Windows
Analysis Report
injectorQWEEX.exe
Overview
General Information
Detection
PureLog Stealer, RedLine, zgRAT
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected PureLog Stealer
Yara detected RedLine Stealer
Yara detected zgRAT
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains very large array initializations
C2 URLs / IPs found in malware configuration
Joe Sandbox ML detected suspicious sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match
Classification
- System is w10x64native
injectorQWEEX.exe (PID: 1304 cmdline:
"C:\Users\ user\Deskt op\injecto rQWEEX.exe " MD5: D44DAF1BEEA1A9ED0CC2EEACD2BFBD5C) conhost.exe (PID: 7532 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
zgRAT | zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. | No Attribution |
{"C2 url": "45.15.156.127:23000"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
| |
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
Click to see the 7 entries |
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00D36370 |
Networking |
---|
Source: | URLs: |
Source: | TCP traffic: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Large array initialization: |
Source: | Code function: | 0_2_00D2C4D0 | |
Source: | Code function: | 0_2_00D28890 | |
Source: | Code function: | 0_2_00D274B0 | |
Source: | Code function: | 0_2_00D2EC50 | |
Source: | Code function: | 0_2_00D1A840 | |
Source: | Code function: | 0_2_00D26030 | |
Source: | Code function: | 0_2_00D2B030 | |
Source: | Code function: | 0_2_00D25C20 | |
Source: | Code function: | 0_2_00D2A1E0 | |
Source: | Code function: | 0_2_00D295E0 | |
Source: | Code function: | 0_2_00D19DB0 | |
Source: | Code function: | 0_2_00D3D151 | |
Source: | Code function: | 0_2_00D2B6C0 | |
Source: | Code function: | 0_2_00D2BA90 | |
Source: | Code function: | 0_2_00D156B0 | |
Source: | Code function: | 0_2_00D27660 | |
Source: | Code function: | 0_2_00D1DA10 | |
Source: | Code function: | 0_2_00D253D0 | |
Source: | Code function: | 0_2_00D26BC0 | |
Source: | Code function: | 0_2_00D29B10 | |
Source: | Code function: | 0_2_00D24B10 | |
Source: | Code function: | 0_2_00D26730 | |
Source: | Code function: | 0_2_00D2E730 | |
Source: | Code function: | 0_2_00D28F20 | |
Source: | Code function: | 0_2_00D26320 | |
Source: | Code function: | 0_2_03340870 | |
Source: | Code function: | 0_2_03340880 | |
Source: | Code function: | 0_2_03347668 | |
Source: | Code function: | 0_2_0334765A | |
Source: | Code function: | 0_2_069475B8 | |
Source: | Code function: | 0_2_0694A3F8 | |
Source: | Code function: | 0_2_0694A3EA | |
Source: | Code function: | 0_2_069481F8 |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00D3D874 | |
Source: | Code function: | 0_2_0334F4F1 | |
Source: | Code function: | 0_2_0694DF7C | |
Source: | Code function: | 0_2_06946FB0 | |
Source: | Code function: | 0_2_0694F290 | |
Source: | Code function: | 0_2_06946FB0 | |
Source: | Code function: | 0_2_06941C20 | |
Source: | Code function: | 0_2_06941BE0 | |
Source: | Code function: | 0_2_06941C00 | |
Source: | Code function: | 0_2_0694E891 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00D36370 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00D33BE6 |
Source: | Code function: | 0_2_00D385F3 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00D2FCEC | |
Source: | Code function: | 0_2_00D2F6B2 | |
Source: | Code function: | 0_2_00D33BE6 | |
Source: | Code function: | 0_2_00D2FB90 |
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 0_2_00D2FDF5 |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00D2FA77 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 2 Virtualization/Sandbox Evasion | OS Credential Dumping | 1 System Time Discovery | Remote Services | 11 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Disable or Modify Tools | LSASS Memory | 121 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 2 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 11 Deobfuscate/Decode Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 23 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
48% | Virustotal | Browse |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
⊘No contacted domains info
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
45.15.156.127 | unknown | Russian Federation | 39493 | RU-KSTVKolomnaGroupofcompaniesGuarantee-tvRU | true |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1630529 |
Start date and time: | 2025-03-06 01:31:32 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 128, Firefox 91, Adobe Reader DC 21, Java 8 Update 301 |
Number of analysed new started processes analysed: | 3 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | injectorQWEEX.exe (renamed file extension from bin to exe) |
Original Sample Name: | injectorQWEEX.bin |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@2/0@0/1 |
EGA Information: |
|
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe
- Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
⊘No simulations
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
45.15.156.127 | Get hash | malicious | PureLog Stealer, RedLine, zgRAT | Browse | ||
Get hash | malicious | PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | RedLine | Browse | |||
Get hash | malicious | RedLine | Browse | |||
Get hash | malicious | RedLine | Browse | |||
Get hash | malicious | RedLine | Browse | |||
Get hash | malicious | AsyncRAT, PureLog Stealer, RHADAMANTHYS, RedLine, XWorm, zgRAT | Browse | |||
Get hash | malicious | PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | RedLine | Browse | |||
Get hash | malicious | RedLine | Browse |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
RU-KSTVKolomnaGroupofcompaniesGuarantee-tvRU | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | GCleaner | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, XWorm | Browse |
| ||
Get hash | malicious | RedLine | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.760055303303282 |
TrID: |
|
File name: | injectorQWEEX.exe |
File size: | 934'664 bytes |
MD5: | d44daf1beea1a9ed0cc2eeacd2bfbd5c |
SHA1: | 22e54e3272ada9a1546e80e10ff73425da5e1ab5 |
SHA256: | b2fc6d0c50f49c03a0f7863ca82036d09a74a275080ae5aebe7131582a893612 |
SHA512: | b54f8231e974942dded54c3e79c9799b9b2cc519bc799f60f16173e6af8cb8443326b8efb35c5cf0a71459c3b2f2e0a8954d543e63b95a744824d6a4781607d9 |
SSDEEP: | 6144:zHRz7kru9osRQqaO16636YZE9sOjftfzgvbLn03pRrx5t6Fx9r+BWH:zHRkruzaqbF36Y+X7gvH0NX6X9FH |
TLSH: | D615E72A59A18781D7F2DEF2FF02D2A2CC600E55092978C2107EAD113FBD7C59662E1F |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........,l."..}k!Fl..UX._.].W.?P...!._..1-.Gg.....!....B<.....1.........H..r>....x..C..V<...7..>.....m[..vJc........PE..L....R.f... |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x41f6a8 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x661552DF [Tue Apr 9 14:38:23 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 512b765c31a25017956fa9f4e97cb280 |
Instruction |
---|
call 00007FA47911C5DCh |
jmp 00007FA47911C039h |
push ebp |
mov ebp, esp |
push 00000000h |
call dword ptr [0042E050h] |
push dword ptr [ebp+08h] |
call dword ptr [0042E04Ch] |
push C0000409h |
call dword ptr [0042E000h] |
push eax |
call dword ptr [0042E054h] |
pop ebp |
ret |
push ebp |
mov ebp, esp |
sub esp, 00000324h |
push 00000017h |
call dword ptr [0042E058h] |
test eax, eax |
je 00007FA47911C1C7h |
push 00000002h |
pop ecx |
int 29h |
mov dword ptr [004E2AB8h], eax |
mov dword ptr [004E2AB4h], ecx |
mov dword ptr [004E2AB0h], edx |
mov dword ptr [004E2AACh], ebx |
mov dword ptr [004E2AA8h], esi |
mov dword ptr [004E2AA4h], edi |
mov word ptr [004E2AD0h], ss |
mov word ptr [004E2AC4h], cs |
mov word ptr [004E2AA0h], ds |
mov word ptr [004E2A9Ch], es |
mov word ptr [004E2A98h], fs |
mov word ptr [004E2A94h], gs |
pushfd |
pop dword ptr [004E2AC8h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [004E2ABCh], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [004E2AC0h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [004E2ACCh], eax |
mov eax, dword ptr [ebp-00000324h] |
mov dword ptr [004E2A08h], 00010001h |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xe69c0 | 0x490 | .reloc |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe4000 | 0x1bb0 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0xe0970 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0xe08b0 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2e000 | 0x144 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x2cc33 | 0x2ce00 | b4b2b081585a241bb2d7651dc086f338 | False | 0.4371518105849582 | data | 6.630422795643705 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x2e000 | 0xb3d16 | 0xb3e00 | a7cf734e68283842a03da3401141de32 | False | 0.20539029925295343 | data | 5.067017537648892 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xe2000 | 0x1634 | 0xa00 | 6786cc10c58411a044b5ef5f478aa4eb | False | 0.17734375 | data | 2.3900382569267067 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0xe4000 | 0x1bb0 | 0x1c00 | 47ea251e016a565ea04ca6795fd0e530 | False | 0.7868303571428571 | data | 6.633302097796085 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
.reloc | 0xe6000 | 0x1000 | 0xd08 | 99697656d12293398a5cea0a221f3f25 | False | 0.3869904076738609 | data | 4.674874952161441 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
DLL | Import |
---|---|
KERNEL32.dll | GetCurrentProcess, GetModuleHandleA, K32GetModuleInformation, CreateFileA, CreateFileMappingA, MapViewOfFile, VirtualProtect, CloseHandle, FreeLibrary, VirtualAlloc, VirtualAllocEx, LoadLibraryA, GetProcAddress, lstrlenW, CreateThread, Sleep, WaitForSingleObject, FreeConsole, GetCurrentThreadId, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleW, WriteConsoleW, RaiseException, RtlUnwind, GetLastError, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, EncodePointer, GetStdHandle, WriteFile, GetModuleFileNameW, ExitProcess, GetModuleHandleExW, GetCommandLineA, GetCommandLineW, CompareStringW, LCMapStringW, HeapAlloc, HeapFree, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, SetStdHandle, GetFileType, GetStringTypeW, GetProcessHeap, HeapSize, HeapReAlloc, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, SetFilePointerEx, CreateFileW, DecodePointer |
ntdll.dll | AdjustElement, StreamlineOperation, ReconstructInstrument, ReconstructComponent, ImproveOperation, EnhanceResource, InnovatePart, OverhaulPart, InnovateOperation, ModifyConfiguration, ImproveResource, OverhaulPart, ReconstructLayer, StreamlineResource, ImproveResource, RefinePart, ReconfigureEndpoint, ImproveComponent, ReconfigureUnit, BuildPart, ReconstructUnit, InnovateResource, AdjustOperation, DeactivateLayer, PersonalizeFramework, DeactivateComponent, ImproveEndpoint, ModernizeEndpoint, ImproveOperation, InnovateConfiguration, StreamlineOperation, ModifyProtocol, StreamlineElement, OverhaulInstrument, ModifyConfiguration, ReconstructObject, AdjustComponent, RefinePart, ImproveConfiguration, ImproveOperation, RefinePart, ReconstructPart, EnhanceResource, ModifyDesire, UpdateLayer, StreamlineCapability, ReconfigureLayer, ImproveProtocol, BuildElement, ReconstructObject, ModifyConfiguration, ReconstructPart, ModifyOperation, AdjustElement, ModernizePart, StreamlineArtifact |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 6, 2025 01:33:46.260256052 CET | 49751 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:46.568438053 CET | 23000 | 49751 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:47.075937986 CET | 49751 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:47.383599997 CET | 23000 | 49751 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:47.888261080 CET | 49751 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:48.199728012 CET | 23000 | 49751 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:48.700661898 CET | 49751 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:49.011476994 CET | 23000 | 49751 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:49.513227940 CET | 49751 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:49.821636915 CET | 23000 | 49751 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:49.941736937 CET | 49752 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:50.250056028 CET | 23000 | 49752 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:50.762712002 CET | 49752 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:51.070544004 CET | 23000 | 49752 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:51.575184107 CET | 49752 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:51.883517981 CET | 23000 | 49752 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:52.387331963 CET | 49752 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:52.702047110 CET | 23000 | 49752 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:53.215501070 CET | 49752 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:53.523829937 CET | 23000 | 49752 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:53.924940109 CET | 49753 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:54.233541965 CET | 23000 | 49753 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:54.746382952 CET | 49753 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:55.054595947 CET | 23000 | 49753 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:55.558792114 CET | 49753 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:55.867587090 CET | 23000 | 49753 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:56.370901108 CET | 49753 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:56.679347038 CET | 23000 | 49753 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:57.183269024 CET | 49753 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:57.491744041 CET | 23000 | 49753 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:57.501349926 CET | 49754 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:57.810534954 CET | 23000 | 49754 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:58.323811054 CET | 49754 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:58.632894039 CET | 23000 | 49754 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:59.135880947 CET | 49754 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:33:59.444493055 CET | 23000 | 49754 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:33:59.948056936 CET | 49754 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:00.256937027 CET | 23000 | 49754 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:00.760404110 CET | 49754 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:01.069154024 CET | 23000 | 49754 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:01.076314926 CET | 49755 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:01.384622097 CET | 23000 | 49755 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:01.885286093 CET | 49755 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:02.193361998 CET | 23000 | 49755 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:02.697544098 CET | 49755 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:03.006416082 CET | 23000 | 49755 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:03.509993076 CET | 49755 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:03.818763018 CET | 23000 | 49755 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:04.322390079 CET | 49755 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:04.631614923 CET | 23000 | 49755 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:04.640007019 CET | 49756 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:04.948561907 CET | 23000 | 49756 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:05.462654114 CET | 49756 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:05.771481037 CET | 23000 | 49756 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:06.274727106 CET | 49756 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:06.582602978 CET | 23000 | 49756 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:07.087049007 CET | 49756 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:07.395421982 CET | 23000 | 49756 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:07.899501085 CET | 49756 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:08.207469940 CET | 23000 | 49756 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:08.214624882 CET | 49757 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:08.523180962 CET | 23000 | 49757 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:09.024108887 CET | 49757 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:09.332771063 CET | 23000 | 49757 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:09.836525917 CET | 49757 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:10.145358086 CET | 23000 | 49757 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:10.648780107 CET | 49757 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:10.957269907 CET | 23000 | 49757 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:11.461056948 CET | 49757 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:11.769469976 CET | 23000 | 49757 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:11.776958942 CET | 49758 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:12.085585117 CET | 23000 | 49758 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:12.585844040 CET | 49758 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:12.894085884 CET | 23000 | 49758 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:13.398382902 CET | 49758 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:13.706990004 CET | 23000 | 49758 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:14.210572004 CET | 49758 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:14.521014929 CET | 23000 | 49758 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:15.022748947 CET | 49758 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:15.331090927 CET | 23000 | 49758 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:15.338243961 CET | 49759 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:15.647948027 CET | 23000 | 49759 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:16.163234949 CET | 49759 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:16.471645117 CET | 23000 | 49759 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:16.975425005 CET | 49759 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:17.283730030 CET | 23000 | 49759 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:17.787990093 CET | 49759 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:18.096535921 CET | 23000 | 49759 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:18.600076914 CET | 49759 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:18.908483982 CET | 23000 | 49759 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:18.918813944 CET | 49760 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:19.230405092 CET | 23000 | 49760 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:19.740609884 CET | 49760 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:20.049590111 CET | 23000 | 49760 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:20.552793026 CET | 49760 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:20.861399889 CET | 23000 | 49760 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:21.365062952 CET | 49760 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:21.674352884 CET | 23000 | 49760 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:22.177522898 CET | 49760 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:22.486278057 CET | 23000 | 49760 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:22.560453892 CET | 49762 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:22.868495941 CET | 23000 | 49762 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:23.380611897 CET | 49762 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:23.689790964 CET | 23000 | 49762 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:24.192766905 CET | 49762 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:24.504163027 CET | 23000 | 49762 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:25.004925013 CET | 49762 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:25.313411951 CET | 23000 | 49762 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:25.817457914 CET | 49762 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:26.126030922 CET | 23000 | 49762 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:26.133785963 CET | 49763 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:26.442600965 CET | 23000 | 49763 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:26.957633018 CET | 49763 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:27.266216993 CET | 23000 | 49763 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:27.769889116 CET | 49763 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:28.080929041 CET | 23000 | 49763 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:28.582110882 CET | 49763 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:28.890399933 CET | 23000 | 49763 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:29.394423962 CET | 49763 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:29.703129053 CET | 23000 | 49763 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:29.710443020 CET | 49764 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:30.018903017 CET | 23000 | 49764 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:30.519543886 CET | 49764 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:30.829497099 CET | 23000 | 49764 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:31.331607103 CET | 49764 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:31.640170097 CET | 23000 | 49764 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:32.143891096 CET | 49764 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:32.453941107 CET | 23000 | 49764 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:32.956324100 CET | 49764 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:33.265652895 CET | 23000 | 49764 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:33.273041964 CET | 49765 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:33.581975937 CET | 23000 | 49765 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:34.096537113 CET | 49765 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:34.405142069 CET | 23000 | 49765 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:34.909143925 CET | 49765 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:35.217994928 CET | 23000 | 49765 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:35.721128941 CET | 49765 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:36.029512882 CET | 23000 | 49765 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:36.533641100 CET | 49765 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:36.842446089 CET | 23000 | 49765 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:36.851358891 CET | 49766 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:37.159831047 CET | 23000 | 49766 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:37.673986912 CET | 49766 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:37.982647896 CET | 23000 | 49766 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:38.486550093 CET | 49766 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:38.794600964 CET | 23000 | 49766 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:39.298604012 CET | 49766 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:39.607988119 CET | 23000 | 49766 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:40.110812902 CET | 49766 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:40.420121908 CET | 23000 | 49766 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:40.427316904 CET | 49767 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:40.735925913 CET | 23000 | 49767 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:41.251363993 CET | 49767 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:41.559858084 CET | 23000 | 49767 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:42.063805103 CET | 49767 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:42.371995926 CET | 23000 | 49767 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:42.875745058 CET | 49767 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:43.184511900 CET | 23000 | 49767 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:43.688237906 CET | 49767 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:43.997178078 CET | 23000 | 49767 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:44.004745960 CET | 49768 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:44.313281059 CET | 23000 | 49768 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:44.828603029 CET | 49768 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:45.136734009 CET | 23000 | 49768 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:45.640805960 CET | 49768 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:45.949681997 CET | 23000 | 49768 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:46.453304052 CET | 49768 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:46.761913061 CET | 23000 | 49768 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:47.265655041 CET | 49768 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:47.575424910 CET | 23000 | 49768 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:47.583117962 CET | 49769 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:47.892446041 CET | 23000 | 49769 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:48.405926943 CET | 49769 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:48.714700937 CET | 23000 | 49769 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:49.218274117 CET | 49769 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:49.527512074 CET | 23000 | 49769 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:50.030436993 CET | 49769 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:50.340220928 CET | 23000 | 49769 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:50.842875957 CET | 49769 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:51.151645899 CET | 23000 | 49769 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:51.219878912 CET | 49770 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:51.528294086 CET | 23000 | 49770 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:52.030190945 CET | 49770 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:52.338699102 CET | 23000 | 49770 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:52.842597008 CET | 49770 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:53.151701927 CET | 23000 | 49770 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:53.654572010 CET | 49770 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:53.962963104 CET | 23000 | 49770 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:54.467040062 CET | 49770 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:54.776451111 CET | 23000 | 49770 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:54.783474922 CET | 49771 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:55.091953039 CET | 23000 | 49771 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:55.607589960 CET | 49771 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:55.916030884 CET | 23000 | 49771 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:56.419600964 CET | 49771 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:56.734586000 CET | 23000 | 49771 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:57.247637987 CET | 49771 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:57.555887938 CET | 23000 | 49771 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:58.060122967 CET | 49771 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:58.368673086 CET | 23000 | 49771 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:58.378025055 CET | 49772 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:58.686469078 CET | 23000 | 49772 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:34:59.200356007 CET | 49772 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:34:59.513046026 CET | 23000 | 49772 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:00.028145075 CET | 49772 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:00.337341070 CET | 23000 | 49772 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:00.840883017 CET | 49772 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:01.149610043 CET | 23000 | 49772 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:01.652838945 CET | 49772 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:01.961571932 CET | 23000 | 49772 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:01.969779015 CET | 49773 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:02.278867006 CET | 23000 | 49773 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:02.793298960 CET | 49773 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:03.102046967 CET | 23000 | 49773 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:03.605487108 CET | 49773 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:03.913990021 CET | 23000 | 49773 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:04.417901993 CET | 49773 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:04.726490021 CET | 23000 | 49773 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:05.230334997 CET | 49773 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:05.539526939 CET | 23000 | 49773 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:05.547405005 CET | 49774 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:05.855709076 CET | 23000 | 49774 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:06.370517969 CET | 49774 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:06.678921938 CET | 23000 | 49774 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:07.183111906 CET | 49774 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:07.490928888 CET | 23000 | 49774 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:07.995122910 CET | 49774 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:08.303610086 CET | 23000 | 49774 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:08.807487965 CET | 49774 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:09.115925074 CET | 23000 | 49774 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:09.122904062 CET | 49775 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:09.427083015 CET | 23000 | 49775 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:09.932416916 CET | 49775 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:10.239869118 CET | 23000 | 49775 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:10.744447947 CET | 49775 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:11.048676014 CET | 23000 | 49775 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:11.557010889 CET | 49775 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:11.861144066 CET | 23000 | 49775 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:12.369311094 CET | 49775 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:12.674632072 CET | 23000 | 49775 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:12.682158947 CET | 49776 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:12.991143942 CET | 23000 | 49776 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:13.494066954 CET | 49776 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:13.805493116 CET | 23000 | 49776 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:14.306312084 CET | 49776 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:14.614883900 CET | 23000 | 49776 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:15.118457079 CET | 49776 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:15.426928997 CET | 23000 | 49776 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:15.931277037 CET | 49776 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:16.240864038 CET | 23000 | 49776 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:16.249454021 CET | 49777 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:16.558924913 CET | 23000 | 49777 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:17.071135998 CET | 49777 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:17.381014109 CET | 23000 | 49777 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:17.883709908 CET | 49777 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:18.192285061 CET | 23000 | 49777 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:18.695780039 CET | 49777 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:19.004160881 CET | 23000 | 49777 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:19.508104086 CET | 49777 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:19.816724062 CET | 23000 | 49777 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:19.825490952 CET | 49778 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:20.133706093 CET | 23000 | 49778 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:20.648551941 CET | 49778 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:20.958523035 CET | 23000 | 49778 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:21.460784912 CET | 49778 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:21.768950939 CET | 23000 | 49778 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:22.273370028 CET | 49778 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:22.581733942 CET | 23000 | 49778 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:23.085429907 CET | 49778 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:23.394407988 CET | 23000 | 49778 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:23.402196884 CET | 49779 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:23.710877895 CET | 23000 | 49779 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:24.225843906 CET | 49779 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:24.534132004 CET | 23000 | 49779 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:25.038089991 CET | 49779 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:25.347310066 CET | 23000 | 49779 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:25.850707054 CET | 49779 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:26.159225941 CET | 23000 | 49779 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:26.662862062 CET | 49779 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:26.971196890 CET | 23000 | 49779 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:26.981538057 CET | 49780 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:27.290307045 CET | 23000 | 49780 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:27.803096056 CET | 49780 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:28.111787081 CET | 23000 | 49780 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:28.615571022 CET | 49780 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:28.924285889 CET | 23000 | 49780 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:29.427684069 CET | 49780 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:29.736465931 CET | 23000 | 49780 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:30.240358114 CET | 49780 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:30.549597979 CET | 23000 | 49780 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:30.556804895 CET | 49781 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:30.867064953 CET | 23000 | 49781 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:31.380728006 CET | 49781 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:31.689551115 CET | 23000 | 49781 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:32.192981005 CET | 49781 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:32.501247883 CET | 23000 | 49781 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:33.005029917 CET | 49781 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:33.313497066 CET | 23000 | 49781 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:33.817389965 CET | 49781 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:34.126672983 CET | 23000 | 49781 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:34.133903027 CET | 49782 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:34.442348003 CET | 23000 | 49782 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:34.957901001 CET | 49782 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:35.275947094 CET | 23000 | 49782 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:35.785742044 CET | 49782 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:36.094522953 CET | 23000 | 49782 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:36.598464012 CET | 49782 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:36.907161951 CET | 23000 | 49782 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:37.410634041 CET | 49782 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:37.719089031 CET | 23000 | 49782 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:37.801599979 CET | 49783 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:38.110846996 CET | 23000 | 49783 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:38.613250017 CET | 49783 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:38.922041893 CET | 23000 | 49783 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:39.425482988 CET | 49783 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:39.734322071 CET | 23000 | 49783 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:40.237984896 CET | 49783 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:40.548976898 CET | 23000 | 49783 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:41.057332039 CET | 49783 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:41.365833998 CET | 23000 | 49783 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:41.374358892 CET | 49784 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:41.682560921 CET | 23000 | 49784 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:42.190685034 CET | 49784 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:42.498558998 CET | 23000 | 49784 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:43.003106117 CET | 49784 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:43.311523914 CET | 23000 | 49784 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:43.815067053 CET | 49784 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:44.123574018 CET | 23000 | 49784 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:44.627376080 CET | 49784 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:44.936410904 CET | 23000 | 49784 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:44.943337917 CET | 49785 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:45.251214981 CET | 23000 | 49785 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:45.752166986 CET | 49785 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:46.060405016 CET | 23000 | 49785 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:46.564440012 CET | 49785 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:46.872437954 CET | 23000 | 49785 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:47.376776934 CET | 49785 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:47.685388088 CET | 23000 | 49785 | 45.15.156.127 | 192.168.11.20 |
Mar 6, 2025 01:35:48.189074039 CET | 49785 | 23000 | 192.168.11.20 | 45.15.156.127 |
Mar 6, 2025 01:35:48.496948957 CET | 23000 | 49785 | 45.15.156.127 | 192.168.11.20 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 19:33:38 |
Start date: | 05/03/2025 |
Path: | C:\Users\user\Desktop\injectorQWEEX.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd10000 |
File size: | 934'664 bytes |
MD5 hash: | D44DAF1BEEA1A9ED0CC2EEACD2BFBD5C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 19:33:38 |
Start date: | 05/03/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60fc60000 |
File size: | 875'008 bytes |
MD5 hash: | 81CA40085FC75BABD2C91D18AA9FFA68 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |