Windows
Analysis Report
pbgjw8i8N7.exe
Overview
General Information
Sample name: | pbgjw8i8N7.exerenamed because original name is a hash value |
Original sample name: | 44095f79a9e682a29ed75fab33f6dcf1e2f11937097e4c7e3f84080ff7444048.exe |
Analysis ID: | 1634876 |
MD5: | 679da76a671452de2f13a1585028e74e |
SHA1: | e89c5b5d3b31025710714c14955d22820e2ed493 |
SHA256: | 44095f79a9e682a29ed75fab33f6dcf1e2f11937097e4c7e3f84080ff7444048 |
Tags: | exeSnakeKeyloggeruser-adrian__luca |
Infos: | |
Detection
Snake Keylogger, VIP Keylogger
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Drops script at startup location
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected Snake Keylogger
Yara detected Telegram RAT
Yara detected VIP Keylogger
.NET source code contains potential unpacker
Drops VBS files to the startup folder
Joe Sandbox ML detected suspicious sample
Sample uses string decryption to hide its real strings
Sigma detected: WScript or CScript Dropper
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses the Telegram API (likely for C&C communication)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Creates a window with clipboard capturing capabilities
Detected potential crypto function
Drops PE files
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Suspicious Outbound SMTP Connections
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses SMTP (mail sending)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match
Classification
- System is w10x64
pbgjw8i8N7.exe (PID: 1988 cmdline:
"C:\Users\ user\Deskt op\pbgjw8i 8N7.exe" MD5: 679DA76A671452DE2F13A1585028E74E) InstallUtil.exe (PID: 8068 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57)
wscript.exe (PID: 6828 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\Micro soft\Windo ws\Start M enu\Progra ms\Startup \XsdType.v bs" MD5: A47CBE969EA935BDD3AB568BB126BC80) XsdType.exe (PID: 6732 cmdline:
"C:\Users\ user\AppDa ta\Roaming \XsdType.e xe" MD5: 679DA76A671452DE2F13A1585028E74E) InstallUtil.exe (PID: 7500 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
404 Keylogger, Snake Keylogger | Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram. | No Attribution |
{"Exfil Mode": "SMTP", "Email ID": "bank@iaa-airferight.com", "Password": "moneyismade22", "Host": "mail.iaa-airferight.com", "Port": "25"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_VIPKeylogger | Yara detected VIP Keylogger | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_VIPKeylogger | Yara detected VIP Keylogger | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
Click to see the 40 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_VIPKeylogger | Yara detected VIP Keylogger | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
Click to see the 32 entries |
System Summary |
---|
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: frack113: |
Source: | Author: Michael Haag: |
Data Obfuscation |
---|
Source: | Author: Joe Security: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T06:10:07.153657+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49714 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:18.915468+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49719 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:30.004518+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49726 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:34.050375+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49729 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:49.188792+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49748 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:52.152063+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49750 | 104.21.96.1 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T06:09:59.024815+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49712 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:04.872621+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49712 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:16.717744+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:24.107212+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49716 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:27.857004+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49716 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:30.716397+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49728 | 158.101.44.242 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T06:10:45.740940+0100 | 1810007 | 1 | Potentially Bad Traffic | 192.168.2.5 | 49745 | 149.154.167.220 | 443 | TCP |
2025-03-11T06:10:54.564569+0100 | 1810007 | 1 | Potentially Bad Traffic | 192.168.2.5 | 49753 | 149.154.167.220 | 443 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Location Tracking |
---|
Source: | DNS query: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_04E903C4 | |
Source: | Code function: | 0_2_04E903D0 | |
Source: | Code function: | 0_2_05254423 | |
Source: | Code function: | 0_2_052540A8 | |
Source: | Code function: | 0_2_05254098 | |
Source: | Code function: | 0_2_0525424E | |
Source: | Code function: | 0_2_0526DE49 | |
Source: | Code function: | 0_2_0526DE58 | |
Source: | Code function: | 1_2_00CE6B28 | |
Source: | Code function: | 1_2_00CE7CA0 | |
Source: | Code function: | 1_2_028DF420 | |
Source: | Code function: | 1_2_028DF68F | |
Source: | Code function: | 1_2_028DF60C | |
Source: | Code function: | 1_2_028DFAC1 | |
Source: | Code function: | 1_2_064B2610 | |
Source: | Code function: | 1_2_064B2C28 | |
Source: | Code function: | 1_2_064B0673 | |
Source: | Code function: | 1_2_064BF628 | |
Source: | Code function: | 1_2_064BD638 | |
Source: | Code function: | 1_2_064BDAC8 | |
Source: | Code function: | 1_2_064BFAB8 | |
Source: | Code function: | 1_2_064BDF58 | |
Source: | Code function: | 1_2_064B2F6E | |
Source: | Code function: | 1_2_064B0B30 | |
Source: | Code function: | 1_2_064B0B30 | |
Source: | Code function: | 1_2_064BE3E8 | |
Source: | Code function: | 1_2_064B0040 | |
Source: | Code function: | 1_2_064B0853 | |
Source: | Code function: | 1_2_064BE878 | |
Source: | Code function: | 1_2_064B2C1A | |
Source: | Code function: | 1_2_064BED08 | |
Source: | Code function: | 1_2_064BF198 | |
Source: | Code function: | 1_2_064BD1A8 | |
Source: | Code function: | 3_2_050603C4 | |
Source: | Code function: | 3_2_050603D0 | |
Source: | Code function: | 3_2_052E441B | |
Source: | Code function: | 3_2_052E40A8 | |
Source: | Code function: | 3_2_052E4098 | |
Source: | Code function: | 3_2_052E424E | |
Source: | Code function: | 3_2_052FDE49 | |
Source: | Code function: | 3_2_052FDE58 | |
Source: | Code function: | 4_2_00626ADC | |
Source: | Code function: | 4_2_00627E40 | |
Source: | Code function: | 4_2_0228F2C0 | |
Source: | Code function: | 4_2_0228F4AC | |
Source: | Code function: | 4_2_0228F961 | |
Source: | Code function: | 4_2_05E62EB0 | |
Source: | Code function: | 4_2_05E62A10 | |
Source: | Code function: | 4_2_05E6ED20 | |
Source: | Code function: | 4_2_05E6E400 | |
Source: | Code function: | 4_2_05E6DF70 | |
Source: | Code function: | 4_2_05E60673 | |
Source: | Code function: | 4_2_05E6F640 | |
Source: | Code function: | 4_2_05E6D650 | |
Source: | Code function: | 4_2_05E631F6 | |
Source: | Code function: | 4_2_05E6D1C0 | |
Source: | Code function: | 4_2_05E6F1B0 | |
Source: | Code function: | 4_2_05E6E890 | |
Source: | Code function: | 4_2_05E60040 | |
Source: | Code function: | 4_2_05E60853 | |
Source: | Code function: | 4_2_05E60B30 | |
Source: | Code function: | 4_2_05E60B30 | |
Source: | Code function: | 4_2_05E6DAE0 | |
Source: | Code function: | 4_2_05E6FAD0 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | COM Object queried: | Jump to behavior |
Source: | Code function: | 0_2_00EB1930 | |
Source: | Code function: | 0_2_00EB1921 | |
Source: | Code function: | 0_2_00EB2BA1 | |
Source: | Code function: | 0_2_00EB1BB0 | |
Source: | Code function: | 0_2_00EB1B4D | |
Source: | Code function: | 0_2_00EB1C06 | |
Source: | Code function: | 0_2_00EB2618 | |
Source: | Code function: | 0_2_00EB2613 | |
Source: | Code function: | 0_2_04E9956B | |
Source: | Code function: | 0_2_04E95660 | |
Source: | Code function: | 0_2_04E9F850 | |
Source: | Code function: | 0_2_04E97BF7 | |
Source: | Code function: | 0_2_04E91C48 | |
Source: | Code function: | 0_2_04E91C39 | |
Source: | Code function: | 0_2_04E95650 | |
Source: | Code function: | 0_2_04E9DB6F | |
Source: | Code function: | 0_2_04FF2B48 | |
Source: | Code function: | 0_2_04FF2B0C | |
Source: | Code function: | 0_2_05127118 | |
Source: | Code function: | 0_2_0512710A | |
Source: | Code function: | 0_2_0512E9B0 | |
Source: | Code function: | 0_2_051277CF | |
Source: | Code function: | 0_2_05120A5F | |
Source: | Code function: | 0_2_05120A70 | |
Source: | Code function: | 0_2_051E1A90 | |
Source: | Code function: | 0_2_051E1DBF | |
Source: | Code function: | 0_2_051E1DF9 | |
Source: | Code function: | 0_2_051E1630 | |
Source: | Code function: | 0_2_051E1622 | |
Source: | Code function: | 0_2_051E1E83 | |
Source: | Code function: | 0_2_051E1EC2 | |
Source: | Code function: | 0_2_051E49B8 | |
Source: | Code function: | 0_2_051E0006 | |
Source: | Code function: | 0_2_051E0040 | |
Source: | Code function: | 0_2_051E1B78 | |
Source: | Code function: | 0_2_051E1B6C | |
Source: | Code function: | 0_2_051E1BA7 | |
Source: | Code function: | 0_2_051E33A0 | |
Source: | Code function: | 0_2_051E1BEC | |
Source: | Code function: | 0_2_051E1A80 | |
Source: | Code function: | 0_2_051E1AFB | |
Source: | Code function: | 0_2_05250040 | |
Source: | Code function: | 0_2_0525BB20 | |
Source: | Code function: | 0_2_05252460 | |
Source: | Code function: | 0_2_05252450 | |
Source: | Code function: | 0_2_052538A8 | |
Source: | Code function: | 0_2_05253898 | |
Source: | Code function: | 0_2_0525BB10 | |
Source: | Code function: | 0_2_0526A0F8 | |
Source: | Code function: | 0_2_0542A758 | |
Source: | Code function: | 0_2_054203D5 | |
Source: | Code function: | 0_2_0542DAC0 | |
Source: | Code function: | 0_2_05429AEC | |
Source: | Code function: | 0_2_05427400 | |
Source: | Code function: | 0_2_0542A749 | |
Source: | Code function: | 0_2_05420040 | |
Source: | Code function: | 0_2_05420006 | |
Source: | Code function: | 0_2_0542F0B8 | |
Source: | Code function: | 0_2_054273F0 | |
Source: | Code function: | 0_2_0542DDE7 | |
Source: | Code function: | 0_2_054CE120 | |
Source: | Code function: | 0_2_054B0040 | |
Source: | Code function: | 0_2_054B0006 | |
Source: | Code function: | 1_2_00CE2944 | |
Source: | Code function: | 1_2_00CE32D0 | |
Source: | Code function: | 1_2_00CE4270 | |
Source: | Code function: | 1_2_00CE2938 | |
Source: | Code function: | 1_2_00CEEE28 | |
Source: | Code function: | 1_2_00CE1DF8 | |
Source: | Code function: | 1_2_00CE1E08 | |
Source: | Code function: | 1_2_028DD278 | |
Source: | Code function: | 1_2_028D5360 | |
Source: | Code function: | 1_2_028DA088 | |
Source: | Code function: | 1_2_028DC146 | |
Source: | Code function: | 1_2_028DC738 | |
Source: | Code function: | 1_2_028DC468 | |
Source: | Code function: | 1_2_028DCA08 | |
Source: | Code function: | 1_2_028DE988 | |
Source: | Code function: | 1_2_028D69A0 | |
Source: | Code function: | 1_2_028DCFA9 | |
Source: | Code function: | 1_2_028D6FC8 | |
Source: | Code function: | 1_2_028DCCD8 | |
Source: | Code function: | 1_2_028DFAC1 | |
Source: | Code function: | 1_2_028D39ED | |
Source: | Code function: | 1_2_028D29EC | |
Source: | Code function: | 1_2_028DE97B | |
Source: | Code function: | 1_2_028D3E09 | |
Source: | Code function: | 1_2_064B2610 | |
Source: | Code function: | 1_2_064B8FE8 | |
Source: | Code function: | 1_2_064B1850 | |
Source: | Code function: | 1_2_064B4CE8 | |
Source: | Code function: | 1_2_064B9930 | |
Source: | Code function: | 1_2_064B2600 | |
Source: | Code function: | 1_2_064BF619 | |
Source: | Code function: | 1_2_064BD629 | |
Source: | Code function: | 1_2_064BF628 | |
Source: | Code function: | 1_2_064BD638 | |
Source: | Code function: | 1_2_064BDAC8 | |
Source: | Code function: | 1_2_064BFAA9 | |
Source: | Code function: | 1_2_064BDAB9 | |
Source: | Code function: | 1_2_064BFAB8 | |
Source: | Code function: | 1_2_064BDF49 | |
Source: | Code function: | 1_2_064BDF58 | |
Source: | Code function: | 1_2_064B9710 | |
Source: | Code function: | 1_2_064B0B20 | |
Source: | Code function: | 1_2_064B0B30 | |
Source: | Code function: | 1_2_064B8FD8 | |
Source: | Code function: | 1_2_064BE3D8 | |
Source: | Code function: | 1_2_064BE3E8 | |
Source: | Code function: | 1_2_064B1841 | |
Source: | Code function: | 1_2_064B0040 | |
Source: | Code function: | 1_2_064B8850 | |
Source: | Code function: | 1_2_064BE868 | |
Source: | Code function: | 1_2_064B8860 | |
Source: | Code function: | 1_2_064BE878 | |
Source: | Code function: | 1_2_064B003F | |
Source: | Code function: | 1_2_064B4CDE | |
Source: | Code function: | 1_2_064BECF8 | |
Source: | Code function: | 1_2_064BED08 | |
Source: | Code function: | 1_2_064BF188 | |
Source: | Code function: | 1_2_064BF198 | |
Source: | Code function: | 1_2_064BD198 | |
Source: | Code function: | 1_2_064BD1A8 | |
Source: | Code function: | 3_2_00E01930 | |
Source: | Code function: | 3_2_00E01921 | |
Source: | Code function: | 3_2_00E02BA2 | |
Source: | Code function: | 3_2_00E01BB0 | |
Source: | Code function: | 3_2_00E01B4D | |
Source: | Code function: | 3_2_00E01C06 | |
Source: | Code function: | 3_2_00E02613 | |
Source: | Code function: | 3_2_00E02618 | |
Source: | Code function: | 3_2_0506956B | |
Source: | Code function: | 3_2_05065660 | |
Source: | Code function: | 3_2_0506F850 | |
Source: | Code function: | 3_2_05067BF7 | |
Source: | Code function: | 3_2_05061C39 | |
Source: | Code function: | 3_2_05061C48 | |
Source: | Code function: | 3_2_0506DB6F | |
Source: | Code function: | 3_2_051B7118 | |
Source: | Code function: | 3_2_051B710A | |
Source: | Code function: | 3_2_051BE9B0 | |
Source: | Code function: | 3_2_051B77CF | |
Source: | Code function: | 3_2_051B0A5F | |
Source: | Code function: | 3_2_051B0A70 | |
Source: | Code function: | 3_2_05271A90 | |
Source: | Code function: | 3_2_05271DBF | |
Source: | Code function: | 3_2_05271DF9 | |
Source: | Code function: | 3_2_05271622 | |
Source: | Code function: | 3_2_05271630 | |
Source: | Code function: | 3_2_05271E83 | |
Source: | Code function: | 3_2_05271EC2 | |
Source: | Code function: | 3_2_052749B8 | |
Source: | Code function: | 3_2_05270006 | |
Source: | Code function: | 3_2_05270040 | |
Source: | Code function: | 3_2_05271B6C | |
Source: | Code function: | 3_2_05271B78 | |
Source: | Code function: | 3_2_05271BA7 | |
Source: | Code function: | 3_2_052733A0 | |
Source: | Code function: | 3_2_05271BEC | |
Source: | Code function: | 3_2_05271A80 | |
Source: | Code function: | 3_2_05271AFB | |
Source: | Code function: | 3_2_052E0040 | |
Source: | Code function: | 3_2_052E2460 | |
Source: | Code function: | 3_2_052E2450 | |
Source: | Code function: | 3_2_052E38A8 | |
Source: | Code function: | 3_2_052E3898 | |
Source: | Code function: | 3_2_052FA0F8 | |
Source: | Code function: | 3_2_054B03D5 | |
Source: | Code function: | 3_2_054BDAC0 | |
Source: | Code function: | 3_2_054B9AEC | |
Source: | Code function: | 3_2_054B7400 | |
Source: | Code function: | 3_2_054BA74C | |
Source: | Code function: | 3_2_054BA758 | |
Source: | Code function: | 3_2_054B0040 | |
Source: | Code function: | 3_2_054B0006 | |
Source: | Code function: | 3_2_054BF0B8 | |
Source: | Code function: | 3_2_054B73F0 | |
Source: | Code function: | 3_2_054BDDE7 | |
Source: | Code function: | 3_2_0555E120 | |
Source: | Code function: | 3_2_05540040 | |
Source: | Code function: | 3_2_05540006 | |
Source: | Code function: | 4_2_006242FD | |
Source: | Code function: | 4_2_006221F8 | |
Source: | Code function: | 4_2_00622208 | |
Source: | Code function: | 4_2_0228D278 | |
Source: | Code function: | 4_2_02285370 | |
Source: | Code function: | 4_2_0228C147 | |
Source: | Code function: | 4_2_0228C738 | |
Source: | Code function: | 4_2_0228C468 | |
Source: | Code function: | 4_2_0228CA08 | |
Source: | Code function: | 4_2_022869A0 | |
Source: | Code function: | 4_2_0228E988 | |
Source: | Code function: | 4_2_02283E09 | |
Source: | Code function: | 4_2_0228CFAA | |
Source: | Code function: | 4_2_02286FC8 | |
Source: | Code function: | 4_2_0228CCD8 | |
Source: | Code function: | 4_2_02289DE0 | |
Source: | Code function: | 4_2_02283AA1 | |
Source: | Code function: | 4_2_0228F961 | |
Source: | Code function: | 4_2_0228E97A | |
Source: | Code function: | 4_2_022829EC | |
Source: | Code function: | 4_2_022839EF | |
Source: | Code function: | 4_2_05E69408 | |
Source: | Code function: | 4_2_05E65108 | |
Source: | Code function: | 4_2_05E61850 | |
Source: | Code function: | 4_2_05E69AD8 | |
Source: | Code function: | 4_2_05E62A10 | |
Source: | Code function: | 4_2_05E6ED20 | |
Source: | Code function: | 4_2_05E6ED10 | |
Source: | Code function: | 4_2_05E68C80 | |
Source: | Code function: | 4_2_05E68C70 | |
Source: | Code function: | 4_2_05E6E400 | |
Source: | Code function: | 4_2_05E6DF61 | |
Source: | Code function: | 4_2_05E6DF70 | |
Source: | Code function: | 4_2_05E6F640 | |
Source: | Code function: | 4_2_05E6D641 | |
Source: | Code function: | 4_2_05E6D650 | |
Source: | Code function: | 4_2_05E6F631 | |
Source: | Code function: | 4_2_05E6D1C0 | |
Source: | Code function: | 4_2_05E6F1A0 | |
Source: | Code function: | 4_2_05E6F1B0 | |
Source: | Code function: | 4_2_05E6D1B0 | |
Source: | Code function: | 4_2_05E650FE | |
Source: | Code function: | 4_2_05E6E880 | |
Source: | Code function: | 4_2_05E6E890 | |
Source: | Code function: | 4_2_05E60040 | |
Source: | Code function: | 4_2_05E61841 | |
Source: | Code function: | 4_2_05E6003F | |
Source: | Code function: | 4_2_05E6E3F0 | |
Source: | Code function: | 4_2_05E693F8 | |
Source: | Code function: | 4_2_05E60B20 | |
Source: | Code function: | 4_2_05E60B30 | |
Source: | Code function: | 4_2_05E6DAE0 | |
Source: | Code function: | 4_2_05E6FAC1 | |
Source: | Code function: | 4_2_05E6FAD0 | |
Source: | Code function: | 4_2_05E6DAD1 | |
Source: | Code function: | 4_2_05E62A00 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Process created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_04E94FE2 | |
Source: | Code function: | 0_2_05121D73 | |
Source: | Code function: | 0_2_0512A995 | |
Source: | Code function: | 0_2_0512D881 | |
Source: | Code function: | 0_2_05122611 | |
Source: | Code function: | 0_2_051EED61 | |
Source: | Code function: | 0_2_051EB461 | |
Source: | Code function: | 0_2_051E0728 | |
Source: | Code function: | 0_2_051EF1C7 | |
Source: | Code function: | 0_2_051EA85B | |
Source: | Code function: | 0_2_05268405 | |
Source: | Code function: | 0_2_052683AB | |
Source: | Code function: | 1_2_00CE28BA | |
Source: | Code function: | 1_2_00CE6C1A | |
Source: | Code function: | 1_2_00CE3076 | |
Source: | Code function: | 1_2_00CE3046 | |
Source: | Code function: | 1_2_00CEF7CE | |
Source: | Code function: | 1_2_00CE3896 | |
Source: | Code function: | 1_2_00CE3A46 | |
Source: | Code function: | 1_2_00CE7DB0 | |
Source: | Code function: | 1_2_064B8448 | |
Source: | Code function: | 1_2_064BC210 | |
Source: | Code function: | 1_2_064B8520 | |
Source: | Code function: | 1_2_064B2519 | |
Source: | Code function: | 1_2_064B25B1 | |
Source: | Code function: | 3_2_0506CC52 | |
Source: | Code function: | 3_2_05064FE2 | |
Source: | Code function: | 3_2_0506E09D | |
Source: | Code function: | 3_2_0506E235 | |
Source: | Code function: | 3_2_051BA995 | |
Source: | Code function: | 3_2_0527B461 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 1_2_064B8FE8 |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 111 Scripting | Valid Accounts | 2 Command and Scripting Interpreter | 111 Scripting | 1 DLL Side-Loading | 1 Disable or Modify Tools | 1 OS Credential Dumping | 2 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 DLL Side-Loading | 11 Process Injection | 3 Obfuscated Files or Information | LSASS Memory | 13 System Information Discovery | Remote Desktop Protocol | 1 Data from Local System | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 12 Software Packing | Security Account Manager | 21 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 11 Encrypted Channel | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Registry Run Keys / Startup Folder | 2 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | NTDS | 1 Process Discovery | Distributed Component Object Model | 1 Clipboard Data | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Masquerading | LSA Secrets | 31 Virtualization/Sandbox Evasion | SSH | Keylogging | 24 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 31 Virtualization/Sandbox Evasion | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 11 Process Injection | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
70% | Virustotal | Browse | ||
63% | ReversingLabs | ByteCode-MSIL.Infostealer.Browsstl | ||
100% | Avira | TR/AD.GenSteal.frzkf |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/AD.GenSteal.frzkf | ||
70% | Virustotal | Browse | ||
63% | ReversingLabs | ByteCode-MSIL.Infostealer.Browsstl |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
mail.iaa-airferight.com | 46.175.148.58 | true | false | high | |
reallyfreegeoip.org | 104.21.96.1 | true | false | high | |
api.telegram.org | 149.154.167.220 | true | false | high | |
checkip.dyndns.com | 158.101.44.242 | true | false | high | |
checkip.dyndns.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | false | |
46.175.148.58 | mail.iaa-airferight.com | Ukraine | 56394 | ASLAGIDKOM-NETUA | false | |
104.21.96.1 | reallyfreegeoip.org | United States | 13335 | CLOUDFLARENETUS | false | |
158.101.44.242 | checkip.dyndns.com | United States | 31898 | ORACLE-BMC-31898US | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1634876 |
Start date and time: | 2025-03-11 06:09:02 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 9m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | pbgjw8i8N7.exerenamed because original name is a hash value |
Original Sample Name: | 44095f79a9e682a29ed75fab33f6dcf1e2f11937097e4c7e3f84080ff7444048.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.expl.evad.winEXE@8/3@4/4 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 23.199.214.10, 52.149.20.212, 150.171.27.10
- Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, g.bing.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
01:10:03 | API Interceptor | |
06:09:59 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
149.154.167.220 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | CryptOne, Snake Keylogger | Browse | |||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
46.175.148.58 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | ||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
104.21.96.1 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Azorult | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Azorult | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
reallyfreegeoip.org | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | CryptOne, Snake Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
mail.iaa-airferight.com | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
api.telegram.org | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | CryptOne, Snake Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TELEGRAMRU | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | CryptOne, Snake Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
ASLAGIDKOM-NETUA | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
ORACLE-BMC-31898US | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | CryptOne, Snake Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | CryptOne, Snake Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | CryptOne, Snake Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
|
⊘No context
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\XsdType.vbs 
Download File
Process: | C:\Users\user\Desktop\pbgjw8i8N7.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 83 |
Entropy (8bit): | 4.8540896607743065 |
Encrypted: | false |
SSDEEP: | 3:FER/n0eFHHoUkh4EaKC54xkAJHn:FER/lFHI9aZ54xkQ |
MD5: | 061D0A86AEDA15C377568F4B29BBAF18 |
SHA1: | 837000CED0C724D9D9E4435B8DEC8F9D9D66DE0D |
SHA-256: | E07469C6D38C6555ECA0663828E9AE9096CB6F2DCD4AF5005B1A5BFFF2BAAE51 |
SHA-512: | F527B876A4BE2E0EFED2385FA4C19CC58729A95E39C5AC32A09B014FA5EB1233EFC467655DAE802245440FD99A80873F1B385694A67B09FB7E909CE9070A15AA |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\pbgjw8i8N7.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2034176 |
Entropy (8bit): | 7.188926297239984 |
Encrypted: | false |
SSDEEP: | 24576:SUeQg2PvNPjxiF1LeVFJ03GDJuwAP3OED/NSq66+0wZPK8FbqFnAYJytaEVarmmI:tNrxiHUJK8lAP3vD/A0uC8tBcytaeXd |
MD5: | 679DA76A671452DE2F13A1585028E74E |
SHA1: | E89C5B5D3B31025710714C14955D22820E2ED493 |
SHA-256: | 44095F79A9E682A29ED75FAB33F6DCF1E2F11937097E4C7E3F84080FF7444048 |
SHA-512: | E21D43F7BBFD77CE1FDCCF438655385EE1EFD026F29ADBA0C1E979186DE0B28B8495C97ED4E89B9324D484B0DB4CE9C9E5D29964D4DF395BE54F6477D086959C |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\pbgjw8i8N7.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.188926297239984 |
TrID: |
|
File name: | pbgjw8i8N7.exe |
File size: | 2'034'176 bytes |
MD5: | 679da76a671452de2f13a1585028e74e |
SHA1: | e89c5b5d3b31025710714c14955d22820e2ed493 |
SHA256: | 44095f79a9e682a29ed75fab33f6dcf1e2f11937097e4c7e3f84080ff7444048 |
SHA512: | e21d43f7bbfd77ce1fdccf438655385ee1efd026f29adba0c1e979186de0b28b8495c97ed4e89b9324d484b0db4ce9c9e5d29964d4df395be54f6477d086959c |
SSDEEP: | 24576:SUeQg2PvNPjxiF1LeVFJ03GDJuwAP3OED/NSq66+0wZPK8FbqFnAYJytaEVarmmI:tNrxiHUJK8lAP3vD/A0uC8tBcytaeXd |
TLSH: | 2A957D0BF79A47A1D274573EC8AB081CA3A4E58267D3DF1E374A235908E37BB8D41617 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...<U.g................................. ... ....@.. .......................`............`................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x5f1e9e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67B7553C [Thu Feb 20 16:15:56 2025 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x1f1e50 | 0x4b | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x1f2000 | 0x598 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x1f4000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x1efea4 | 0x1f0000 | d03b9bac6ae442dab3dbcb8283e6b212 | False | 0.7072488107988911 | data | 7.19209181797832 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x1f2000 | 0x598 | 0x600 | a728d9befd81068fd0b723357e4d78c7 | False | 0.4147135416666667 | data | 4.067971838205649 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x1f4000 | 0xc | 0x200 | 076cee7609f3daeac8d8b0882acc6e9f | False | 0.044921875 | MacBinary, Mon Feb 6 07:28:16 2040 INVALID date, modified Mon Feb 6 07:28:16 2040 "\037" | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x1f20a0 | 0x30c | data | 0.4256410256410256 | ||
RT_MANIFEST | 0x1f23ac | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Description | Data |
---|---|
Translation | 0x0000 0x04b0 |
Comments | |
CompanyName | |
FileDescription | Jurfzqn |
FileVersion | 1.0.0.0 |
InternalName | Jurfzqn.exe |
LegalCopyright | Copyright 2017 |
LegalTrademarks | |
OriginalFilename | Jurfzqn.exe |
ProductName | Jurfzqn |
ProductVersion | 1.0.0.0 |
Assembly Version | 1.0.0.0 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T06:09:59.024815+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49712 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:04.872621+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49712 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:07.153657+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49714 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:16.717744+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:18.915468+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49719 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:24.107212+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49716 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:27.857004+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49716 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:30.004518+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49726 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:30.716397+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49728 | 158.101.44.242 | 80 | TCP |
2025-03-11T06:10:34.050375+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49729 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:45.740940+0100 | 1810007 | Joe Security ANOMALY Telegram Send Message | 1 | 192.168.2.5 | 49745 | 149.154.167.220 | 443 | TCP |
2025-03-11T06:10:49.188792+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49748 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:52.152063+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49750 | 104.21.96.1 | 443 | TCP |
2025-03-11T06:10:54.564569+0100 | 1810007 | Joe Security ANOMALY Telegram Send Message | 1 | 192.168.2.5 | 49753 | 149.154.167.220 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 11, 2025 06:09:58.196594000 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:09:58.201539040 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:09:58.201631069 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:09:58.201845884 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:09:58.206703901 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:09:58.804289103 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:09:58.809731007 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:09:58.814605951 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:09:58.969089031 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:09:59.024815083 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:09:59.184804916 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:09:59.184845924 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:09:59.184916973 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:09:59.195746899 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:09:59.195763111 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:01.023005009 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:01.023175001 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:01.028198004 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:01.028213978 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:01.028573990 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:01.075717926 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:01.098586082 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:01.144330025 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:01.514763117 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:01.514834881 CET | 443 | 49713 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:01.514961958 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:01.536267996 CET | 49713 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:01.540587902 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:01.545878887 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:04.818378925 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:04.851866007 CET | 49714 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:04.851918936 CET | 443 | 49714 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:04.851999998 CET | 49714 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:04.852268934 CET | 49714 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:04.852287054 CET | 443 | 49714 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:04.872621059 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:06.655890942 CET | 443 | 49714 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:06.658418894 CET | 49714 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:06.658446074 CET | 443 | 49714 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:07.153671026 CET | 443 | 49714 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:07.187417984 CET | 443 | 49714 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:07.187485933 CET | 49714 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:07.187844038 CET | 49714 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:07.191013098 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:07.192315102 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:07.195959091 CET | 80 | 49712 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:07.196023941 CET | 49712 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:07.197169065 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:07.197247028 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:07.197340012 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:07.202102900 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:10.489057064 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:10.494088888 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:10.494184017 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:10.494441032 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:10.499280930 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:16.672739983 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:16.674268961 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:16.674312115 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:16.674541950 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:16.674657106 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:16.674668074 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:16.717744112 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:18.433254004 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:18.435569048 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:18.435590029 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:18.796195030 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:18.799894094 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:18.804873943 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:18.915431976 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:18.915515900 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:18.915601015 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:18.916363955 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:18.923038960 CET | 49721 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:18.927947044 CET | 80 | 49721 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:18.928029060 CET | 49721 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:18.928136110 CET | 49721 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:18.932892084 CET | 80 | 49721 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:24.057415009 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:24.094259977 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:24.094338894 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:24.095242977 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:24.101233006 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:24.101257086 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:24.107212067 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:24.490513086 CET | 80 | 49721 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:24.492300987 CET | 49724 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:24.492351055 CET | 443 | 49724 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:24.492444038 CET | 49724 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:24.492710114 CET | 49724 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:24.492716074 CET | 443 | 49724 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:24.544517040 CET | 49721 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:25.970891953 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:25.971016884 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:25.972632885 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:25.972647905 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:25.972912073 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.013284922 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:26.020716906 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:26.068326950 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.207742929 CET | 443 | 49724 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.209573030 CET | 49724 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:26.209595919 CET | 443 | 49724 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.448091030 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.448158026 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.448225021 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:26.451183081 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:26.454727888 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:26.459640980 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:26.709454060 CET | 443 | 49724 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.709635019 CET | 443 | 49724 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:26.710135937 CET | 49724 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:26.710135937 CET | 49724 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:26.713639021 CET | 49721 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:26.714632034 CET | 49725 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:26.718704939 CET | 80 | 49721 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:26.718750954 CET | 49721 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:26.719412088 CET | 80 | 49725 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:26.719482899 CET | 49725 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:26.719578028 CET | 49725 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:26.724317074 CET | 80 | 49725 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:27.801373005 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:27.803348064 CET | 49726 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:27.803395033 CET | 443 | 49726 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:27.803452015 CET | 49726 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:27.803725004 CET | 49726 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:27.803739071 CET | 443 | 49726 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:27.857003927 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:28.659517050 CET | 80 | 49725 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:28.662779093 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:28.662834883 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:28.662935972 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:28.663168907 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:28.663182974 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:28.716413021 CET | 49725 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:29.523813963 CET | 443 | 49726 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:29.525787115 CET | 49726 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:29.525830030 CET | 443 | 49726 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.004548073 CET | 443 | 49726 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.004611969 CET | 443 | 49726 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.004674911 CET | 49726 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.005197048 CET | 49726 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.009097099 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.010252953 CET | 49728 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.014256001 CET | 80 | 49716 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:30.014348984 CET | 49716 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.015130043 CET | 80 | 49728 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:30.015218973 CET | 49728 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.015328884 CET | 49728 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.020148039 CET | 80 | 49728 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:30.323795080 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.325453043 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.325485945 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.665066004 CET | 80 | 49728 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:30.669235945 CET | 49729 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.669292927 CET | 443 | 49729 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.669374943 CET | 49729 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.669650078 CET | 49729 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.669662952 CET | 443 | 49729 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.716397047 CET | 49728 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.810040951 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.810132027 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:30.810201883 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.810945034 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:30.815278053 CET | 49725 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.816453934 CET | 49730 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.820391893 CET | 80 | 49725 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:30.820466995 CET | 49725 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.822271109 CET | 80 | 49730 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:30.822390079 CET | 49730 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.822541952 CET | 49730 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:30.827383041 CET | 80 | 49730 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:31.433689117 CET | 80 | 49730 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:31.435121059 CET | 49731 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:31.435180902 CET | 443 | 49731 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:31.435383081 CET | 49731 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:31.435709953 CET | 49731 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:31.435728073 CET | 443 | 49731 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:31.482038975 CET | 49730 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:33.571739912 CET | 443 | 49729 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:33.573477983 CET | 49729 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:33.573510885 CET | 443 | 49729 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:33.595948935 CET | 443 | 49731 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:33.597489119 CET | 49731 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:33.597522020 CET | 443 | 49731 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.050415039 CET | 443 | 49729 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.050478935 CET | 443 | 49729 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.050540924 CET | 49729 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.051345110 CET | 49729 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.055862904 CET | 49732 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.061263084 CET | 80 | 49732 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:34.061330080 CET | 49732 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.061528921 CET | 49732 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.067306042 CET | 80 | 49732 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:34.102574110 CET | 443 | 49731 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.102634907 CET | 443 | 49731 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.102735043 CET | 49731 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.103251934 CET | 49731 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.107259035 CET | 49730 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.109204054 CET | 49733 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.113286018 CET | 80 | 49730 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:34.113337994 CET | 49730 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.115147114 CET | 80 | 49733 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:34.115268946 CET | 49733 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.115523100 CET | 49733 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.120488882 CET | 80 | 49733 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:34.633016109 CET | 80 | 49732 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:34.634454012 CET | 49734 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.634507895 CET | 443 | 49734 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.634660959 CET | 49734 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.635020971 CET | 49734 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.635036945 CET | 443 | 49734 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.685179949 CET | 49732 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:34.715038061 CET | 80 | 49733 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:34.717171907 CET | 49735 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.717212915 CET | 443 | 49735 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.717284918 CET | 49735 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.717713118 CET | 49735 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:34.717725039 CET | 443 | 49735 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:34.764244080 CET | 49733 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:36.692977905 CET | 443 | 49734 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:36.694638014 CET | 49734 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:36.694674969 CET | 443 | 49734 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:36.703741074 CET | 443 | 49735 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:36.705287933 CET | 49735 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:36.705378056 CET | 443 | 49735 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.166501045 CET | 443 | 49734 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.166577101 CET | 443 | 49734 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.166621923 CET | 49734 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.167105913 CET | 49734 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.169821978 CET | 443 | 49735 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.169982910 CET | 443 | 49735 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.170315027 CET | 49735 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.170538902 CET | 49735 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.171906948 CET | 49732 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.172130108 CET | 49736 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.174561024 CET | 49733 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.175118923 CET | 49737 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.176990986 CET | 80 | 49732 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.177011013 CET | 80 | 49736 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.177062035 CET | 49732 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.177144051 CET | 49736 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.177220106 CET | 49736 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.179534912 CET | 80 | 49733 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.179588079 CET | 49733 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.179954052 CET | 80 | 49737 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.180053949 CET | 49737 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.180102110 CET | 49737 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.182015896 CET | 80 | 49736 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.184938908 CET | 80 | 49737 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.753390074 CET | 80 | 49737 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.754750967 CET | 49738 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.754806995 CET | 443 | 49738 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.754900932 CET | 49738 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.755168915 CET | 49738 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.755182028 CET | 443 | 49738 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.769226074 CET | 80 | 49736 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:37.770575047 CET | 49739 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.770620108 CET | 443 | 49739 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.770802021 CET | 49739 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.771034956 CET | 49739 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:37.771047115 CET | 443 | 49739 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:37.794564962 CET | 49737 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:37.810261965 CET | 49736 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:39.583549023 CET | 443 | 49739 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:39.583767891 CET | 443 | 49738 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:39.585258007 CET | 49738 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:39.585273027 CET | 443 | 49738 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:39.586363077 CET | 49739 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:39.586388111 CET | 443 | 49739 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.120002031 CET | 443 | 49738 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.120014906 CET | 443 | 49739 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.120080948 CET | 443 | 49738 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.120093107 CET | 443 | 49739 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.120232105 CET | 49738 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.120240927 CET | 49739 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.120704889 CET | 49739 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.120716095 CET | 49738 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.124272108 CET | 49737 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.124926090 CET | 49736 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.124926090 CET | 49740 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.124988079 CET | 49741 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.129280090 CET | 80 | 49737 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.129403114 CET | 49737 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.129883051 CET | 80 | 49736 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.129908085 CET | 80 | 49740 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.129920959 CET | 80 | 49741 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.129940987 CET | 49736 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.129985094 CET | 49740 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.130079985 CET | 49740 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.130079985 CET | 49741 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.130145073 CET | 49741 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.134824038 CET | 80 | 49740 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.134917021 CET | 80 | 49741 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.711698055 CET | 80 | 49740 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.713227034 CET | 49742 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.713267088 CET | 443 | 49742 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.713352919 CET | 49742 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.713639975 CET | 49742 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.713644981 CET | 80 | 49741 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:40.713650942 CET | 443 | 49742 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.714786053 CET | 49743 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.714848042 CET | 443 | 49743 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.714910984 CET | 49743 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.715167999 CET | 49743 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:40.715188980 CET | 443 | 49743 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:40.763462067 CET | 49740 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:40.766407013 CET | 49741 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:42.491727114 CET | 443 | 49742 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:42.493666887 CET | 49742 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:42.493684053 CET | 443 | 49742 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:42.543528080 CET | 443 | 49743 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:42.545352936 CET | 49743 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:42.545372009 CET | 443 | 49743 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:42.980353117 CET | 443 | 49742 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:42.980429888 CET | 443 | 49742 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:42.980535030 CET | 49742 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:42.981141090 CET | 49742 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:42.985301018 CET | 49740 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:42.986653090 CET | 49744 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:43.200967073 CET | 80 | 49744 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:43.200983047 CET | 80 | 49740 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:43.201069117 CET | 49740 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:43.201098919 CET | 443 | 49743 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:43.201092958 CET | 49744 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:43.201181889 CET | 443 | 49743 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:43.201225996 CET | 49743 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:43.201354027 CET | 49744 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:43.201726913 CET | 49743 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:43.206269026 CET | 80 | 49744 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:43.353679895 CET | 49741 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:43.358933926 CET | 80 | 49741 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:43.359015942 CET | 49741 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:43.362276077 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:43.362337112 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:43.362431049 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:43.362896919 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:43.362910032 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:43.793822050 CET | 80 | 49744 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:43.795388937 CET | 49746 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:43.795438051 CET | 443 | 49746 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:43.795530081 CET | 49746 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:43.795797110 CET | 49746 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:43.795811892 CET | 443 | 49746 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:43.841443062 CET | 49744 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:45.210735083 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:45.210974932 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:45.212857962 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:45.212867975 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:45.213140011 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:45.214550018 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:45.260332108 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:45.625278950 CET | 443 | 49746 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:45.626995087 CET | 49746 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:45.627031088 CET | 443 | 49746 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:45.741005898 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:45.741099119 CET | 443 | 49745 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:45.741183996 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:45.762387991 CET | 49745 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:46.100775957 CET | 443 | 49746 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:46.100856066 CET | 443 | 49746 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:46.100958109 CET | 49746 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:46.101470947 CET | 49746 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:46.104734898 CET | 49744 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:46.105848074 CET | 49747 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:46.109833002 CET | 80 | 49744 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:46.109918118 CET | 49744 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:46.110699892 CET | 80 | 49747 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:46.110789061 CET | 49747 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:46.110882044 CET | 49747 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:46.115700960 CET | 80 | 49747 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:46.695955992 CET | 80 | 49747 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:46.702601910 CET | 49748 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:46.702665091 CET | 443 | 49748 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:46.702729940 CET | 49748 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:46.703011990 CET | 49748 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:46.703026056 CET | 443 | 49748 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:46.749979019 CET | 49747 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:48.688457012 CET | 443 | 49748 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:48.690203905 CET | 49748 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:48.690253019 CET | 443 | 49748 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:49.188817024 CET | 443 | 49748 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:49.212374926 CET | 443 | 49748 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:49.212505102 CET | 49748 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:49.212956905 CET | 49748 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:49.235582113 CET | 49747 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:49.236691952 CET | 49749 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:49.241055965 CET | 80 | 49747 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:49.241131067 CET | 49747 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:49.241580009 CET | 80 | 49749 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:49.241641998 CET | 49749 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:49.241878033 CET | 49749 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:49.246718884 CET | 80 | 49749 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:49.821760893 CET | 80 | 49749 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:49.827111006 CET | 49750 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:49.827159882 CET | 443 | 49750 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:49.827224016 CET | 49750 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:49.836088896 CET | 49750 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:49.836116076 CET | 443 | 49750 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:49.872706890 CET | 49749 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:51.674071074 CET | 443 | 49750 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:51.675717115 CET | 49750 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:51.675748110 CET | 443 | 49750 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:51.720437050 CET | 49751 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:10:51.720566034 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:52.152093887 CET | 443 | 49750 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:52.152172089 CET | 443 | 49750 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 06:10:52.152242899 CET | 49750 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:52.152668953 CET | 49750 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 06:10:52.163111925 CET | 49749 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:52.163995028 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:52.164030075 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:52.164084911 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:52.164516926 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:52.164526939 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:52.168147087 CET | 80 | 49749 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 06:10:52.168205976 CET | 49749 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:10:52.732116938 CET | 49751 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:10:53.992244959 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:53.992398977 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:53.994050980 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:53.994062901 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:53.994405985 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:53.995883942 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:54.036329985 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:54.564598083 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:54.564682961 CET | 443 | 49753 | 149.154.167.220 | 192.168.2.5 |
Mar 11, 2025 06:10:54.564763069 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:54.567018032 CET | 49753 | 443 | 192.168.2.5 | 149.154.167.220 |
Mar 11, 2025 06:10:54.732146978 CET | 49751 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:10:58.732254982 CET | 49751 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:10:59.692954063 CET | 49754 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:10:59.692958117 CET | 49728 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 06:11:00.700939894 CET | 49754 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:02.700942993 CET | 49754 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:06.716516972 CET | 49754 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:06.732148886 CET | 49751 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:14.732218981 CET | 49754 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:21.830097914 CET | 49755 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:22.841634989 CET | 49755 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:24.857237101 CET | 49755 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:28.857407093 CET | 49755 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:29.829961061 CET | 49756 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:30.841613054 CET | 49756 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:32.841690063 CET | 49756 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:36.841599941 CET | 49756 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:36.857238054 CET | 49755 | 25 | 192.168.2.5 | 46.175.148.58 |
Mar 11, 2025 06:11:44.855026007 CET | 49756 | 25 | 192.168.2.5 | 46.175.148.58 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 11, 2025 06:09:58.183087111 CET | 63645 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 06:09:58.189814091 CET | 53 | 63645 | 1.1.1.1 | 192.168.2.5 |
Mar 11, 2025 06:09:59.174424887 CET | 59165 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 06:09:59.184005022 CET | 53 | 59165 | 1.1.1.1 | 192.168.2.5 |
Mar 11, 2025 06:10:43.354370117 CET | 64380 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 06:10:43.361470938 CET | 53 | 64380 | 1.1.1.1 | 192.168.2.5 |
Mar 11, 2025 06:10:51.709068060 CET | 57115 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 06:10:51.719671965 CET | 53 | 57115 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 11, 2025 06:09:58.183087111 CET | 192.168.2.5 | 1.1.1.1 | 0x2b24 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2025 06:09:59.174424887 CET | 192.168.2.5 | 1.1.1.1 | 0xfa64 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2025 06:10:43.354370117 CET | 192.168.2.5 | 1.1.1.1 | 0x2522 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2025 06:10:51.709068060 CET | 192.168.2.5 | 1.1.1.1 | 0xbd97 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 11, 2025 06:09:58.189814091 CET | 1.1.1.1 | 192.168.2.5 | 0x2b24 | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:58.189814091 CET | 1.1.1.1 | 192.168.2.5 | 0x2b24 | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:58.189814091 CET | 1.1.1.1 | 192.168.2.5 | 0x2b24 | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:58.189814091 CET | 1.1.1.1 | 192.168.2.5 | 0x2b24 | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:58.189814091 CET | 1.1.1.1 | 192.168.2.5 | 0x2b24 | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:58.189814091 CET | 1.1.1.1 | 192.168.2.5 | 0x2b24 | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:59.184005022 CET | 1.1.1.1 | 192.168.2.5 | 0xfa64 | No error (0) | 104.21.96.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:59.184005022 CET | 1.1.1.1 | 192.168.2.5 | 0xfa64 | No error (0) | 104.21.48.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:59.184005022 CET | 1.1.1.1 | 192.168.2.5 | 0xfa64 | No error (0) | 104.21.64.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:59.184005022 CET | 1.1.1.1 | 192.168.2.5 | 0xfa64 | No error (0) | 104.21.80.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:59.184005022 CET | 1.1.1.1 | 192.168.2.5 | 0xfa64 | No error (0) | 104.21.32.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:59.184005022 CET | 1.1.1.1 | 192.168.2.5 | 0xfa64 | No error (0) | 104.21.112.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:09:59.184005022 CET | 1.1.1.1 | 192.168.2.5 | 0xfa64 | No error (0) | 104.21.16.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:10:43.361470938 CET | 1.1.1.1 | 192.168.2.5 | 0x2522 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 06:10:51.719671965 CET | 1.1.1.1 | 192.168.2.5 | 0xbd97 | No error (0) | 46.175.148.58 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49712 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:09:58.201845884 CET | 151 | OUT | |
Mar 11, 2025 06:09:58.804289103 CET | 321 | IN | |
Mar 11, 2025 06:09:58.809731007 CET | 127 | OUT | |
Mar 11, 2025 06:09:58.969089031 CET | 321 | IN | |
Mar 11, 2025 06:10:01.540587902 CET | 127 | OUT | |
Mar 11, 2025 06:10:04.818378925 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:07.197340012 CET | 127 | OUT | |
Mar 11, 2025 06:10:16.672739983 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49716 | 158.101.44.242 | 80 | 7500 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:10.494441032 CET | 151 | OUT | |
Mar 11, 2025 06:10:18.796195030 CET | 321 | IN | |
Mar 11, 2025 06:10:18.799894094 CET | 127 | OUT | |
Mar 11, 2025 06:10:24.057415009 CET | 321 | IN | |
Mar 11, 2025 06:10:26.454727888 CET | 127 | OUT | |
Mar 11, 2025 06:10:27.801373005 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49721 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:18.928136110 CET | 151 | OUT | |
Mar 11, 2025 06:10:24.490513086 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49725 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:26.719578028 CET | 151 | OUT | |
Mar 11, 2025 06:10:28.659517050 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49728 | 158.101.44.242 | 80 | 7500 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:30.015328884 CET | 127 | OUT | |
Mar 11, 2025 06:10:30.665066004 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49730 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:30.822541952 CET | 151 | OUT | |
Mar 11, 2025 06:10:31.433689117 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49732 | 158.101.44.242 | 80 | 7500 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:34.061528921 CET | 151 | OUT | |
Mar 11, 2025 06:10:34.633016109 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49733 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:34.115523100 CET | 151 | OUT | |
Mar 11, 2025 06:10:34.715038061 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.5 | 49736 | 158.101.44.242 | 80 | 7500 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:37.177220106 CET | 151 | OUT | |
Mar 11, 2025 06:10:37.769226074 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.5 | 49737 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:37.180102110 CET | 151 | OUT | |
Mar 11, 2025 06:10:37.753390074 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.5 | 49740 | 158.101.44.242 | 80 | 7500 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:40.130079985 CET | 151 | OUT | |
Mar 11, 2025 06:10:40.711698055 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.5 | 49741 | 158.101.44.242 | 80 | 8068 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:40.130145073 CET | 151 | OUT | |
Mar 11, 2025 06:10:40.713644981 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.5 | 49744 | 158.101.44.242 | 80 | 7500 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 06:10:43.201354027 CET | 151 | OUT |