Windows
Analysis Report
GyGE2VaBFL.exe
Overview
General Information
Sample name: | GyGE2VaBFL.exerenamed because original name is a hash value |
Original sample name: | 0a494235e29b9a51ba2120377cbc09ae119c0e6eda64072218343e69c85d1783.exe |
Analysis ID: | 1632354 |
MD5: | d8eacf83ca07943696bf5e23528cc348 |
SHA1: | 1aa708342f955f268f43cbd7705dc1497cf91d46 |
SHA256: | 0a494235e29b9a51ba2120377cbc09ae119c0e6eda64072218343e69c85d1783 |
Tags: | exeuser-adrian__luca |
Infos: | |
Detection
GuLoader
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Early bird code injection technique detected
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected GuLoader
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Powershell drops PE file
Queues an APC in another process (thread injection)
Suspicious powershell command line found
Writes to foreign memory regions
Checks if the current process is being debugged
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Msiexec Initiated Connection
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Classification
- System is w10x64
GyGE2VaBFL.exe (PID: 7680 cmdline:
"C:\Users\ user\Deskt op\GyGE2Va BFL.exe" MD5: D8EACF83CA07943696BF5E23528CC348) powershell.exe (PID: 7720 cmdline:
powershell .exe -wind owstyle hi dden "$App assionatae ns178=Get- Content -R aw 'C:\Use rs\user\Ap pData\Loca l\afsindig stes\physi theism\alt ingsmedlem met\Ricino leic.Eks'; $Desquamat ive=$Appas sionataens 178.SubStr ing(52965, 3);.$Desqu amative($A ppassionat aens178) " MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) conhost.exe (PID: 7728 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) msiexec.exe (PID: 6128 cmdline:
"C:\Window s\SysWOW64 \msiexec.e xe" MD5: 9D09DC1EDA745A5F87553048E57620CF)
svchost.exe (PID: 7896 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CloudEyE, GuLoader | CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. | No Attribution |
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security |
System Summary |
---|
Source: | Author: frack113: |
Source: | Author: frack113, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: vburov: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-07T22:46:43.879482+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.4 | 49720 | 216.58.206.78 | 443 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00406448 | |
Source: | Code function: | 0_2_0040589C | |
Source: | Code function: | 0_2_004027A1 |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00405339 |
System Summary |
---|
Source: | File created: | Jump to dropped file |
Source: | Code function: | 0_2_00403325 |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00403325 |
Source: | Code function: | 0_2_004045EA |
Source: | Code function: | 0_2_0040216B |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Anti Malware Scan Interface: | ||
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 1_2_04A5A4A1 | |
Source: | Code function: | 1_2_04A5EA0C |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: |
Source: | Code function: | 0_2_00406448 | |
Source: | Code function: | 0_2_0040589C | |
Source: | Code function: | 0_2_004027A1 |
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-3250 | ||
Source: | API call chain: | graph_0-3415 |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 1_2_04A57810 |
Source: | Process token adjusted: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created / APC Queued / Resumed: | Jump to behavior |
Source: | Thread APC queued: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00403325 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Windows Management Instrumentation | 1 DLL Side-Loading | 1 Access Token Manipulation | 11 Masquerading | OS Credential Dumping | 121 Security Software Discovery | Remote Services | 1 Clipboard Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 1 Command and Scripting Interpreter | Boot or Logon Initialization Scripts | 311 Process Injection | 41 Virtualization/Sandbox Evasion | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | 1 DLL Side-Loading | 1 Access Token Manipulation | Security Account Manager | 41 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 311 Process Injection | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 14 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 3 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 24 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
64% | Virustotal | Browse | ||
47% | ReversingLabs | Win32.Trojan.GuLoader |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
64% | Virustotal | Browse | ||
47% | ReversingLabs | Win32.Trojan.GuLoader |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
drive.google.com | 216.58.206.78 | true | false | high | |
drive.usercontent.google.com | 142.250.185.193 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.185.193 | drive.usercontent.google.com | United States | 15169 | GOOGLEUS | false | |
216.58.206.78 | drive.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1632354 |
Start date and time: | 2025-03-07 22:44:48 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 21s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | GyGE2VaBFL.exerenamed because original name is a hash value |
Original Sample Name: | 0a494235e29b9a51ba2120377cbc09ae119c0e6eda64072218343e69c85d1783.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@7/27@2/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, sppsvc.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 23.60.203.209
- Excluded domains from analysis (whitelisted): fs.microsoft.com, e16604.f.akamaiedge.net, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
- Execution Graph export aborted for target powershell.exe, PID 7720 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtQueryAttributesFile calls found.
Time | Type | Description |
---|---|---|
16:45:46 | API Interceptor | |
16:45:47 | API Interceptor | |
16:46:45 | API Interceptor |
⊘No context
⊘No context
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | GuLoader | Browse |
| |
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
|
⊘No context
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073662174470488 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrf:KooCEYhgYEL0In |
MD5: | 6C26B1A84A15EA72D024C3CA321F0F43 |
SHA1: | AE352680D26D98E431FA281D62E60C51E5309F29 |
SHA-256: | F492F5F47DDC2E4DC249F212831CF7CE176AA00199B15B0DBECB0CB9AA655762 |
SHA-512: | BB7E553BA766A2A11BC133083A53CB24F89670D4DD1147A034CAA81843A9F95413B8AA3DAD294312049FB7D593C7D960C3B70E2AF1DD405C29B2387ED33B010B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4221517097470329 |
Encrypted: | false |
SSDEEP: | 1536:ZSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Zaza/vMUM2Uvz7DO |
MD5: | 9F0210455A788C5EC4399730917CA80D |
SHA1: | EFE5B8798EC6C6A9124B29AFECEFB0843961E233 |
SHA-256: | 8D27833F9420FCB87CE1B61A6913D796594CD5AE1379152B796D344654F81AE8 |
SHA-512: | 4DE09870AADA85F7807A2922BDAE5FCD82F050E9E87D48308F5C2DDDF9D0E865457E39C8963785257EF69A2A1E3568733EAA2D2956D33247557C4746338C5D76 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07722811369453877 |
Encrypted: | false |
SSDEEP: | 3:blXKYe9NVmYGjjn13a/H9tAllcVO/lnlZMxZNQl:b1Kz9NEYGj53q/AOewk |
MD5: | 5050EAF3EC42DD5B8F9A7DCC5538CE57 |
SHA1: | 3B61F0163A4CB3B4EF4A92C56F33B22B5E88CE54 |
SHA-256: | 123BDD6EF26C97E41C5DD2FEAEE403A03B0389D15CC30F6447819B594A9ACE7C |
SHA-512: | C9832F7273D7C41C777488086EBFC73E985663298699A63BADE7C70F4E2AA1B47D7B1300D22CB66289A3F7CCADA0AE45E311203B31098A173FDFAE4281430F90 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | modified |
Size (bytes): | 53158 |
Entropy (8bit): | 5.062687652912555 |
Encrypted: | false |
SSDEEP: | 1536:N8Z+z30pPV3CNBQkj2Ph4iUx7aVKflJnqvPqdKgfSRIOdBlzStAHk4NKeCMiYoLs:iZ+z30pPV3CNBQkj2PqiU7aVKflJnqvF |
MD5: | 5D430F1344CE89737902AEC47C61C930 |
SHA1: | 0B90F23535E8CDAC8EC1139183D5A8A269C2EFEB |
SHA-256: | 395099D9A062FA7A72B73D7B354BF411DA7CFD8D6ADAA9FDBC0DD7C282348DC7 |
SHA-512: | DFC18D47703A69D44643CFC0209B785A4393F4A4C84FAC5557D996BC2A3E4F410EA6D26C66EA7F765CEC491DD52C8454CB0F538D20D2EFF09DC89DDECC0A2AFE |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\GyGE2VaBFL.exe 

Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 791053 |
Entropy (8bit): | 7.596359760786588 |
Encrypted: | false |
SSDEEP: | 12288:2tlyuHaQfKR13fxFozNXofFxNc3pipkyfGSw:AbQRdpAiF3c5yfFw |
MD5: | D8EACF83CA07943696BF5E23528CC348 |
SHA1: | 1AA708342F955F268F43CBD7705DC1497CF91D46 |
SHA-256: | 0A494235E29B9A51BA2120377CBC09AE119C0E6EDA64072218343E69C85D1783 |
SHA-512: | 72D24F737152A33FB7B9BB38B4DC9886711F8A1CD4089021AA08482DB193221359CAC6836F63362994E988F02788E00DCB0A836C0387DF19F04BB557561F8FEC |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\GyGE2VaBFL.exe:Zone.Identifier 
Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\Krukkes.for
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 216186 |
Entropy (8bit): | 1.2440696313854045 |
Encrypted: | false |
SSDEEP: | 3072:JWmCwIPw5AcywvTvHnxuoEWljFo26U82/LdKhBMqn3xh0:7BIM8I |
MD5: | A294462A1566CE13B91DCE3515CBBE99 |
SHA1: | 2EE7CA771D5EE98F23DFD60AEF636063FB9FB39E |
SHA-256: | 159A445C0FE5840209F47C0846AAC408D7A52CB16BF69E8ED9EF461CF9618063 |
SHA-512: | E08266B0CAF0E0089EFCA6FF49924E65073B89F26B60F84642F744E4C24BD8F0F61F892BC5DA8C36A276CA40090DF427DCA581B43AEDB841F2188983F2CBDE21 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\Levnedsmiddelet.hyd
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 52515 |
Entropy (8bit): | 1.2339950087992486 |
Encrypted: | false |
SSDEEP: | 384:TZuT1tvvcUHAApb0CSLYXN2ESvROeZ+tAKgXBmf6rF0OxFpsDcfTcG+nOMT60EI/:ItMfIDSvRBZ+tbgXBDF0Ovx+fT64oNy |
MD5: | 7FB552F9EDF2578492ECB1AC6ED812D4 |
SHA1: | D976EC08EE4E7F05B8A370B904332F56471D27DE |
SHA-256: | 6356F2D4505DB44E6E8159A1D677250F09B796DDDB00182951E16D04E7A53F63 |
SHA-512: | 342ECEFD649D96C9A06DC283DB808A4320A2803DCD461FE509E5D564ABB612EF4B65A9450511189B29E49D5A4087A3F27A9D5C15EEEC2D2EB55C49D486F48F54 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\Meir.ini
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6406 |
Entropy (8bit): | 7.91324021094192 |
Encrypted: | false |
SSDEEP: | 192:LXXQXQ7uxIm/3REK132D5phEiQirK5Xvctcs:7XzuOmvyfhEE25XvJs |
MD5: | 69FDCA2AECDDEC1F02F8849BB7524031 |
SHA1: | 897688E80B403AAC39036851ABDF8D07F948CFED |
SHA-256: | 7AFD32B592315D4D5DACC9205EDB18F058CC312B95C690AEC795AE1C5CDBCFD9 |
SHA-512: | 0AEE6236EC213A1F829F64A94F277C334467CCA974664104129BD3B52E8FDCC049741B73E5B5E9453A1B8D7E5A828C5DB8A5BBECB4A3FF5470B42C082469172B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\Supratonsillar.ini
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 14049 |
Entropy (8bit): | 7.91807748657587 |
Encrypted: | false |
SSDEEP: | 384:wqmHIc+9W7tPMa2+d7ubE2CwYyjyzzlpyCEysbOJbV2C:wqmocnd/aSwz2XX/sbEJD |
MD5: | 8AB3CA28CE62FC46C07B5B98FBBB414B |
SHA1: | 240E8583EFDC5A9C6D75BF7B11F262914BD04200 |
SHA-256: | C5A65D61DD4F44DEEDC787B8A3D6C4B09B38DC25EB93AD8FEDDA047C00C6CEA4 |
SHA-512: | 295B01BD4821D508415FAC01E09EFA81B3CF4C73749CBD9BB58B578B26476E19CA2A08E67A11A60843CECFCE05FB5066B3DD277CC5CA0107D4283E8E992928ED |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\asaraceae.txt
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13561 |
Entropy (8bit): | 7.944486430660756 |
Encrypted: | false |
SSDEEP: | 384:wqmHIc+9W7tPMa2+d7ubE2CwYyjyzzlpyCEysbOJbVD:wqmocnd/aSwz2XX/sbEJD |
MD5: | B01D2EE27691E0946A05D90BFF5738FF |
SHA1: | 7202B8A8FA2CB0BE12C35E1DB38B73D7EF5BE2B3 |
SHA-256: | 99A8FF2023B2897A6521E088258EBD61EF560283D294E395A6CE4671EE0E3FA6 |
SHA-512: | 1916D6C935EEF69CAEA32989023F337AD1D68DFFD6A2E6018DFC010E3BFA3B70A0EBCA797446C46C35BC273C91D2005A117EA35704AED9FC4BBBB75A85F6506B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\friezer.txt
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7274 |
Entropy (8bit): | 7.778553745678111 |
Encrypted: | false |
SSDEEP: | 192:LXXQXQ7uxIm/3REK132D5phEiQirK5Xvctc0an:7XzuOmvyfhEE25XvJ08 |
MD5: | D3B67F439E3520AD4222C98CA488BFA2 |
SHA1: | 9CE0BBE7AEA677CD022980D1237690B66BF9C380 |
SHA-256: | 43FB0CAAFF47E62E124A73C22E07E89D6D94BC93FF2A6DDA57A2C28A1225DFFD |
SHA-512: | 1EC28E17F10D8A2E6412281122F84AAB26210E8A6C99A60CD34F88E2222780419B285E4CCEEE16B7CB5F1B41BC8B343B39A0D280D5A861336B731F2A240E8AEE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\kderegel.txt
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 27142 |
Entropy (8bit): | 7.937950694247041 |
Encrypted: | false |
SSDEEP: | 384:HPIGC4eyQ7QeqSad6dm8wme7yjVd/oZRLcz3jP2kjc7JKAWdylE8RcCfAhZwJ8a:HPw42hasAN7yjHQc3pA0LMDRcwJF |
MD5: | 541F2C5A945E473E104CB993414ACF54 |
SHA1: | E87A90C84328C40E059CD05F136235C1A9DDD9AE |
SHA-256: | D3EFA687CCDF945CE7AE1C524BA2883057A0D00C6BF317DB5519164344188494 |
SHA-512: | FD5B135D735C334755763CCEE29861B68D10437938947A4E140576A3420DC73EE163FDB21A2082635848DC33F8A4614AB2BC0C1F6E9FF1EAE5FBA7E2BCA96468 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\lorded.txt
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26575 |
Entropy (8bit): | 7.946417329290275 |
Encrypted: | false |
SSDEEP: | 384:HPIGC4eyQ7QeqSad6dm8wme7yjVd/oZRLcz3jP2kjc7JKAWdylE8RcCfAhZQ:HPw42hasAN7yjHQc3pA0LMDRcQ |
MD5: | B3C9708BAAA65457A17170269A21EF71 |
SHA1: | F2EAE9E9F236AF8A61A17BC765FBA90A8CE393F7 |
SHA-256: | 0652B5053D759D94FE40A67BC2FF470A250533B75570F0D0D86A759681573B3E |
SHA-512: | A7B5A431FDA7F30E601806D248302ACCF73D54C73723B900E0F9152D7D8F2A15A362A55C4059DA1BF7E6C5224E6CC04EAE201BD9FC25D95B3023C9D9E49233E9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\snusdaases.jpg
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26001 |
Entropy (8bit): | 7.948061981828881 |
Encrypted: | false |
SSDEEP: | 384:HPIGC4eyQ7QeqSad6dm8wme7yjVd/oZRLcz3jP2kjc7JKAWdylE8RcCfAhO:HPw42hasAN7yjHQc3pA0LMDRp |
MD5: | 47F9CE8203A2AF484EBF0EFB9AAC90AA |
SHA1: | D696706CF587DA3AEAA852C0623EC0037CE429E8 |
SHA-256: | BE707A416458B30652EC5A6C36FCA438E8E3DE4341742646ECB4FDD4ED8A9947 |
SHA-512: | A7DC9F3D57C8D5A99F6D9827C8692A0A85FD3528BEB3D4DAC3861DF611123901FAF49A3853DE48681D72DA558262E10360A78CC4668AB638E66DB6141B05DE58 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\tavse.gam
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 369267 |
Entropy (8bit): | 1.2505498508943538 |
Encrypted: | false |
SSDEEP: | 3072:q4GegDIdTXvDmD7bAesUYZXiOcxlvD2srap7dG7kw/d+yIX2CoVN/18d1/MWmYB1:BIW+zx6PXU+ |
MD5: | C6FFD2E64ED2416142F50EA4046578B8 |
SHA1: | 875FF4760B702CAA1D2AA7E1482D0468BB95850C |
SHA-256: | 90C089F5BBAA260A087BF1B8C5F56C14F0D3E4A369872AB1E429DB71A969B80F |
SHA-512: | 685D035FDBEFD3BCD3B703F6D7D5BB4FA7D242B62326052B279634DDCB7C3AD1100DF7C2730B5CCF647D0B4E43C26AB4FA97711013327204E162D7D3CEA4A6D2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\ungauntlet.txt
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7742 |
Entropy (8bit): | 7.685816559459474 |
Encrypted: | false |
SSDEEP: | 192:LXXQXQ7uxIm/3REK132D5phEiQirK5Xvctc0awWk/:7XzuOmvyfhEE25XvJ0// |
MD5: | CAB6C7C8AB58D902E1836D53A688CD4A |
SHA1: | 55C46FA98306F5E0F35B89796891CA126E52F02A |
SHA-256: | 82B4B8B3994B4A9D277F249AC6D2B034715DA0F5BAE309604D3BF1CA7247B4E9 |
SHA-512: | 9115FF2B00F98109B989DDEB316D5D6F1A1509DCFA56FE8ABB75F0753DE7BE0C8CD16C978F36CA46DFF5BA0A55E67A432077A14EBAFC1446260E7B249A938A3E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\vejningers.jpg
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12929 |
Entropy (8bit): | 7.957757236123418 |
Encrypted: | false |
SSDEEP: | 384:wqmHIc+9W7tPMa2+d7ubE2CwYyjyzzlpyCEysbG:wqmocnd/aSwz2XX/sbG |
MD5: | D80B9F37C8A58A34326507D15B2141F3 |
SHA1: | 92A352F9BCF3E9231FB96F2EBCE0EEB3B28D53C3 |
SHA-256: | 83BB4E7FFE9511AE104E48B1F9E350308AFAA12F12F8750170A7C6A956EA7238 |
SHA-512: | DD6CD1188BB082A1D336D0DCBEAD91B26B1EE045CD852B9CBF61DFEF11D7EC940199034C389FB30838B82EBB672622D3994409409C8A68834D3F276469E9C370 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\afsindigstes\physitheism\altingsmedlemmet\Cideren231\vitrifacture.txt
Download File
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6748 |
Entropy (8bit): | 7.868770137002905 |
Encrypted: | false |
SSDEEP: | 192:LXXQXQ7uxIm/3REK132D5phEiQirK5Xvctc0J:7XzuOmvyfhEE25XvJ0J |
MD5: | 9361066F2EAB82730A5F698F735ECF25 |
SHA1: | 7279F63469EFC0AAF9FCF70D8ACCD623F7D5AC6B |
SHA-256: | 4976EE2C2C27F507B578F55C6323533DEE7B47E25877F8F51398AD34545497D0 |
SHA-512: | F706FB6DBD5596631AE35A2F6B8FD0D723BD46E6F646383245C470F57C2B3CEE2A82F4695E24D9E0A2F7382156EAAD4AE218443069C962B247015EC8429583EE |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6028 |
Entropy (8bit): | 7.934780456271549 |
Encrypted: | false |
SSDEEP: | 96:RhXE4WTXQUVsLLl9vaxwrBnNk/3REfi132Co5p7lrEik1MEirZ8Jcics9:LXXQXQ7uxIm/3REK132D5phEiQirK5X9 |
MD5: | F9D9FF81C5A1981E6D8D05FF64C375A3 |
SHA1: | A880B1EE40AF72076B8BC02BF62E89489A5481ED |
SHA-256: | FA20D23F9216A071D4A75F1ED13515C02704746D091EF2B9D5C09896E5143534 |
SHA-512: | 6D1CEA465CF4BC488C94AD875E9DE0EC4B73061CF94A2D6F200C7DA8DA472A83C2ADF6413383BAC18843BF9ED1FA5B0D633C326E82AEFCE532C8BF2512F83124 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 310172 |
Entropy (8bit): | 7.730220826478408 |
Encrypted: | false |
SSDEEP: | 6144:vtlXxoirgTHS9GMQdWzWXWfldHMR2tWcTn6mVpJOwf0rjztxSXLyfu:VZxKS9MW6WddscQcTn66psW0DHS7yG |
MD5: | C0AE77537787BD3E4FC226F700D6ABBC |
SHA1: | 7C51BA74161A9866CA1569257B45353F485947BB |
SHA-256: | AE59AA2ADB65D3963B98EF51AB9FF0EF289CDD98C063CE9A29F375A38FD62293 |
SHA-512: | 29525C27A856C80986392833666E70A02DE27CD95C7DA43FE022A5A0B3D2D0A8AB7CE5D8798708F20596E95282A353F57DCFED8C8F300DF58F93F7E80820D6F0 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 52995 |
Entropy (8bit): | 5.328813408673782 |
Encrypted: | false |
SSDEEP: | 1536:yYXWMCcIl8U2gCVnaihuyUH6bGZpufwhFz5od:/hU2g6aYs6b+pvlE |
MD5: | C740FC11F250034D77CB8DCA8A40FE8F |
SHA1: | 9758084B008638DA2208BB32908340B6627C17AA |
SHA-256: | F995D79992D17DC66BE7688AFCAD5B741C0EDDEE7A427318581091058F140D49 |
SHA-512: | 7D302BC092D5C1518CE8606A212C5CA04E4A3DBCFD27F0B2E1617D857382312ED004373C4A5D151A07EC49E131177C7D90D4741CF9F1EF15BB201E285D2D9A6C |
Malicious: | true |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.596359760786588 |
TrID: |
|
File name: | GyGE2VaBFL.exe |
File size: | 791'053 bytes |
MD5: | d8eacf83ca07943696bf5e23528cc348 |
SHA1: | 1aa708342f955f268f43cbd7705dc1497cf91d46 |
SHA256: | 0a494235e29b9a51ba2120377cbc09ae119c0e6eda64072218343e69c85d1783 |
SHA512: | 72d24f737152a33fb7b9bb38b4dc9886711f8a1cd4089021aa08482db193221359cac6836f63362994e988f02788e00dcb0a836c0387df19f04bb557561f8fec |
SSDEEP: | 12288:2tlyuHaQfKR13fxFozNXofFxNc3pipkyfGSw:AbQRdpAiF3c5yfFw |
TLSH: | 4EF4F165AB69CD03E3C205B0C5B7D3B967788E54163F82228BD1BE5BF97CBE10D19212 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........!.@.@...@...@../O...@...@..L@../O...@...c...@..+F...@..Rich.@..........PE..L......`.................d....9.....%3............@ |
Icon Hash: | 49c5e9ec6d5d8413 |
Entrypoint: | 0x403325 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x60FC909C [Sat Jul 24 22:13:48 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | ced282d9b261d1462772017fe2f6972b |
Instruction |
---|
sub esp, 00000184h |
push ebx |
push esi |
push edi |
xor ebx, ebx |
push 00008001h |
mov dword ptr [esp+18h], ebx |
mov dword ptr [esp+10h], 0040A198h |
mov dword ptr [esp+20h], ebx |
mov byte ptr [esp+14h], 00000020h |
call dword ptr [004080B8h] |
call dword ptr [004080BCh] |
and eax, BFFFFFFFh |
cmp ax, 00000006h |
mov dword ptr [007A2F6Ch], eax |
je 00007F793CF5EFB3h |
push ebx |
call 00007F793CF62116h |
cmp eax, ebx |
je 00007F793CF5EFA9h |
push 00000C00h |
call eax |
mov esi, 004082A0h |
push esi |
call 00007F793CF62092h |
push esi |
call dword ptr [004080CCh] |
lea esi, dword ptr [esi+eax+01h] |
cmp byte ptr [esi], bl |
jne 00007F793CF5EF8Dh |
push 0000000Bh |
call 00007F793CF620EAh |
push 00000009h |
call 00007F793CF620E3h |
push 00000007h |
mov dword ptr [007A2F64h], eax |
call 00007F793CF620D7h |
cmp eax, ebx |
je 00007F793CF5EFB1h |
push 0000001Eh |
call eax |
test eax, eax |
je 00007F793CF5EFA9h |
or byte ptr [007A2F6Fh], 00000040h |
push ebp |
call dword ptr [00408038h] |
push ebx |
call dword ptr [00408288h] |
mov dword ptr [007A3038h], eax |
push ebx |
lea eax, dword ptr [esp+38h] |
push 00000160h |
push eax |
push ebx |
push 0079E528h |
call dword ptr [0040816Ch] |
push 0040A188h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8438 | 0xa0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x3b3000 | 0x2a768 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x8000 | 0x29c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x6230 | 0x6400 | 1ac97b0b8e41e1ffbb716878bb5109f2 | False | 0.6699609375 | data | 6.441889952551939 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x8000 | 0x1274 | 0x1400 | b8e42f3d3b81b0e2a4080ab31bc2d1f4 | False | 0.4337890625 | data | 5.061067348371254 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xa000 | 0x399078 | 0x600 | be2892f1b11a971e0c6c4e83000268f5 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x3a4000 | 0xf000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x3b3000 | 0x2a768 | 0x2a800 | 0cb6c80894f545860470303df9b92eb7 | False | 0.3268037683823529 | data | 4.893333095662434 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x3b3400 | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 67584 | English | United States | 0.2678782680705075 |
RT_ICON | 0x3c3c28 | 0x94a8 | Device independent bitmap graphic, 96 x 192 x 32, image size 38016 | English | United States | 0.3491959217994534 |
RT_ICON | 0x3cd0d0 | 0x5488 | Device independent bitmap graphic, 72 x 144 x 32, image size 21600 | English | United States | 0.36455637707948246 |
RT_ICON | 0x3d2558 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16896 | English | United States | 0.3328412848370335 |
RT_ICON | 0x3d6780 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | English | United States | 0.41068464730290455 |
RT_ICON | 0x3d8d28 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | English | United States | 0.4584896810506567 |
RT_ICON | 0x3d9dd0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | English | United States | 0.5255863539445629 |
RT_ICON | 0x3dac78 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | English | United States | 0.5389344262295082 |
RT_ICON | 0x3db600 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | English | United States | 0.5577617328519856 |
RT_ICON | 0x3dbea8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | English | United States | 0.5011520737327189 |
RT_ICON | 0x3dc570 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | English | United States | 0.375 |
RT_ICON | 0x3dcad8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | English | United States | 0.5868794326241135 |
RT_DIALOG | 0x3dcf40 | 0x120 | data | English | United States | 0.53125 |
RT_DIALOG | 0x3dd060 | 0x120 | data | English | United States | 0.5138888888888888 |
RT_DIALOG | 0x3dd180 | 0xf8 | data | English | United States | 0.6330645161290323 |
RT_DIALOG | 0x3dd278 | 0xa0 | data | English | United States | 0.6125 |
RT_DIALOG | 0x3dd318 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_GROUP_ICON | 0x3dd378 | 0xae | data | English | United States | 0.6609195402298851 |
RT_MANIFEST | 0x3dd428 | 0x33e | XML 1.0 document, ASCII text, with very long lines (830), with no line terminators | English | United States | 0.5542168674698795 |
DLL | Import |
---|---|
ADVAPI32.dll | RegCreateKeyExA, RegEnumKeyA, RegQueryValueExA, RegSetValueExA, RegCloseKey, RegDeleteValueA, RegDeleteKeyA, AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, SetFileSecurityA, RegOpenKeyExA, RegEnumValueA |
SHELL32.dll | SHGetFileInfoA, SHFileOperationA, SHGetPathFromIDListA, ShellExecuteExA, SHGetSpecialFolderLocation, SHBrowseForFolderA |
ole32.dll | IIDFromString, OleInitialize, OleUninitialize, CoCreateInstance, CoTaskMemFree |
COMCTL32.dll | ImageList_Create, ImageList_Destroy, ImageList_AddMasked |
USER32.dll | SetClipboardData, CharPrevA, CallWindowProcA, PeekMessageA, DispatchMessageA, MessageBoxIndirectA, GetDlgItemTextA, SetDlgItemTextA, GetSystemMetrics, CreatePopupMenu, AppendMenuA, TrackPopupMenu, FillRect, EmptyClipboard, LoadCursorA, GetMessagePos, CheckDlgButton, GetSysColor, SetCursor, GetWindowLongA, SetClassLongA, SetWindowPos, IsWindowEnabled, GetWindowRect, GetSystemMenu, EnableMenuItem, RegisterClassA, ScreenToClient, EndDialog, GetClassInfoA, SystemParametersInfoA, CreateWindowExA, ExitWindowsEx, DialogBoxParamA, CharNextA, SetTimer, DestroyWindow, CreateDialogParamA, SetForegroundWindow, SetWindowTextA, PostQuitMessage, SendMessageTimeoutA, ShowWindow, wsprintfA, GetDlgItem, FindWindowExA, IsWindow, GetDC, SetWindowLongA, LoadImageA, InvalidateRect, ReleaseDC, EnableWindow, BeginPaint, SendMessageA, DefWindowProcA, DrawTextA, GetClientRect, EndPaint, IsWindowVisible, CloseClipboard, OpenClipboard |
GDI32.dll | SetBkMode, SetBkColor, GetDeviceCaps, CreateFontIndirectA, CreateBrushIndirect, DeleteObject, SetTextColor, SelectObject |
KERNEL32.dll | GetExitCodeProcess, WaitForSingleObject, GetProcAddress, GetSystemDirectoryA, WideCharToMultiByte, MoveFileExA, ReadFile, GetTempFileNameA, WriteFile, RemoveDirectoryA, CreateProcessA, CreateFileA, GetLastError, CreateThread, CreateDirectoryA, GlobalUnlock, GetDiskFreeSpaceA, GlobalLock, SetErrorMode, GetVersion, lstrcpynA, GetCommandLineA, GetTempPathA, lstrlenA, SetEnvironmentVariableA, ExitProcess, GetWindowsDirectoryA, GetCurrentProcess, GetModuleFileNameA, CopyFileA, GetTickCount, Sleep, GetFileSize, GetFileAttributesA, SetCurrentDirectoryA, SetFileAttributesA, GetFullPathNameA, GetShortPathNameA, MoveFileA, CompareFileTime, SetFileTime, SearchPathA, lstrcmpiA, lstrcmpA, CloseHandle, GlobalFree, GlobalAlloc, ExpandEnvironmentStringsA, LoadLibraryExA, FreeLibrary, lstrcpyA, lstrcatA, FindClose, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, SetFilePointer, GetModuleHandleA, FindNextFileA, FindFirstFileA, DeleteFileA, MulDiv |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-07T22:46:43.879482+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.4 | 49720 | 216.58.206.78 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 7, 2025 22:46:40.919590950 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:40.919627905 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:40.919713974 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:40.934269905 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:40.934297085 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:42.922703981 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:42.922795057 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:42.923880100 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:42.923940897 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:42.979957104 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:42.979991913 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:42.980479002 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:42.980649948 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:42.984359980 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:43.032329082 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:43.879511118 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:43.879622936 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:43.879713058 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:43.879713058 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:43.881603956 CET | 49720 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:43.881624937 CET | 443 | 49720 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:43.914422035 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:43.914475918 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:43.914647102 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:43.914891958 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:43.914906025 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:45.956949949 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:45.957108974 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:45.963340044 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:45.963357925 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:45.963717937 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:45.963792086 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:45.964334965 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:46.008326054 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:47.003773928 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:47.003850937 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:47.003916025 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:47.004017115 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:47.004017115 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:47.010677099 CET | 49721 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:47.010703087 CET | 443 | 49721 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:47.141498089 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:47.141602993 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:47.141752958 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:47.142045975 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:47.142081022 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:49.201395035 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:49.201579094 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:49.202354908 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:49.202373028 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:49.202872038 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:49.202881098 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:50.064728022 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:50.064820051 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:50.064938068 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:50.065139055 CET | 49722 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:50.065159082 CET | 443 | 49722 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:50.076832056 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:50.076867104 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:50.076945066 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:50.077172995 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:50.077182055 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:52.158866882 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:52.158916950 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:52.159406900 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:52.159415007 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:52.159632921 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:52.159637928 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:53.040184975 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:53.040335894 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:53.040447950 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:53.040448904 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:53.040467024 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:53.040580034 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:53.041697979 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:53.041771889 CET | 443 | 49723 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:53.041835070 CET | 49723 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:53.169833899 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:53.169892073 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:53.169982910 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:53.170331955 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:53.170355082 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:55.266928911 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:55.267035961 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:55.267942905 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:55.267960072 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:55.268449068 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:55.268455029 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:56.206621885 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:56.206898928 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:56.206935883 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:56.207010984 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:56.207171917 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:56.207221031 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:56.207232952 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:56.207278013 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:56.210144997 CET | 49724 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:56.210172892 CET | 443 | 49724 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:56.222399950 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:56.222435951 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:56.222498894 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:56.222735882 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:56.222748041 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:58.297597885 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:58.297749043 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:58.299561024 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:58.299573898 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:58.299829960 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:58.303715944 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:58.304125071 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:58.344320059 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:59.142993927 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:59.143266916 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:59.143280983 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:59.143330097 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:59.191649914 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:59.191731930 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:59.191750050 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:59.191828012 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:59.191875935 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:59.191915989 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:59.191934109 CET | 443 | 49725 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:46:59.191943884 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:59.191975117 CET | 49725 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:46:59.326349020 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:59.326405048 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:46:59.326559067 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:59.326884031 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:46:59.326894045 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:01.610225916 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:01.610553980 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:01.610980988 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:01.611000061 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:01.611177921 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:01.611192942 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:02.451056004 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:02.451132059 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:02.451160908 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:02.451193094 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:02.451394081 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:02.451411009 CET | 443 | 49726 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:02.451421976 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:02.451459885 CET | 49726 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:02.460697889 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:02.460736990 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:02.460814953 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:02.461036921 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:02.461045027 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:04.652884960 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:04.652967930 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:04.653498888 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:04.653506994 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:04.653695107 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:04.653698921 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:05.546591043 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:05.546715021 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:05.546869993 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:05.546869993 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:05.546890974 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:05.546948910 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:05.547883034 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:05.547954082 CET | 443 | 49727 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:05.548027992 CET | 49727 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:05.669684887 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:05.669785023 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:05.669970989 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:05.670372009 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:05.670402050 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:07.711519003 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:07.711796999 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:07.712161064 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:07.712196112 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:07.712358952 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:07.712373018 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:08.587593079 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:08.587732077 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:08.587800980 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:08.587835073 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:08.587865114 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:08.587893963 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:08.587944031 CET | 49728 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:08.587975979 CET | 443 | 49728 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:08.597511053 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:08.597552061 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:08.597625017 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:08.597887039 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:08.597903013 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:10.765549898 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:10.765676975 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:10.767607927 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:10.767625093 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:10.768667936 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:10.768748045 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:10.769067049 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:10.812325001 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:11.640079021 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:11.640199900 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:11.640206099 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:11.640252113 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:11.640263081 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:11.640321016 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:11.640341043 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:11.640394926 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:11.641119957 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:11.641194105 CET | 443 | 49729 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:11.641263008 CET | 49729 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:11.763379097 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:11.763437033 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:11.763596058 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:11.763977051 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:11.763989925 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:14.990888119 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:14.991925955 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:14.993026018 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:14.993033886 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:14.993230104 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:14.993235111 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:15.850039959 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:15.850267887 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:15.850306034 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:15.850374937 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:15.850660086 CET | 49730 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:15.850708008 CET | 443 | 49730 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:15.863717079 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:15.863765001 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:15.863835096 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:15.864115953 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:15.864131927 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:17.922533035 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:17.922643900 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:17.924253941 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:17.924264908 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:17.924510002 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:17.924555063 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:17.924832106 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:17.968324900 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:18.798623085 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:18.798672915 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:18.798701048 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:18.798718929 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:18.798733950 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:18.798851967 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:18.800327063 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:18.800405025 CET | 443 | 49731 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:18.800498009 CET | 49731 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:18.919636965 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:18.919701099 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:18.919835091 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:18.920079947 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:18.920089960 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:20.991605043 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:20.991771936 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:20.993741989 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:20.993755102 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:20.993876934 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:20.993881941 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:21.852293968 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:21.852499962 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:21.852529049 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:21.852580070 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:21.852636099 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:21.852750063 CET | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:21.852811098 CET | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:21.866972923 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:21.867011070 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:21.867089033 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:21.867311954 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:21.867325068 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.000996113 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.001117945 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.002743959 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.002753019 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.003138065 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.003190994 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.003453970 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.044334888 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.964629889 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.964709997 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.964724064 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.964768887 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.964776993 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.964808941 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.964827061 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.964873075 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.964885950 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.964932919 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.965781927 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:24.965852976 CET | 443 | 49733 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:24.965910912 CET | 49733 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:25.107207060 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:25.107316017 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:25.107486963 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:25.107671976 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:25.107698917 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:27.337619066 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:27.337707996 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:27.340321064 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:27.340396881 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:27.342313051 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:27.342333078 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:27.342833996 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:27.342895031 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:27.343436956 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:27.388323069 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:28.293688059 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:28.293764114 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:28.293776989 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:28.293838024 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:28.294034004 CET | 49734 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:28.294061899 CET | 443 | 49734 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:28.309556007 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:28.309602022 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:28.309664965 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:28.309899092 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:28.309916973 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:30.337565899 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:30.337734938 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:30.340003967 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:30.340020895 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:30.340327024 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:30.340399027 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:30.340758085 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:30.388320923 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:31.247251034 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:31.247302055 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:31.247423887 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:31.247442007 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:31.247452974 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:31.247524023 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:31.248513937 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:31.248598099 CET | 443 | 49735 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:31.248666048 CET | 49735 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:31.401258945 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:31.401329994 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:31.401449919 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:31.401938915 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:31.401954889 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:33.477806091 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:33.477936029 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:33.478518963 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:33.478535891 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:33.478792906 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:33.478800058 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:34.324826956 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:34.324893951 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:34.324917078 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:34.324963093 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:34.324968100 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:34.324978113 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:34.325004101 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:34.325031996 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:34.325145006 CET | 49736 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:34.325158119 CET | 443 | 49736 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:34.342756033 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:34.342863083 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:34.342977047 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:34.343410969 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:34.343442917 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:36.979727983 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:36.979839087 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:37.006742954 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:37.006803036 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:37.007091045 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:37.007164001 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:37.016324043 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:37.060347080 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:38.632225990 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:38.632287025 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:38.632365942 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:38.632405043 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:38.632422924 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:38.632457018 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:38.633047104 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:38.633135080 CET | 443 | 49737 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:38.633208036 CET | 49737 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:38.779968023 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:38.780028105 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:38.780128956 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:38.780461073 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:38.780503035 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:41.868155956 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:41.868343115 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:41.869090080 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:41.869106054 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:41.869352102 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:41.869359016 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:43.150921106 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:43.151170015 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:43.151209116 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:43.151313066 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:43.151705027 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:43.151762009 CET | 443 | 49738 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:43.151855946 CET | 49738 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:43.180906057 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:43.180969954 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:43.181066036 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:43.181359053 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:43.181375027 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:45.680160046 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:45.680322886 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:45.685225010 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:45.685237885 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:45.700654030 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:45.700751066 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:45.701637030 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:45.744321108 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:46.604269028 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:46.604351044 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:46.604505062 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:46.604505062 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:46.604551077 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:46.604619980 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:46.605168104 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:46.605211973 CET | 443 | 49739 | 142.250.185.193 | 192.168.2.4 |
Mar 7, 2025 22:47:46.605261087 CET | 49739 | 443 | 192.168.2.4 | 142.250.185.193 |
Mar 7, 2025 22:47:46.732172012 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:46.732217073 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:46.732291937 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:46.732623100 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:46.732640982 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:48.799031973 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:48.799228907 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:48.799741030 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:48.799841881 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:48.802767038 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:48.802797079 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:48.803173065 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:48.803232908 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:48.803972006 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:48.844341993 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:49.612785101 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:49.612931967 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:49.612998962 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:49.613071918 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:49.615051031 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:49.615117073 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Mar 7, 2025 22:47:49.615178108 CET | 443 | 49740 | 216.58.206.78 | 192.168.2.4 |
Mar 7, 2025 22:47:49.615241051 CET | 49740 | 443 | 192.168.2.4 | 216.58.206.78 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 7, 2025 22:46:40.905935049 CET | 53739 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 7, 2025 22:46:40.913626909 CET | 53 | 53739 | 1.1.1.1 | 192.168.2.4 |
Mar 7, 2025 22:46:43.904580116 CET | 54777 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 7, 2025 22:46:43.913497925 CET | 53 | 54777 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 7, 2025 22:46:40.905935049 CET | 192.168.2.4 | 1.1.1.1 | 0x16d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 7, 2025 22:46:43.904580116 CET | 192.168.2.4 | 1.1.1.1 | 0x256d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 7, 2025 22:46:40.913626909 CET | 1.1.1.1 | 192.168.2.4 | 0x16d5 | No error (0) | 216.58.206.78 | A (IP address) | IN (0x0001) | false | ||
Mar 7, 2025 22:46:43.913497925 CET | 1.1.1.1 | 192.168.2.4 | 0x256d | No error (0) | 142.250.185.193 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49720 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:46:42 UTC | 216 | OUT | |
2025-03-07 21:46:43 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49721 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:46:45 UTC | 258 | OUT | |
2025-03-07 21:46:46 UTC | 1926 | IN | |
2025-03-07 21:46:46 UTC | 1652 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49722 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:46:49 UTC | 428 | OUT | |
2025-03-07 21:46:50 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49723 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:46:52 UTC | 470 | OUT | |
2025-03-07 21:46:53 UTC | 1541 | IN | |
2025-03-07 21:46:53 UTC | 1541 | IN | |
2025-03-07 21:46:53 UTC | 111 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49724 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:46:55 UTC | 428 | OUT | |
2025-03-07 21:46:56 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49725 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:46:58 UTC | 470 | OUT | |
2025-03-07 21:46:59 UTC | 1534 | IN | |
2025-03-07 21:46:59 UTC | 1534 | IN | |
2025-03-07 21:46:59 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49726 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:01 UTC | 428 | OUT | |
2025-03-07 21:47:02 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49727 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:04 UTC | 470 | OUT | |
2025-03-07 21:47:05 UTC | 1534 | IN | |
2025-03-07 21:47:05 UTC | 1534 | IN | |
2025-03-07 21:47:05 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49728 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:07 UTC | 428 | OUT | |
2025-03-07 21:47:08 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49729 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:10 UTC | 470 | OUT | |
2025-03-07 21:47:11 UTC | 1541 | IN | |
2025-03-07 21:47:11 UTC | 1541 | IN | |
2025-03-07 21:47:11 UTC | 111 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49730 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:14 UTC | 428 | OUT | |
2025-03-07 21:47:15 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49731 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:17 UTC | 470 | OUT | |
2025-03-07 21:47:18 UTC | 1534 | IN | |
2025-03-07 21:47:18 UTC | 1534 | IN | |
2025-03-07 21:47:18 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49732 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:20 UTC | 428 | OUT | |
2025-03-07 21:47:21 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49733 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:23 UTC | 470 | OUT | |
2025-03-07 21:47:24 UTC | 1533 | IN | |
2025-03-07 21:47:24 UTC | 1533 | IN | |
2025-03-07 21:47:24 UTC | 119 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49734 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:27 UTC | 428 | OUT | |
2025-03-07 21:47:28 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49735 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:30 UTC | 470 | OUT | |
2025-03-07 21:47:31 UTC | 1534 | IN | |
2025-03-07 21:47:31 UTC | 1534 | IN | |
2025-03-07 21:47:31 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49736 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:33 UTC | 428 | OUT | |
2025-03-07 21:47:34 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49737 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:37 UTC | 470 | OUT | |
2025-03-07 21:47:38 UTC | 1534 | IN | |
2025-03-07 21:47:38 UTC | 1534 | IN | |
2025-03-07 21:47:38 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49738 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:41 UTC | 428 | OUT | |
2025-03-07 21:47:43 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49739 | 142.250.185.193 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:45 UTC | 470 | OUT | |
2025-03-07 21:47:46 UTC | 1534 | IN | |
2025-03-07 21:47:46 UTC | 1534 | IN | |
2025-03-07 21:47:46 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49740 | 216.58.206.78 | 443 | 6128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-07 21:47:48 UTC | 428 | OUT | |
2025-03-07 21:47:49 UTC | 1610 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 16:45:43 |
Start date: | 07/03/2025 |
Path: | C:\Users\user\Desktop\GyGE2VaBFL.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 791'053 bytes |
MD5 hash: | D8EACF83CA07943696BF5E23528CC348 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 16:45:45 |
Start date: | 07/03/2025 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb80000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 16:45:45 |
Start date: | 07/03/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62fc20000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 16:45:47 |
Start date: | 07/03/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ca680000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 16:46:33 |
Start date: | 07/03/2025 |
Path: | C:\Windows\SysWOW64\msiexec.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xcc0000 |
File size: | 59'904 bytes |
MD5 hash: | 9D09DC1EDA745A5F87553048E57620CF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |