B632AEC2EBB3 |
SHA1: | 4CFDB8C72CE335E89992D2302F8C80DDF4C59AFB |
SHA-256: | 8BF73AA439FCDB3B09B7C892BC371169332E0A5B69538C98B9B0D1A39F205D4A |
SHA-512: | 156300E2763C445C83993C575691CA09D68542D0FAA3845BA368692029FE3D00E6AA6A323FD5323E53017392E61C24BC4E38F88B9ACBC58B40AA39F675D4D87E |
Malicious: | false |
URL: | https://5320986944-1317754460.cos.ap-singapore.myqcloud.com/bootstrap.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 69597 |
Entropy (8bit): | 5.369216080582935 |
Encrypted: | false |
SSDEEP: | 1536:qNhEyjjTikEJO4edXXe9J578go6MWX2xkjVe4c4j2ll2Ac7pK3F71QDU8CuT:Exc2yjq4j2uYnQDU8CuT |
MD5: | 5F48FC77CAC90C4778FA24EC9C57F37D |
SHA1: | 9E89D1515BC4C371B86F4CB1002FD8E377C1829F |
SHA-256: | 9365920887B11B33A3DC4BA28A0F93951F200341263E3B9CEFD384798E4BE398 |
SHA-512: | CAB8C4AFA1D8E3A8B7856EE29AE92566D44CEEAD70C8D533F2C98A976D77D0E1D314719B5C6A473789D8C6B21EBB4B89A6B0EC2E1C9C618FB1437EBC77D3A269 |
Malicious: | false |
URL: | https://code.jquery.com/jquery-3.2.1.slim.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 51039 |
Entropy (8bit): | 5.247253437401007 |
Encrypted: | false |
SSDEEP: | 768:E9Yw7GuJM+HV0cen/7Kh5rM7V4RxCKg8FW/xsXQUd+FiID65r48Hgp5HRl+:E9X7PMIM7V4R5LFAxTWyuHHgp5HRl+ |
MD5: | 67176C242E1BDC20603C878DEE836DF3 |
SHA1: | 27A71B00383D61EF3C489326B3564D698FC1227C |
SHA-256: | 56C12A125B021D21A69E61D7190CEFA168D6C28CE715265CEA1B3B0112D169C4 |
SHA-512: | 9FA75814E1B9F7DB38FE61A503A13E60B82D83DB8F4CE30351BD08A6B48C0D854BAF472D891AF23C443C8293380C2325C7B3361B708AF9971AA0EA09A25CDD0A |
Malicious: | false |
URL: | https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1864 |
Entropy (8bit): | 5.222032823730197 |
Encrypted: | false |
SSDEEP: | 48:yvswNIBLBpJawmMH44log6gw/MHm7pJroog6gwkMH9Xog6gwdMHdqdyqog7C:ykfXYx+odPcs9B |
MD5: | BC3D32A696895F78C19DF6C717586A5D |
SHA1: | 9191CB156A30A3ED79C44C0A16C95159E8FF689D |
SHA-256: | 0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68 |
SHA-512: | 8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64 |
Malicious: | false |
URL: | https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1864 |
Entropy (8bit): | 5.222032823730197 |
Encrypted: | false |
SSDEEP: | 48:yvswNIBLBpJawmMH44log6gw/MHm7pJroog6gwkMH9Xog6gwdMHdqdyqog7C:ykfXYx+odPcs9B |
MD5: | BC3D32A696895F78C19DF6C717586A5D |
SHA1: | 9191CB156A30A3ED79C44C0A16C95159E8FF689D |
SHA-256: | 0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68 |
SHA-512: | 8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32 |
Entropy (8bit): | 4.390319531114783 |
Encrypted: | false |
SSDEEP: | 3:HYmpBth0tYY:4mpbgYY |
MD5: | EB3CE3190D8A58E048D35E620747D3A5 |
SHA1: | 76B5B6461189F839B018EF5C785DB4836B818B7D |
SHA-256: | 2D670E2962D8D805B95912CACA0822CE7C6913636BA40373C6E6AEA73CAC8457 |
SHA-512: | 08F9C680B09CC25919A91F8E080CFC517F7354F49759DDC8CF6FFEB5ADE2E46F80A866E7531B6EA97188A5E4647093350F91ED51254351C47BCE3488EF88A595 |
Malicious: | false |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAlhSHdrYzQqjhIFDa0JrrESEAlDqT-QIEcedRIFDUPzdjk=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 553316 |
Entropy (8bit): | 4.912196464984696 |
Encrypted: | false |
SSDEEP: | 6144:TTWsY1akh5JWPJurgWLNW6VF7YlNbx1eX8jumoHL4owSKrthO4bQVw:Kay8oLLc6VF7eNyMjumoHL4owSKrcw |
MD5: | 722DEBEFD083ED4F4C27B632AEC2EBB3 |
SHA1: | 4CFDB8C72CE335E89992D2302F8C80DDF4C59AFB |
SHA-256: | 8BF73AA439FCDB3B09B7C892BC371169332E0A5B69538C98B9B0D1A39F205D4A |
SHA-512: | 156300E2763C445C83993C575691CA09D68542D0FAA3845BA368692029FE3D00E6AA6A323FD5323E53017392E61C24BC4E38F88B9ACBC58B40AA39F675D4D87E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 61 |
Entropy (8bit): | 3.990210155325004 |
Encrypted: | false |
SSDEEP: | 3:yionv//thPltV/CI7syxl/k4E08up:6v/lhPgI17Tp |
MD5: | 9246CCA8FC3C00F50035F28E9F6B7F7D |
SHA1: | 3AA538440F70873B574F40CD793060F53EC17A5D |
SHA-256: | C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84 |
SHA-512: | A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48139 |
Entropy (8bit): | 5.399746609631708 |
Encrypted: | false |
SSDEEP: | 768:nCbU/CNu5h5taq75KvO0fV9/KFeWlzQylfTDjVsgVX2bwDBslY1L8ep7K1oiSJvU:4Nu5h5taq7gGYV9yjcylh2bQs3 |
MD5: | 59306E15EB43DE76A56231E5E426EC80 |
SHA1: | 7606B8E4AEACE12B393AD6DCEBDF6D64BC7240E9 |
SHA-256: | 69865FE9BE4F6CDCED3CA8C047A486DB063F1179846F5EDFF395C39A7494FA34 |
SHA-512: | 99C5EE7567FECB0FD92C4622EE949975972FC46E165AA8E9FF719B3A64472F15E6A79EC83CA533C7305B70B35984B7980AC0552CE1169DBD1DC2C3C1F2D83F4B |
Malicious: | false |
URL: | https://challenges.cloudflare.com/turnstile/v0/b/324d0dcf743c/api.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 61 |
Entropy (8bit): | 3.990210155325004 |
Encrypted: | false |
SSDEEP: | 3:yionv//thPltV/CI7syxl/k4E08up:6v/lhPgI17Tp |
MD5: | 9246CCA8FC3C00F50035F28E9F6B7F7D |
SHA1: | 3AA538440F70873B574F40CD793060F53EC17A5D |
SHA-256: | C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84 |
SHA-512: | A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B |
Malicious: | false |
URL: | https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1746 |
Entropy (8bit): | 7.0941604123505115 |
Encrypted: | false |
SSDEEP: | 48:0OTCvdgy5wWh9XtNmtNvVII0Xk0t54tO31aUanH:09vdgy5d0vVvz0tuA8x |
MD5: | FF9BBAC9E01B1DDD59C87D1E8DD194D1 |
SHA1: | 018AD340A895FB021B57B3C08A4D88646F2981F1 |
SHA-256: | C28BD21CF6420D2282292B8FD5DF776B62B68C9681AEDC0D2E73D6444C0BF3A1 |
SHA-512: | CC7AEF1C346579FF31A504B82D719D73A15A895D08494AF0BA6905CD5DDF4B147FEA627E96AF4AAB8F177A84283F51F10FEF08C71C75851023A0ECF9A26A681E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 19188 |
Entropy (8bit): | 5.212814407014048 |
Encrypted: | false |
SSDEEP: | 384:+CbuG4xGNoDic2UjKPafxwC5b/4xQviOJU7QzxzivDdE3pcGdjkd/9jt3B+Kb964:zb4xGmiJfaf7gxQvVU7eziv+cSjknZ3f |
MD5: | 70D3FDA195602FE8B75E0097EED74DDE |
SHA1: | C3B977AA4B8DFB69D651E07015031D385DED964B |
SHA-256: | A52F7AA54D7BCAAFA056EE0A050262DFC5694AE28DEE8B4CAC3429AF37FF0D66 |
SHA-512: | 51AFFB5A8CFD2F93B473007F6987B19A0A1A0FB970DDD59EF45BD77A355D82ABBBD60468837A09823496411E797F05B1F962AE93C725ED4C00D514BA40269D14 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 621 |
Entropy (8bit): | 7.673946009263606 |
Encrypted: | false |
SSDEEP: | 12:Xp7fmqfW/e4YC2L0E5DZLB62y/+6lbPa1Gotq8mdd2Xmy2QLBwxD+QkCfBJ:Xp6qf2SCk3LBpy/rtPa1GKq8mOX5jLcD |
MD5: | 4761405717E938D7E7400BB15715DB1E |
SHA1: | 76FED7C229D353A27DB3257F5927C1EAF0AB8DE9 |
SHA-256: | F7ED91A1DAB5BB2802A7A3B3890DF4777588CCBE04903260FBA83E6E64C90DDF |
SHA-512: | E8DAC6F81EB4EBA2722E9F34DAF9B99548E5C40CCA93791FBEDA3DEBD8D6E401975FC1A75986C0E7262AFA1B9D1475E1008A89B92C8A7BEC84D8A917F221B4A2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 48139 |
Entropy (8bit): | 5.399746609631708 |
Encrypted: | false |
SSDEEP: | 768:nCbU/CNu5h5taq75KvO0fV9/KFeWlzQylfTDjVsgVX2bwDBslY1L8ep7K1oiSJvU:4Nu5h5taq7gGYV9yjcylh2bQs3 |
MD5: | 59306E15EB43DE76A56231E5E426EC80 |
SHA1: | 7606B8E4AEACE12B393AD6DCEBDF6D64BC7240E9 |
SHA-256: | 69865FE9BE4F6CDCED3CA8C047A486DB063F1179846F5EDFF395C39A7494FA34 |
SHA-512: | 99C5EE7567FECB0FD92C4622EE949975972FC46E165AA8E9FF719B3A64472F15E6A79EC83CA533C7305B70B35984B7980AC0552CE1169DBD1DC2C3C1F2D83F4B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 48944 |
Entropy (8bit): | 5.272507874206726 |
Encrypted: | false |
SSDEEP: | 768:9VG5R15WbHVKZrycEHSYro34CrSLB6WU/6DqBf4l1B:9VIRuo53XiwWTvl1B |
MD5: | 14D449EB8876FA55E1EF3C2CC52B0C17 |
SHA1: | A9545831803B1359CFEED47E3B4D6BAE68E40E99 |
SHA-256: | E7ED36CEEE5450B4243BBC35188AFABDFB4280C7C57597001DE0ED167299B01B |
SHA-512: | 00D9069B9BD29AD0DAA0503F341D67549CCE28E888E1AFFD1A2A45B64A4C1BC460D81CFC4751857F991F2F4FB3D2572FD97FCA651BA0C2B0255530209B182F22 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1746 |
Entropy (8bit): | 7.0941604123505115 |
Encrypted: | false |
SSDEEP: | 48:0OTCvdgy5wWh9XtNmtNvVII0Xk0t54tO31aUanH:09vdgy5d0vVvz0tuA8x |
MD5: | FF9BBAC9E01B1DDD59C87D1E8DD194D1 |
SHA1: | 018AD340A895FB021B57B3C08A4D88646F2981F1 |
SHA-256: | C28BD21CF6420D2282292B8FD5DF776B62B68C9681AEDC0D2E73D6444C0BF3A1 |
SHA-512: | CC7AEF1C346579FF31A504B82D719D73A15A895D08494AF0BA6905CD5DDF4B147FEA627E96AF4AAB8F177A84283F51F10FEF08C71C75851023A0ECF9A26A681E |
Malicious: | false |
URL: | https://cdn.jsdelivr.net/gh/pranaynamnaik/files@latest/micro-123787483.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 196 |
Entropy (8bit): | 5.098952451791238 |
Encrypted: | false |
SSDEEP: | 6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezocKqD:J0+oxBeRmR9etdzRxGez1T |
MD5: | 62962DAA1B19BBCC2DB10B7BFD531EA6 |
SHA1: | D64BAE91091EDA6A7532EBEC06AA70893B79E1F8 |
SHA-256: | 80C3FE2AE1062ABF56456F52518BD670F9EC3917B7F85E152B347AC6B6FAF880 |
SHA-512: | 9002A0475FDB38541E78048709006926655C726E93E823B84E2DBF5B53FD539A5342E7266447D23DB0E5528E27A19961B115B180C94F2272FF124C7E5C8304E7 |
Malicious: | false |
URL: | https://gastechnologypartnership.thesilkfactorycloudfileshub.click/favicon.ico |
Preview: |
File type: | |
Entropy (8bit): | 7.80404833720663 |
TrID: |
|
File name: | GasTechnologyPartnership.pdf |
File size: | 68'605 bytes |
MD5: | b032e18d6fc45f4d1ca894c6e203d5ce |
SHA1: | aa10156a60f0a1145bfc10788db7f26766d78986 |
SHA256: | 1083d09f6d3069e0c5ce4e0bf04418532237e411e59662e32039418c9f04078c |
SHA512: | 55c36ed9b057c62250806d528de4189908efe18d0198a41a194d5240d3e6d22b72a95a50eb0ea1f6075f7b95f515652cae8f51fdd11e647beede1cd327b31d8d |
SSDEEP: | 768:ygIDPBnp0Hln+lPi6WUhz+b0EV8JgZSK2xRxlxnf3xFCjQVJCkynhQ0Ph9bX9p9Y:4dPASK2/xPSjW4jbX/9Bx06DTyQHFmR |
TLSH: | 20639D178808ABCED16497C57F073D482A5F7750F1C469A2367DCA8F1B80E3A89D751E |
File Content Preview: | %PDF-1.7..%......1 0 obj..<</Type/Catalog/Pages 2 0 R/Lang(en-US) /StructTreeRoot 26 0 R/MarkInfo<</Marked true>>/Metadata 94 0 R/ViewerPreferences 95 0 R>>..endobj..2 0 obj..<</Type/Pages/Count 1/Kids[ 3 0 R] >>..endobj..3 0 obj..<</Type/Page/Parent 2 0 |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.7 |
Total Entropy: | 7.804048 |
Total Bytes: | 68605 |
Stream Entropy: | 7.882994 |
Stream Bytes: | 60408 |
Entropy outside Streams: | 5.268742 |
Bytes outside Streams: | 8197 |
Number of EOF found: | 2 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 35 |
endobj | 35 |
stream | 10 |
endstream | 10 |
xref | 2 |
trailer | 2 |
startxref | 2 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 1 |
/URI | 6 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Image Streams |
---|
ID | DHASH | MD5 | Preview |
---|---|---|---|
19 | cca66d5555558acc | 2ea40adc801642de7499a1ab11605616 | |
20 | cca66d5555558acc | 61d4b6efaf4ef250d34e1564825cf588 | |
21 | 6267756627352606 | 6e79e58153c6296a29f8ad34ada5bc3c | |
23 | b24d4c8e4c291382 | 0c9afa24b1235f5a043b61b3804e1e68 | |
24 | a2008000008000a2 | 2401d9dd5055c7c0fde0e1ba20666811 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 15, 2025 15:29:37.272316933 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Feb 15, 2025 15:29:37.584631920 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Feb 15, 2025 15:29:38.190610886 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Feb 15, 2025 15:29:39.396358013 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Feb 15, 2025 15:29:40.660672903 CET | 49690 | 80 | 192.168.2.16 | 2.23.77.188 |
Feb 15, 2025 15:29:40.660758972 CET | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Feb 15, 2025 15:29:41.809612036 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Feb 15, 2025 15:29:45.440160036 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Feb 15, 2025 15:29:45.741878033 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Feb 15, 2025 15:29:46.345635891 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Feb 15, 2025 15:29:46.613650084 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Feb 15, 2025 15:29:47.552644968 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Feb 15, 2025 15:29:49.905846119 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Feb 15, 2025 15:29:49.953689098 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Feb 15, 2025 15:29:50.033627987 CET | 49716 | 80 | 192.168.2.16 | 92.123.17.129 |
Feb 15, 2025 15:29:50.040080070 CET | 80 | 49716 | 92.123.17.129 | 192.168.2.16 |
Feb 15, 2025 15:29:50.040173054 CET | 49716 | 80 | 192.168.2.16 | 92.123.17.129 |
Feb 15, 2025 15:29:50.040260077 CET | 49716 | 80 | 192.168.2.16 | 92.123.17.129 |
Feb 15, 2025 15:29:50.045367002 CET | 80 | 49716 | 92.123.17.129 | 192.168.2.16 |
Feb 15, 2025 15:29:50.209682941 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Feb 15, 2025 15:29:50.640671968 CET | 80 | 49716 | 92.123.17.129 | 192.168.2.16 |
Feb 15, 2025 15:29:50.640686989 CET | 80 | 49716 | 92.123.17.129 | 192.168.2.16 |
Feb 15, 2025 15:29:50.640741110 CET | 49716 | 80 | 192.168.2.16 | 92.123.17.129 |
Feb 15, 2025 15:29:50.812695980 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Feb 15, 2025 15:29:52.026732922 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Feb 15, 2025 15:29:54.441837072 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Feb 15, 2025 15:29:54.758708954 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Feb 15, 2025 15:29:56.226032972 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Feb 15, 2025 15:29:57.877121925 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:57.877151012 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:57.877754927 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:57.881026983 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:57.881040096 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.349854946 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.350188971 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.350205898 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.351854086 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.351918936 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.353866100 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.353987932 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.354099035 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.354110003 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.407691002 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.502720118 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.502842903 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.502944946 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.503479958 CET | 49763 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.503495932 CET | 443 | 49763 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.523068905 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.523122072 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.523262024 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.523494005 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.523509979 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.983036041 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.983351946 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.983398914 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.983874083 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.984179020 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:58.984265089 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:58.984354019 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:59.027354956 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.140007973 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.140075922 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.140111923 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.140150070 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.140161037 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:59.140235901 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.140274048 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:59.140317917 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.140367031 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:59.142119884 CET | 49771 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:29:59.142153978 CET | 443 | 49771 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:29:59.162159920 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.162206888 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.162292004 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.162516117 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.162534952 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.165113926 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.165127993 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.165196896 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.165421009 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.165433884 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.249700069 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Feb 15, 2025 15:29:59.625901937 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.626190901 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.626225948 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.627019882 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.627202034 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.627213001 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.627274990 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.627338886 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.628429890 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.628505945 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.628659010 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.628664017 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.628669024 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.628722906 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.629550934 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.629681110 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.629687071 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.629712105 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.677696943 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.677717924 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.677727938 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.725750923 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.747749090 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.747818947 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.747901917 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.748347998 CET | 49772 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.748390913 CET | 443 | 49772 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.750217915 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.750314951 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.750405073 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.750622988 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:29:59.750657082 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:29:59.812752962 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.812844038 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.812903881 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.812912941 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.812959909 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.813894033 CET | 49773 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.813913107 CET | 443 | 49773 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.825553894 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.825583935 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:29:59.825658083 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.825846910 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:29:59.825860023 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.205229998 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.205558062 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.205621958 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.206020117 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.206933975 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.207034111 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.207061052 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.247366905 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.249744892 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.302066088 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.302411079 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.302479029 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.303963900 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.304050922 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.304330111 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.304402113 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.304483891 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.326447010 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.326507092 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.326539993 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.326570988 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.326594114 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.326598883 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.326627970 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.326646090 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.326675892 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.327234030 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.327295065 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.328370094 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.328377962 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.331238031 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.331274986 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.331291914 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.331299067 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.331670046 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.345794916 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.345873117 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.393733978 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.413496971 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413590908 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413620949 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413677931 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413707018 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413707972 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.413738012 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413749933 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413764000 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.413788080 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.413906097 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.413943052 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.413953066 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.414009094 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.414037943 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.414055109 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.414082050 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415000916 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415034056 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415064096 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415070057 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.415096998 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415124893 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.415858030 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415883064 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415910006 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415916920 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.415949106 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.415977955 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.415996075 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.416045904 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.416059971 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.416101933 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.416960955 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.417012930 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.417064905 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.417090893 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.417119980 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.417167902 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.417355061 CET | 49779 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.417390108 CET | 443 | 49779 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.428484917 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.428528070 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.428606033 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.428939104 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.428956032 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.449342966 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.449393034 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.449461937 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.449704885 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.449726105 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.575268984 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.575371027 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.575454950 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.575534105 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.576183081 CET | 49780 | 443 | 192.168.2.16 | 151.101.1.229 |
Feb 15, 2025 15:30:00.576240063 CET | 443 | 49780 | 151.101.1.229 | 192.168.2.16 |
Feb 15, 2025 15:30:00.883935928 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.884196043 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.884222984 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.885236979 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.885296106 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.885579109 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.885639906 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.885720968 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.912734985 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.913028002 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.913044930 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.914495945 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.914558887 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.914890051 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.914971113 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.915034056 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.927330971 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.935702085 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.935724020 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.955327988 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.966697931 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:00.966722012 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:00.982691050 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.014705896 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.035161018 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035214901 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035247087 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035264969 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.035289049 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035325050 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.035331964 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035792112 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035830975 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035830975 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.035845995 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.035881042 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.035887003 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.039915085 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.039943933 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.039961100 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.039978027 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.040024996 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.040031910 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.094711065 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.121763945 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.121907949 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.121934891 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.121962070 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.121989012 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.122030973 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.122096062 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.122445107 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.122492075 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.122499943 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.122539043 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.122571945 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.122574091 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.122585058 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.122620106 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.122626066 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.123459101 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.123487949 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.123507977 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.123521090 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.123555899 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.123560905 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.123570919 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.123614073 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.123620987 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.124377012 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.124409914 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.124428034 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.124438047 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.124470949 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.124478102 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.124536037 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.124567032 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.124576092 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.125257015 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.125305891 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.125447035 CET | 49786 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.125462055 CET | 443 | 49786 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.129637003 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.129753113 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.129792929 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.129797935 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.129817963 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.129851103 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.129852057 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.129865885 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.129904985 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.130137920 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.130530119 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.130572081 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.130580902 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.134350061 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.134397030 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.134402990 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.134413958 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.134454012 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.171283007 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.171335936 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.171431065 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.171683073 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.171700001 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218004942 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218096972 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218143940 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218147039 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.218158960 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218204975 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.218225002 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218595028 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218638897 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218641043 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.218653917 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218688965 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.218698025 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218772888 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218810081 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.218818903 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218854904 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.218892097 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.218977928 CET | 49787 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.218990088 CET | 443 | 49787 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.224507093 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.224545956 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.224625111 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.224829912 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.224847078 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.650917053 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.651211977 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.651233912 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.651567936 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.651868105 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.651927948 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.652019978 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.685636044 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.685929060 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.685952902 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.687055111 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.687355995 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.687485933 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.687493086 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.687561989 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.695336103 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.728741884 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.809591055 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.809765100 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.809815884 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.810591936 CET | 49794 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.810611963 CET | 443 | 49794 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811038017 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811094046 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811126947 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811131001 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.811146021 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811184883 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.811189890 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811573029 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811625004 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.811630964 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811908960 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.811948061 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.811954021 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.813867092 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.813905001 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.813978910 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.814203024 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.814218998 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.820240974 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.820297956 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.820313931 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.872697115 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.872715950 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.906162024 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.906203985 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.906229019 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.906239033 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.906275988 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.906280994 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.906758070 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.906802893 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.906809092 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907299042 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907347918 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907351971 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.907360077 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907393932 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.907398939 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907432079 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907469034 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.907474041 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907922029 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907960892 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.907974958 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.907980919 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.908019066 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.908024073 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.908925056 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.908952951 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.908973932 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.908979893 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.909002066 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.909018040 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.909023046 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.909060001 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.909943104 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.946933985 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.946995020 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.947005033 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997292042 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997338057 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997345924 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.997359991 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997395992 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.997396946 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997410059 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997445107 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.997452021 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997490883 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997529030 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.997533083 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997541904 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.997569084 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.997567892 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.999211073 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.999268055 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:01.999274969 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:01.999984980 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.000047922 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.000053883 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.000087023 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.000207901 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.000262022 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.002656937 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.002720118 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.003598928 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.003637075 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.003669024 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.003674984 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.003696918 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.003709078 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.004484892 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.004539967 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.004643917 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.004688978 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.005384922 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.005446911 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.035754919 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.035830021 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.035872936 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.035923958 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.087713957 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.087831974 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.087882042 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.087913990 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.087939024 CET | 443 | 49793 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.087948084 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.087980032 CET | 49793 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.090358973 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.090411901 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.090486050 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.090776920 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.090796947 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.107847929 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.107881069 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.107944012 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.108165979 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.108181953 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.261693001 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.261718988 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.261796951 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.262135983 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.262145996 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.276161909 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.276474953 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.276504040 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.277633905 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.278003931 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.278148890 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.278177023 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.330868006 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.453003883 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.453181028 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.453273058 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.453933954 CET | 49800 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.453952074 CET | 443 | 49800 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.556710005 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.557286978 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.557324886 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.557791948 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.558058977 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.558140993 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.558185101 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.577475071 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.577677965 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.577693939 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.578155994 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.578424931 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.578511000 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.578528881 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.599338055 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.600749969 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.619340897 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.632777929 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.661322117 CET | 49809 | 443 | 192.168.2.16 | 216.58.206.36 |
Feb 15, 2025 15:30:02.661375046 CET | 443 | 49809 | 216.58.206.36 | 192.168.2.16 |
Feb 15, 2025 15:30:02.661468983 CET | 49809 | 443 | 192.168.2.16 | 216.58.206.36 |
Feb 15, 2025 15:30:02.661758900 CET | 49809 | 443 | 192.168.2.16 | 216.58.206.36 |
Feb 15, 2025 15:30:02.661771059 CET | 443 | 49809 | 216.58.206.36 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705351114 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705396891 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705434084 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705476046 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705516100 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705513000 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.705548048 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705600023 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705646038 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.705646038 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.705818892 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705856085 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705882072 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.705898046 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.705957890 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.705972910 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.735593081 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.735878944 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.735924959 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.736229897 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.736524105 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.736582041 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.736668110 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.736705065 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.736735106 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.741199970 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.741328001 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.741388083 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.742101908 CET | 49802 | 443 | 192.168.2.16 | 188.114.97.3 |
Feb 15, 2025 15:30:02.742139101 CET | 443 | 49802 | 188.114.97.3 | 192.168.2.16 |
Feb 15, 2025 15:30:02.759748936 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.759762049 CET | 49810 | 443 | 192.168.2.16 | 35.190.80.1 |
Feb 15, 2025 15:30:02.759777069 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.759799957 CET | 443 | 49810 | 35.190.80.1 | 192.168.2.16 |
Feb 15, 2025 15:30:02.759856939 CET | 49810 | 443 | 192.168.2.16 | 35.190.80.1 |
Feb 15, 2025 15:30:02.760178089 CET | 49810 | 443 | 192.168.2.16 | 35.190.80.1 |
Feb 15, 2025 15:30:02.760195017 CET | 443 | 49810 | 35.190.80.1 | 192.168.2.16 |
Feb 15, 2025 15:30:02.791968107 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792013884 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792104959 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792110920 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.792139053 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792155027 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792162895 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.792182922 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.792789936 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792836905 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792841911 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.792853117 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792891979 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.792891979 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792905092 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.792943954 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.793792963 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.793840885 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.793870926 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.793874979 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.793885946 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.793917894 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.793925047 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.794696093 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.794724941 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.794744968 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.794754982 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.794780016 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.794790030 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.794795036 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.794832945 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.794838905 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.795923948 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.795986891 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.795994997 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.839728117 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.878602982 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.878683090 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.878721952 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.878737926 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.878762007 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.878801107 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.878806114 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.878915071 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.878988028 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.878993034 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879034042 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879081011 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.879086018 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879132986 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.879275084 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879369974 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879417896 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.879424095 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879456997 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.879693031 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879750013 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.879906893 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879946947 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879956007 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.879961014 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.879987001 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.879987955 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.880001068 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.880033016 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.880045891 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.880045891 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.880052090 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.880072117 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.885977030 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.886046886 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.886065960 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.886109114 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.886131048 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.886173010 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.886181116 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.886185884 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.886213064 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.886293888 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.886337042 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.886861086 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.886917114 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.907254934 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907298088 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907332897 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907358885 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907361984 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.907396078 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907407999 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907413006 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.907442093 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.907470942 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907527924 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.907582998 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.907597065 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.912127972 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.912154913 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.912185907 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.912204981 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.912260056 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.921834946 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.921914101 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.921931982 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.921948910 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.922002077 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.922029018 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.922029018 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.922046900 CET | 443 | 49801 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.922087908 CET | 49801 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:02.999665022 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.999938965 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:02.999984026 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.000004053 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.000821114 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.000848055 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.000868082 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.000874043 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.000910997 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.000915051 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.001447916 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.001476049 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.001501083 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.001504898 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.001535892 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.001538992 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.002156973 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.002199888 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.002202988 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.002355099 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.002377033 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.002389908 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.002394915 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.002427101 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.003196955 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.003243923 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.003287077 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.003290892 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.003403902 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.003420115 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.003454924 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.003459930 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.003499031 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.004251957 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.004337072 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.004378080 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.004380941 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.045717955 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.089658022 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.089693069 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.089719057 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.089732885 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.089766979 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.089776993 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.089813948 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.089880943 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.089880943 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.090926886 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.091002941 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.091017008 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.091074944 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.091793060 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.091855049 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.091978073 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.092051029 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.092824936 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.092890978 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.093008995 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.093072891 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.094027996 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.094091892 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.094882965 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.094949007 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.095069885 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.095122099 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.095858097 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.095886946 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.095927954 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.095940113 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.095968962 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.096893072 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.096962929 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.096973896 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.097029924 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.098077059 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.098140001 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.177902937 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178002119 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178025961 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178052902 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178081989 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178116083 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178138018 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178199053 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178222895 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178267002 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178297997 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178350925 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178374052 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178431034 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178442955 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16 |
Feb 15, 2025 15:30:03.178507090 CET | 49807 | 443 | 192.168.2.16 | 104.18.94.41 |
Feb 15, 2025 15:30:03.178891897 CET | 443 | 49807 | 104.18.94.41 | 192.168.2.16< |