Windows
Analysis Report
zXtG0a5Gt0.exe
Overview
General Information
Sample name: | zXtG0a5Gt0.exerenamed because original name is a hash value |
Original sample name: | dc3657abea2cc9c36a8f7a7cf4f61a22ba2172bd1040c229d5b2cdd8af10bff0.exe |
Analysis ID: | 1631786 |
MD5: | 89757ce41562cf1c80dbc27625d64cbb |
SHA1: | 2ba3c337f490e647361869e54116f08aa190a983 |
SHA256: | dc3657abea2cc9c36a8f7a7cf4f61a22ba2172bd1040c229d5b2cdd8af10bff0 |
Tags: | exeuser-adrian__luca |
Infos: | |
Detection
XWorm
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Drops script at startup location
Yara detected AntiVM3
Yara detected XWorm
.NET source code contains potential unpacker
C2 URLs / IPs found in malware configuration
Drops VBS files to the startup folder
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Sample uses string decryption to hide its real strings
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Writes to foreign memory regions
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara signature match
Classification
- System is w10x64
zXtG0a5Gt0.exe (PID: 7912 cmdline:
"C:\Users\ user\Deskt op\zXtG0a5 Gt0.exe" MD5: 89757CE41562CF1C80DBC27625D64CBB) InstallUtil.exe (PID: 7632 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57) WerFault.exe (PID: 3484 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 7 632 -s 908 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
{"C2 url": ["147.124.212.231"], "Aes key": "6262", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.6"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
Click to see the 6 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
Click to see the 9 entries |
Data Obfuscation |
---|
Source: | Author: Joe Security: |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 1_2_0612CFE5 | |
Source: | Code function: | 1_2_0612D1E7 | |
Source: | Code function: | 1_2_06203668 | |
Source: | Code function: | 1_2_06203678 | |
Source: | Code function: | 1_2_0620374E |
Networking |
---|
Source: | URLs: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 1_2_055F7130 | |
Source: | Code function: | 1_2_055FA988 | |
Source: | Code function: | 1_2_055F712A | |
Source: | Code function: | 1_2_055FA982 |
Source: | Code function: | 1_2_04A42C69 | |
Source: | Code function: | 1_2_04A426E8 | |
Source: | Code function: | 1_2_04A426D8 | |
Source: | Code function: | 1_2_055F38C8 | |
Source: | Code function: | 1_2_055F8EC8 | |
Source: | Code function: | 1_2_055F003A | |
Source: | Code function: | 1_2_055F38B8 | |
Source: | Code function: | 1_2_055F8EB9 | |
Source: | Code function: | 1_2_06009763 | |
Source: | Code function: | 1_2_06005A28 | |
Source: | Code function: | 1_2_06001F59 | |
Source: | Code function: | 1_2_06001F68 | |
Source: | Code function: | 1_2_0600DC7F | |
Source: | Code function: | 1_2_0600DC90 | |
Source: | Code function: | 1_2_06007DF0 | |
Source: | Code function: | 1_2_06045C48 | |
Source: | Code function: | 1_2_06043082 | |
Source: | Code function: | 1_2_06043088 | |
Source: | Code function: | 1_2_060422AA | |
Source: | Code function: | 1_2_060422F8 | |
Source: | Code function: | 1_2_06070E21 | |
Source: | Code function: | 1_2_06070E30 | |
Source: | Code function: | 1_2_0607E288 | |
Source: | Code function: | 1_2_060772F3 | |
Source: | Code function: | 1_2_06077300 | |
Source: | Code function: | 1_2_060779B7 | |
Source: | Code function: | 1_2_06128FF8 | |
Source: | Code function: | 1_2_0612E4B0 | |
Source: | Code function: | 1_2_0612F1A8 | |
Source: | Code function: | 1_2_0612F62E | |
Source: | Code function: | 1_2_0612E4A1 | |
Source: | Code function: | 1_2_0612F197 | |
Source: | Code function: | 1_2_06143428 | |
Source: | Code function: | 1_2_06146C78 | |
Source: | Code function: | 1_2_0614B278 | |
Source: | Code function: | 1_2_06148E70 | |
Source: | Code function: | 1_2_06148E80 | |
Source: | Code function: | 1_2_06146C69 | |
Source: | Code function: | 1_2_0614A560 | |
Source: | Code function: | 1_2_06141590 | |
Source: | Code function: | 1_2_061415A0 | |
Source: | Code function: | 1_2_0614A560 | |
Source: | Code function: | 1_2_06144B18 | |
Source: | Code function: | 1_2_06140006 | |
Source: | Code function: | 1_2_06140040 | |
Source: | Code function: | 1_2_0620B020 | |
Source: | Code function: | 1_2_0620B030 | |
Source: | Code function: | 1_2_06201AA2 | |
Source: | Code function: | 1_2_06201AB0 | |
Source: | Code function: | 1_2_062176C0 | |
Source: | Code function: | 1_2_06219858 | |
Source: | Code function: | 1_2_0621D9E0 | |
Source: | Code function: | 1_2_062176B0 | |
Source: | Code function: | 1_2_0621A540 | |
Source: | Code function: | 1_2_0621A550 | |
Source: | Code function: | 1_2_0621001F | |
Source: | Code function: | 1_2_0621EFDB | |
Source: | Code function: | 1_2_0621DD07 | |
Source: | Code function: | 1_2_0621984B | |
Source: | Code function: | 1_2_0652FB40 | |
Source: | Code function: | 1_2_0652F890 | |
Source: | Code function: | 1_2_0652DF78 | |
Source: | Code function: | 1_2_06510040 | |
Source: | Code function: | 1_2_0652E418 | |
Source: | Code function: | 1_2_06510006 | |
Source: | Code function: | 1_2_06045C43 | |
Source: | Code function: | 6_2_012E12D8 |
Source: | Process created: |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 1_2_055F976C | |
Source: | Code function: | 1_2_055F7399 | |
Source: | Code function: | 1_2_055F8E79 | |
Source: | Code function: | 1_2_055F72E9 | |
Source: | Code function: | 1_2_06074F15 | |
Source: | Code function: | 1_2_06120C41 | |
Source: | Code function: | 1_2_06120C39 | |
Source: | Code function: | 1_2_061468B8 | |
Source: | Code function: | 1_2_06213783 | |
Source: | Code function: | 1_2_06213EB0 | |
Source: | Code function: | 1_2_06212FD6 | |
Source: | Code function: | 1_2_06213D78 | |
Source: | Code function: | 1_2_065136BA |
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | 1 Scheduled Task/Job | 1 Scripting | 211 Process Injection | 1 Masquerading | OS Credential Dumping | 211 Security Software Discovery | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Disable or Modify Tools | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 2 Registry Run Keys / Startup Folder | 2 Registry Run Keys / Startup Folder | 41 Virtualization/Sandbox Evasion | Security Account Manager | 41 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 1 DLL Side-Loading | 1 DLL Side-Loading | 211 Process Injection | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 113 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 13 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Obfuscated Files or Information | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Software Packing | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
62% | Virustotal | Browse | ||
66% | ReversingLabs | ByteCode-MSIL.Backdoor.Crysan | ||
100% | Avira | TR/Dldr.Agent.juage |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Dldr.Agent.juage | ||
66% | ReversingLabs | ByteCode-MSIL.Backdoor.Crysan |
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
oshi.at | 194.15.112.248 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
194.15.112.248 | oshi.at | Ukraine | 213354 | INTERNATIONAL-HOSTING-SOLUTIONS-ASEUDCrouteGB | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1631786 |
Start date and time: | 2025-03-07 15:47:40 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | zXtG0a5Gt0.exerenamed because original name is a hash value |
Original Sample Name: | dc3657abea2cc9c36a8f7a7cf4f61a22ba2172bd1040c229d5b2cdd8af10bff0.exe |
Detection: | MAL |
Classification: | mal100.troj.expl.evad.winEXE@4/3@1/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WerFault.exe, WMIADAP.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 23.199.214.10, 2.16.185.191
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ctldl.windowsupdate.com, c.pki.goog
- Execution Graph export aborted for target InstallUtil.exe, PID 7632 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
09:48:46 | API Interceptor | |
14:48:56 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
194.15.112.248 | Get hash | malicious | DarkCloud | Browse | ||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | DarkCloud | Browse | |||
Get hash | malicious | DarkCloud | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | DarkCloud | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
oshi.at | Get hash | malicious | DarkCloud | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | DarkCloud | Browse |
| ||
Get hash | malicious | DarkCloud | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | DarkCloud | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
INTERNATIONAL-HOSTING-SOLUTIONS-ASEUDCrouteGB | Get hash | malicious | DarkCloud | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | DarkCloud | Browse |
| ||
Get hash | malicious | DarkCloud | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | DarkCloud | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix, LummaC Stealer | Browse |
|
⊘No context
Process: | C:\Users\user\Desktop\zXtG0a5Gt0.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 80 |
Entropy (8bit): | 4.77019102629464 |
Encrypted: | false |
SSDEEP: | 3:FER/n0eFHHot+kiEaKC5UkHn:FER/lFHIwknaZ5UO |
MD5: | 39BC99232A88BE224BA34A7651DE688B |
SHA1: | 438C2E3712A361C44BDFCD3433AFEAC848C1CA54 |
SHA-256: | E67B1256A7A57CD26AF16ADD8C522BB126EBCB7A0682628FBFD4B590C7FADD27 |
SHA-512: | 5C36D671E9EF4210BA51D6DE16F4DCA4FD9640BE0BB14F4D38A1D4A49030EC2DCC94B661E724F6166AFA7A840CE01681575A2C6760B846C4EFD7F5031D6F1153 |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\zXtG0a5Gt0.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65656 |
Entropy (8bit): | 5.607359601092592 |
Encrypted: | false |
SSDEEP: | 768:69s9+6QHH22F+HIGbu3jI0/6PYrB5TH50hf2QojGF2zInyQS+ST6nkC1:Ys9wFN3jIU6PYrB5TKh+9kiInv/mq |
MD5: | 89757CE41562CF1C80DBC27625D64CBB |
SHA1: | 2BA3C337F490E647361869E54116F08AA190A983 |
SHA-256: | DC3657ABEA2CC9C36A8F7A7CF4F61A22BA2172BD1040C229D5B2CDD8AF10BFF0 |
SHA-512: | 46F93775279A3408CB005B1FD9A7FC3EF0781E96972795782F3096ACB9360A69463152AA715C85FD6FE23EB8C63730C159A79F4D7D403B62364EBF408D0120A3 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\zXtG0a5Gt0.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.607359601092592 |
TrID: |
|
File name: | zXtG0a5Gt0.exe |
File size: | 65'656 bytes |
MD5: | 89757ce41562cf1c80dbc27625d64cbb |
SHA1: | 2ba3c337f490e647361869e54116f08aa190a983 |
SHA256: | dc3657abea2cc9c36a8f7a7cf4f61a22ba2172bd1040c229d5b2cdd8af10bff0 |
SHA512: | 46f93775279a3408cb005b1fd9a7fc3ef0781e96972795782f3096acb9360a69463152aa715c85fd6fe23eb8c63730c159a79f4d7d403b62364ebf408d0120a3 |
SSDEEP: | 768:69s9+6QHH22F+HIGbu3jI0/6PYrB5TH50hf2QojGF2zInyQS+ST6nkC1:Ys9wFN3jIU6PYrB5TKh+9kiInv/mq |
TLSH: | 8553FA87536942F2D15A0F7E9CF1C2720B7BED53AE05DACB16C83F4C39313866A92625 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....@.g.....................J........... ........@.. .......................@............`................................ |
Icon Hash: | 27d8d8d4d4d85006 |
Entrypoint: | 0x40a59a |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x678640F8 [Tue Jan 14 10:48:24 2025 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Signature Valid: | false |
Signature Issuer: | CN=GlobalSign GCC R45 EV CodeSigning CA 2020, O=GlobalSign nv-sa, C=BE |
Signature Validation Error: | The digital signature of the object did not verify |
Error Number: | -2146869232 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 0D966BC363CD56690E80EE36566E3C7B |
Thumbprint SHA-1: | A955D2CBD3F7D394053A3C5219A93AF13917EA0D |
Thumbprint SHA-256: | 2362CABC8423B1EE01F2DE0F40197E509F8FA6DCF631E687EDB44792B241E526 |
Serial: | 138A5335DB02BAFDC71DC47A |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xa550 | 0x4a | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc000 | 0x46d6 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0xd200 | 0x2e78 | .rsrc |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x12000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x85a0 | 0x8600 | 1dd131da4b764e2d533516cd263a3e7b | False | 0.48361707089552236 | data | 5.629981859353038 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc000 | 0x46d6 | 0x4800 | 885760287f0a2860824aeb8d6bd0e215 | False | 0.06342230902777778 | data | 2.218213336098414 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x12000 | 0xc | 0x200 | a2877fd6acbeac9f748cf617852ffa91 | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xc06c | 0x4028 | Device independent bitmap graphic, 64 x 128 x 32, image size 0 | 0.02289332683877253 | ||
RT_GROUP_ICON | 0x100d0 | 0x14 | data | 1.05 | ||
RT_VERSION | 0x10120 | 0x390 | data | 0.4309210526315789 | ||
RT_MANIFEST | 0x104ec | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Description | Data |
---|---|
Translation | 0x0000 0x04b0 |
Comments | Gyazo: Screen Uploader |
CompanyName | Helpfeel Inc. |
FileDescription | Gyazo: Screen Uploader |
FileVersion | 5.5.3.0 |
InternalName | reff.exe |
LegalCopyright | (c) Helpfeel Inc. All rights reserved. |
LegalTrademarks | |
OriginalFilename | reff.exe |
ProductName | Gyazo |
ProductVersion | 5.5.3.0 |
Assembly Version | 5.5.3.0 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 7, 2025 15:48:47.551743984 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:47.551812887 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:47.551877975 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:47.566236019 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:47.566258907 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:50.148551941 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:50.148648024 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:50.170346975 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:50.170384884 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:50.170639992 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:50.220427990 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:50.248616934 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:50.296328068 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.261878967 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.261902094 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.261985064 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.262017965 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.262212038 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.268455982 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.268556118 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.275559902 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.275860071 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.400624990 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.401417017 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.414657116 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.414988995 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.424773932 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.425179005 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.431566954 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.431643963 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.445103884 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.445240974 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.445261955 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.445389032 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.452188969 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.452430964 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.494323969 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.494482994 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.601416111 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.601588011 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.614252090 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.614928007 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.620924950 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.621260881 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.627224922 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.627290964 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.640281916 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.640495062 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.666249990 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.666260958 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.666321993 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.666353941 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.666363001 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.666389942 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.666595936 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.782946110 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.783058882 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.799279928 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.799635887 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.804481983 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.804661036 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.806410074 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.806592941 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.810718060 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.810816050 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.814794064 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.814887047 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.820858002 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.820954084 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.833045006 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.835094929 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.839165926 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.839510918 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.935692072 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.935807943 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.987428904 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.987559080 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.992151976 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.992261887 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:51.996762991 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:51.996864080 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.020011902 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.020080090 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.020122051 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.020139933 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.020153046 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.020170927 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.024595976 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.024702072 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.033948898 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.034001112 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.081069946 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.081121922 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.081187963 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.081187963 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.081221104 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.081259012 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.111668110 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.111764908 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.113095999 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.113173962 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.123984098 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.124049902 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.127104998 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.127181053 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.134850979 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.135308027 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.141644001 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.141727924 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.246982098 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.247044086 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.247419119 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.247435093 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.280380964 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.280544996 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.280571938 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.280616045 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.283982038 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.284058094 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.286571980 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.286654949 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.289171934 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.289243937 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.294363022 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.294444084 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.296989918 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.297060013 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.302166939 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.302262068 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.304758072 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.304852009 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.307353020 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.307421923 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.312393904 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.312468052 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.480212927 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.480292082 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.480410099 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.480421066 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.480459929 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.482606888 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.482763052 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.482773066 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.482815027 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.485232115 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.485290051 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.487796068 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.487869978 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.492930889 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.492999077 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.495479107 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.495558023 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.500718117 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.500782013 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.503247023 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.503310919 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.511367083 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.511441946 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.604530096 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.604652882 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.622761965 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.622853041 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.623857021 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.624021053 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.628963947 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.629035950 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.631623983 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.631690025 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.636729002 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.636811018 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.663901091 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.664000988 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.667824030 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.667881966 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.670253992 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.670315027 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.672847986 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.672900915 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.678081036 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.678164959 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.776712894 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.776858091 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.777112961 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.777160883 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.796550035 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.796662092 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.798861980 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.798933983 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.804039001 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.804130077 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.806605101 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.806662083 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.811713934 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.811768055 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.814331055 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.814385891 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.833101034 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.833172083 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.835771084 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.835820913 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.951940060 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.952002048 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.952085972 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.952096939 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.952114105 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.994929075 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.995065928 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.995083094 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.995129108 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:52.998698950 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:52.998876095 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.001854897 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.001919031 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.003938913 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.004004002 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.009021044 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.009074926 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.011642933 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.011697054 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.016772032 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.016854048 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.019464970 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.019524097 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.024486065 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.024548054 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.027146101 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.027215958 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.029666901 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.029725075 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.034856081 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.034926891 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.138518095 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.138582945 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.210710049 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.210784912 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.211000919 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.211040974 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.211050987 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.211066961 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.211097956 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.212016106 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.212066889 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.212075949 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.212121010 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.212726116 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.212779999 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.212873936 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.212922096 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.213666916 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.213721991 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.215987921 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.216042995 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.218595982 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.218650103 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.221189022 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.221244097 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.226279974 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.226331949 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.228866100 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.228921890 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.285691023 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.285756111 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.286525011 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.286593914 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.326631069 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.326694012 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.326777935 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.326791048 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.326829910 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.329209089 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.329274893 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.331840992 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.331911087 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.336858988 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.336932898 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.339457989 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.339560032 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.344655991 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.344723940 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.347186089 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.347244024 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.349904060 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.349994898 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.355024099 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.355108023 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.358741045 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.358803988 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.451066971 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.451265097 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.479120016 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.479259014 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.481864929 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.481952906 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.484206915 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.484285116 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.485722065 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.485810041 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.489464045 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.489546061 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.491282940 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.491379023 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.494955063 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.495028019 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.496826887 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.496902943 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.498733997 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.498814106 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.502481937 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.502574921 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.504353046 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.504424095 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.508128881 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.508214951 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.509975910 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.510050058 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.513647079 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.513776064 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.664298058 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.664473057 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.696762085 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.696820021 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.697000980 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.697021961 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.700474024 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.700545073 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.700551033 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.700601101 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.708030939 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.708071947 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.708250046 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.708255053 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.711750031 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.711827993 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.711838961 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.711880922 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.713557005 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.713624001 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.715446949 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.715514898 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.719234943 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.719316006 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.721101999 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.721174955 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.724911928 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.724997997 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.726896048 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.726993084 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.729470015 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.729533911 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.757940054 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.758049011 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.851604939 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.851779938 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.866677046 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.866820097 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.868442059 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.868693113 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.872230053 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.872289896 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.874068022 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.874123096 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.875983000 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.876108885 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.879719019 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.879779100 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.881629944 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.881688118 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.885858059 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.886044025 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.887412071 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.887465954 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.891088963 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.891249895 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.892796040 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.892858028 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.894671917 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.894834042 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.898459911 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.898566961 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.900316000 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.900587082 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.944506884 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.944566011 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:53.975836039 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:53.975991964 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.011501074 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.011631012 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.011651993 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.011663914 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.011686087 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.011704922 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.014439106 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.014566898 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.014656067 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.014710903 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.018615961 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.018676996 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.020355940 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.020463943 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.022181988 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.022238970 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.025909901 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.025969982 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.027959108 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.028029919 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.031531096 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.031629086 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.033545971 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.033660889 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.037539959 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.037707090 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.039412975 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.039521933 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.040822983 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.040880919 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.068569899 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.068703890 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.147006989 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.147160053 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.150455952 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.150564909 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.152396917 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.152503967 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.156071901 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.156147957 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.159053087 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.159131050 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.159939051 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.159996986 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.165163994 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.165292025 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.168049097 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.168189049 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.169361115 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.169696093 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.173403025 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.173564911 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.174997091 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.175101042 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.176757097 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.177042961 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.208024025 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.208163023 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.208297014 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.208385944 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.208420992 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.208493948 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.258106947 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.258208990 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.258271933 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.258281946 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.258335114 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.262341976 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.262451887 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.262460947 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.262501001 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.293145895 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.293301105 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.294083118 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.294313908 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.297744036 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.297874928 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.299648046 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.299778938 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.303275108 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.303396940 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.305327892 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.305407047 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.307161093 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.307254076 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.310898066 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.310986996 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.316092968 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.316231012 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.318808079 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.318885088 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.320749998 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.320812941 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.322498083 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.322561026 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.326237917 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.326307058 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.328198910 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.328267097 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.331770897 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.331836939 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.333805084 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.333868980 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.337518930 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.337762117 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.460843086 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.461251020 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.463363886 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.463445902 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.470712900 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.470756054 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.470782995 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.470791101 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.470974922 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.472546101 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.472737074 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.476608038 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.476708889 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.478205919 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.478507042 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.480065107 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.480146885 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.483809948 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.483895063 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.485786915 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.485856056 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.489427090 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.489518881 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.491235018 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.491349936 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.493562937 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.493669987 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.496818066 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.496968985 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.498753071 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.498886108 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.502479076 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.502979994 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.504357100 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.504487038 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.508059025 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.508182049 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.509929895 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.510010004 CET | 443 | 49717 | 194.15.112.248 | 192.168.2.4 |
Mar 7, 2025 15:48:54.510021925 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.510065079 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Mar 7, 2025 15:48:54.516329050 CET | 49717 | 443 | 192.168.2.4 | 194.15.112.248 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 7, 2025 15:48:47.529319048 CET | 61656 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 7, 2025 15:48:47.543452024 CET | 53 | 61656 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 7, 2025 15:48:47.529319048 CET | 192.168.2.4 | 1.1.1.1 | 0x7df6 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 7, 2025 15:48:47.543452024 CET | 1.1.1.1 | 192.168.2.4 | 0x7df6 | No error (0) | 194.15.112.248 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49717 | 194.15.112.248 | 443 | 7912 | C:\Users\user\Desktop\zXtG0a5Gt0.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 14:48:50 UTC | 186 | OUT | |
2025-03-07 14:48:51 UTC | 308 | IN | |
2025-03-07 14:48:51 UTC | 3775 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN | |
2025-03-07 14:48:51 UTC | 676 | IN | |
2025-03-07 14:48:51 UTC | 4096 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 09:48:46 |
Start date: | 07/03/2025 |
Path: | C:\Users\user\Desktop\zXtG0a5Gt0.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2b0000 |
File size: | 65'656 bytes |
MD5 hash: | 89757CE41562CF1C80DBC27625D64CBB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 09:48:55 |
Start date: | 07/03/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa30000 |
File size: | 42'064 bytes |
MD5 hash: | 5D4073B2EB6D217C19F2B22F21BF8D57 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 09:48:58 |
Start date: | 07/03/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfc0000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |