Windows
Analysis Report
rDatosbancarios.exe
Overview
General Information
Detection
GuLoader, Snake Keylogger
Score: | 96 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected GuLoader
Yara detected Snake Keylogger
Joe Sandbox ML detected suspicious sample
Switches to a custom stack to bypass stack traces
Tries to detect the country of the analysis system (by using the IP)
Tries to detect virtualization through RDTSC time measurements
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality for read data from the clipboard
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Classification
- System is w10x64
rDatosbancarios.exe (PID: 8704 cmdline:
"C:\Users\ user\Deskt op\rDatosb ancarios.e xe" MD5: AD465ED89A2C85DE228C1ECA00AD3C21) rDatosbancarios.exe (PID: 7148 cmdline:
"C:\Users\ user\Deskt op\rDatosb ancarios.e xe" MD5: AD465ED89A2C85DE228C1ECA00AD3C21)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CloudEyE, GuLoader | CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
404 Keylogger, Snake Keylogger | Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram. | No Attribution |
{"Exfil Mode": "Telegram", "Token": "7869489618:AAHN5xZzcFLHOzYCX49Sa8fwJ0Zb2PusB48", "Chat_id": "7618581100", "Version": "4.4"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security |
⊘No Sigma rule has matched
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T08:03:09.275038+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49717 | 104.21.96.1 | 443 | TCP |
2025-03-11T08:03:20.166172+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49723 | 104.21.96.1 | 443 | TCP |
2025-03-11T08:03:30.111896+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49727 | 104.21.96.1 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T08:03:02.458220+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | TCP |
2025-03-11T08:03:05.223981+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | TCP |
2025-03-11T08:03:09.911374+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49718 | 158.101.44.242 | 80 | TCP |
2025-03-11T08:03:12.958256+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49720 | 158.101.44.242 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T08:02:55.349179+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49713 | 172.217.16.142 | 443 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Location Tracking |
---|
Source: | DNS query: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Code function: | 0_2_0040596F | |
Source: | Code function: | 0_2_004064C1 | |
Source: | Code function: | 0_2_004027FB | |
Source: | Code function: | 6_2_0040596F | |
Source: | Code function: | 6_2_004064C1 | |
Source: | Code function: | 6_2_004027FB |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_0040541C |
Source: | Process Stats: |
Source: | Code function: | 0_2_004033B6 | |
Source: | Code function: | 6_2_004033B6 |
Source: | Code function: | 0_2_00406846 | |
Source: | Code function: | 0_2_00404C59 | |
Source: | Code function: | 6_2_00406846 | |
Source: | Code function: | 6_2_00404C59 | |
Source: | Code function: | 6_2_035B5370 | |
Source: | Code function: | 6_2_035BCA08 | |
Source: | Code function: | 6_2_035BC146 | |
Source: | Code function: | 6_2_035B69A0 | |
Source: | Code function: | 6_2_035BA088 | |
Source: | Code function: | 6_2_035BC738 | |
Source: | Code function: | 6_2_035B6FC8 | |
Source: | Code function: | 6_2_035BCFAA | |
Source: | Code function: | 6_2_035B3E09 | |
Source: | Code function: | 6_2_035BC46A | |
Source: | Code function: | 6_2_035BCCD8 | |
Source: | Code function: | 6_2_035B3AA1 | |
Source: | Code function: | 6_2_035B29EC | |
Source: | Code function: | 6_2_035BB0B8 |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_004033B6 | |
Source: | Code function: | 6_2_004033B6 |
Source: | Code function: | 0_2_004046DD |
Source: | Code function: | 0_2_00402095 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | File source: |
Source: | Code function: | 0_2_10001B18 |
Source: | Code function: | 0_2_10002E0E |
Source: | File created: | Jump to dropped file |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 0_2_0040596F | |
Source: | Code function: | 0_2_004064C1 | |
Source: | Code function: | 0_2_004027FB | |
Source: | Code function: | 6_2_0040596F | |
Source: | Code function: | 6_2_004064C1 | |
Source: | Code function: | 6_2_004027FB |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-4497 | ||
Source: | API call chain: | graph_0-4499 |
Source: | Code function: | 0_2_10001B18 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_004061A0 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 Access Token Manipulation | 1 Masquerading | OS Credential Dumping | 21 Security Software Discovery | Remote Services | 1 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 11 Process Injection | 1 Disable or Modify Tools | LSASS Memory | 31 Virtualization/Sandbox Evasion | Remote Desktop Protocol | 1 Clipboard Data | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Access Token Manipulation | NTDS | 1 System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Process Injection | LSA Secrets | 4 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Deobfuscate/Decode Files or Information | Cached Domain Credentials | 214 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 2 Obfuscated Files or Information | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
45% | Virustotal | Browse | ||
42% | ReversingLabs | Win32.Trojan.SnakeKeylogger | ||
100% | Avira | HEUR/AGEN.1338065 |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
drive.google.com | 172.217.16.142 | true | false | high | |
drive.usercontent.google.com | 172.217.16.193 | true | false | high | |
reallyfreegeoip.org | 104.21.96.1 | true | false | high | |
checkip.dyndns.com | 158.101.44.242 | true | false | high | |
checkip.dyndns.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.96.1 | reallyfreegeoip.org | United States | 13335 | CLOUDFLARENETUS | false | |
158.101.44.242 | checkip.dyndns.com | United States | 31898 | ORACLE-BMC-31898US | false | |
172.217.16.193 | drive.usercontent.google.com | United States | 15169 | GOOGLEUS | false | |
172.217.16.142 | drive.google.com | United States | 15169 | GOOGLEUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1634944 |
Start date and time: | 2025-03-11 08:00:26 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | rDatosbancarios.exe |
Detection: | MAL |
Classification: | mal96.troj.evad.winEXE@3/21@4/4 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 23.60.203.209, 20.109.210.53, 150.171.27.10
- Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, g.bing.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target rDatosbancarios.exe, PID 7148 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Report size getting too big, too many NtSetInformationFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
03:03:04 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.21.96.1 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Azorult | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Azorult | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
158.101.44.242 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
checkip.dyndns.com | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
reallyfreegeoip.org | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ORACLE-BMC-31898US | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MSIL Logger, MassLogger RAT | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Lokibot | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix | Browse |
| ||
Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | CryptOne, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\nsqE012.tmp\System.dll | Get hash | malicious | GuLoader | Browse | ||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | FormBook, GuLoader | Browse | |||
Get hash | malicious | Discord Token Stealer, GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 11776 |
Entropy (8bit): | 5.656126712214018 |
Encrypted: | false |
SSDEEP: | 192:em24sihno00Wfl97nH6T2enXwWobpWBTU4VtHT7dmN35OlESl:m8QIl975eXqlWBrz7YLOlE |
MD5: | A4DD044BCD94E9B3370CCF095B31F896 |
SHA1: | 17C78201323AB2095BC53184AA8267C9187D5173 |
SHA-256: | 2E226715419A5882E2E14278940EE8EF0AA648A3EF7AF5B3DC252674111962BC |
SHA-512: | 87335A43B9CA13E1300C7C23E702E87C669E2BCF4F6065F0C684FC53165E9C1F091CC4D79A3ECA3910F0518D3B647120AC0BE1A68EAADE2E75EAA64ADFC92C5A |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1469430 |
Entropy (8bit): | 5.2803666246948415 |
Encrypted: | false |
SSDEEP: | 24576:rSDrA5uDk+b/xvoR1eoDgNqCnz9u82zPS8XgSk3Aits6S7F/CnSZ8FTY+fTIe+ui:rwLbpRoDgNqCnz9u82zPS8XgSk3Aitsp |
MD5: | 174DFAB360BD94E92F845867793DDAE0 |
SHA1: | 0A057D6ABFE4016B5F56F05562C14D02A0EE35CC |
SHA-256: | 951D1DABF8B1DF7C8B432B791DA9598C74D6A099FECCC6D95E011C6248D8F168 |
SHA-512: | BEB5B36264A348145DEEF4AA8152352F9182B9E2D75EADE2F9DC9CB2D15DC8B6565C403F01429282EA9AC03271F370D11AD099973C844667D2FF2C5527F4C235 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 18357 |
Entropy (8bit): | 7.936619496429841 |
Encrypted: | false |
SSDEEP: | 384:wLlcElbGb3W7VDV2Swn7tXub10dVKzPcZcf606g48xYryovEcQp3Y:wLlcEdGTEVT2RXup0jsPo7ryoJQRY |
MD5: | 2310C19BB5C1C394A44C78C0485061A6 |
SHA1: | 4BDCC7A01455909E94A4622E341B568CE00A7BD9 |
SHA-256: | 066ACF51FEC7AA4B6D955CEBE64823A8E8972CACB760712579381D37FBF80306 |
SHA-512: | B5DD5056DAAB22A8EA6175C334B8323BCB205FC91BBA9B35403BECF3B3E167E66A02C43F7B2E8A8D3665E4821014047B4D56D7C29E445748F6631367476CC1A1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4615 |
Entropy (8bit): | 7.913142776059761 |
Encrypted: | false |
SSDEEP: | 96:RhEEfNCijUsrmoPC+31/X5eXoXsqhyGoThEmNVtN6FHXAjpW:LEGpmoPzpeYX7hTGEm5gxAQ |
MD5: | 3EE4B8300AA101C6EECD0129D40CD83F |
SHA1: | D289E32FB683DBAC9C964B67B9A54197D7D9B3C7 |
SHA-256: | 654EA2227816CB5C698D39635C996F89C3CFBD4511C6D2868D7DC2BFB87447F8 |
SHA-512: | 1712CC4ED2783CF63ED582BAB4A33C575F995D70C540BBA4D8EC4D59D855F8D441373CE859A7AAB9F8008E338271588115E918060B53B1CC9FDBFF339A430587 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 255 |
Entropy (8bit): | 4.491038896938942 |
Encrypted: | false |
SSDEEP: | 6:PNHc2eqaia5RnWMeRJqcK8QqAgWl0oAGsY9B8YNEKZAXDcn+:182j8XeRJqlqbWl1Z8gVZi |
MD5: | 608DD5D5CE8FF7DEC268A045823B8739 |
SHA1: | 245FEC873579B46DCFACCC21C122F61ADD5C7D01 |
SHA-256: | 4C5FC7BDB9CA4152EC687DDF62878678004F90A86F664CDFB449BB14E2739873 |
SHA-512: | BE39F08E33AE99810B9311FBCAFCE0EE5048A2CF2433A2282FF0C3B08268190CADFA95CF8EEB330738AFF5489FE2542D9C834944DB9D19BCBF7CB2F187BFBB96 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 19980 |
Entropy (8bit): | 7.9347335065473565 |
Encrypted: | false |
SSDEEP: | 384:KDMaD0UP/dh+GUXvhVKhS4FGwgggkaucOLdL2Qsiu7alJ2RR:Kg9Uth+GWvbKhSIgg3aucOLdKQplJ2/ |
MD5: | A7D9A21C810423F81DBD1A3C8CC606E0 |
SHA1: | 436BF63A4435835195930B6B6454AAC10ECEA63B |
SHA-256: | 0FC777C30A909F2D4EA552B3E65EF20A3CFDC96EFE421643C02273F53025C1B5 |
SHA-512: | A8F126C5A14251E47AEF27538A9F095044E20CBD287AAE53F16F286D7D3DF14FA39E25B07E54CEC494101CF267623934B6922A6889E764C4F0E49A039E33AC0A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 602 |
Entropy (8bit): | 4.400582645082127 |
Encrypted: | false |
SSDEEP: | 12:nELjhLvCiHUlIOoZ9iZ9SCIkNvAVu8zLNM1kALSx/mQdqkt:EL1zOQiSCPNYPluyzt |
MD5: | B3A3DEB1B5F4A4C580ACE8A6C15D33D5 |
SHA1: | 400C731533811C1011F6A087482D4D9E084ECF33 |
SHA-256: | 098FC4B8FA81A699B5A25AFEF7AEFA525FB0BCD4D399712614A05600D001D53A |
SHA-512: | 2B5D9BB74D591C6DF1A2F37D81D451C93424C3295E5C90830433003D759B6E4C9A31F604FC6571222E282C3E124E7A6771DB44AE7E7208125F35A7FB14E5C637 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 27542 |
Entropy (8bit): | 7.958951812891919 |
Encrypted: | false |
SSDEEP: | 768:oyA9XtfIBaIY046fhF5kMOpXqYM2pYVdU:o99GoO465OpXxMfVO |
MD5: | B8C33A1F37EA85FFB025D82118F2647B |
SHA1: | 7A38F95728E463AFD778AE6DCBB47EE89C2C6689 |
SHA-256: | CBE381CD0F898B412637635E1E3DA6C737070B4809A3607E214556DC9EA809D2 |
SHA-512: | 74ECA396725E90EE5EB69A03A055235272A68F3479B1C4D1AA1A7D532CAA415D77B92ABF9CA84C2CB547F8796CE3F9A897A206D6B572C4797CD1A07BB13FAC3B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 672 |
Entropy (8bit): | 4.384924435729617 |
Encrypted: | false |
SSDEEP: | 12:FkJCwccT6RG52sZN0I6XAnNGDqvopQy+LuJ3+3D5OEzMc93kHWEFtg0OHRA:FkJD2RCZNsX4E9p+MuiWERy2 |
MD5: | 1709A1B3D0B2161DFFB11E3BB49391D6 |
SHA1: | AE803E87FA20DDC94DCDF5C9403F819E2D2856C9 |
SHA-256: | 033F0809C3E10E14769FA2BC034EAEC542ACA89206C8DB96C896E718D2F128EC |
SHA-512: | 46DC3A150CEF2A6093EF3942E3C4824F5B30FDE5962875352CB339A46F36F16D7801A568B6D0A8926BC81D204FCEBAECBB5370420FBC1F36F90A837316311057 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 587 |
Entropy (8bit): | 4.276286407187743 |
Encrypted: | false |
SSDEEP: | 12:IC519inXhWTIOS/8kMFgnFUeJ7lSCJmjTMw0WXj3RueZf5CiQo+M:RvUnsMOS7HvJm/MwoC5XiM |
MD5: | DC58AFEB9A432A91F1BE0DC7916C4D26 |
SHA1: | BD00AF173B3C83F9A77D3C766381A8294AFC306C |
SHA-256: | E9F2AF66E251B66BAEF24A53987EA575092DB07EAD6FDD1440EB47283B80A21B |
SHA-512: | 2379500EA5E90130C745837C45B3A521CC057B946910561774F9C7B2D219BAEDCE60DFA42D27CDDA0059BA2D7E73E9B79D23FB9FD8CEBAA302EF4F225185A9E5 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 400 |
Entropy (8bit): | 4.357244201086591 |
Encrypted: | false |
SSDEEP: | 6:Xp13ip+GAHk53OXiIvLNJHBYzegQQ/CuA9ThLBHBukm59QgpHEaS1B2XdR4cy4+L:DyQCIiIOQGCbH1hu5AgpnSmXdRyL |
MD5: | BCC2B9D5C8A310A8CB1C9ED3E3971E64 |
SHA1: | CD932AF1B5B6491E21EB8534E887A800E2971548 |
SHA-256: | F62709FC9E5EF7BB035641EDDEBB5973864B038107D96C16FAD8A436A9314F99 |
SHA-512: | 53710CB6A7D9DFAF5B26CE8C3AC85FA81F4CB0E02C966F5D22B4F3C5EA4B4B88FFFE63837CF829BE249D82BB1B475EF6FD10243C915A08B4A67F9A41B27FB315 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 190 |
Entropy (8bit): | 4.786907758850494 |
Encrypted: | false |
SSDEEP: | 3:CVNLF7sQVAExM+Ici/7sg32ctqaV12JMeIA8M3yPMILJeA80lkLAtrOmkfuCIARq:CzdxqExu//7sgGcqaLD5JZje1Atavf7G |
MD5: | B0EC8F1E428B995EBB7CB83AB260B97B |
SHA1: | 39D31FA468223F785C17F5B2E232C0E3F2706907 |
SHA-256: | 432628CF62464AB33BC62FA420034B761ED8BBE623954689E766569E696F4824 |
SHA-512: | 434D2A790FB1BD5A34A8F2FA4AB225B81511DC05237963AF7D257E56660716BBFBD6DAA141A9F803B09F02E4F1B6D100E811A973370CD97949B160446B6C37A1 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 153908 |
Entropy (8bit): | 1.2580823700855364 |
Encrypted: | false |
SSDEEP: | 3072:Z6pvA+Q+0+3a7DX+GsFrYfYxoPgw9oN/9Hs+cBtSkiraqmIDeEYTkFTPhKjlB3xn:Z6pvA+Q+z3a7DX+GsFkfYxoPgw9oN/9Y |
MD5: | FB75D2F95476E7E6E5B8F1C2F40772ED |
SHA1: | 26BEF9734C0FFB6FE6EA88D9A16D649D66239710 |
SHA-256: | 5AEC35BFBEA04788332E6D70821AA729D84BF60312D99D9552DCF9E223F3C151 |
SHA-512: | 47F696C1BA4A9886BBDCEBB847D1E9FE61375B8AEFE7CC2399020BB15D0C648F1F425F05DB231CE34A379B80339FD56AFA78E06F1E47C1597BE74CBAC855F200 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 555 |
Entropy (8bit): | 4.4140301344852935 |
Encrypted: | false |
SSDEEP: | 12:1azD3bZFT9pZVAXoN9rH4kUptK5LzLAD8PULksPUaw5w:1a33zHzQkUpY5LnobLk5af |
MD5: | 8485D862CC0FCCFB55162BF96E001924 |
SHA1: | 1C64B62E7DCF26519F149768AC7420E710CBABD3 |
SHA-256: | C511D6E4008BB72191BA68E2721D21843219C378590032948B9666DC9D970885 |
SHA-512: | 4A6C5E27B27D1BEF80343D021F1ABA17C77F615D4A4814213035087DAFB7A61962F98D7174FDD502B2C7CC9EF375ECEC34A9F6691F9F5D29602095B35D9EF80E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 382877 |
Entropy (8bit): | 1.2490703351639014 |
Encrypted: | false |
SSDEEP: | 6144:aoDgNqCnz9u82zPS8XgSk3Aits6S7FEgCnSZ8lTTZK+fTIe+ula7gJ+UoQlL+69v:aoDgNqCnz9u82zPS8XgSk3Aits6S7FEf |
MD5: | 0A272F75F56AB61366EC763E7E0A6A13 |
SHA1: | 7465696F465799C9898ADC9AB082FBE76982FECF |
SHA-256: | EBCDFBA62A2AB8D8740FC978DC4E0216500BF83E4E0EBA96F485CDF651546596 |
SHA-512: | 3D2198A7610EFE31EE248615F75F61D6913784DD3B15F669C76ED5229A03C359F05A47CAEF70F45F2F3B19C3BD383AFB7249D58BC89859F1469FCB56C6A4BD2E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55848 |
Entropy (8bit): | 1.2387501956568354 |
Encrypted: | false |
SSDEEP: | 192:1w8kCYQS+bJkaIsu+DdFEdgY1ZUzNiwl3xRuqYkU4sIJ05KrZbYqBP9FXDU6onA/:u7/VstblBMVu0UrJr5+AYEw6 |
MD5: | 5E62DAA89B112148219B9BFE1787C7D4 |
SHA1: | B1F60EEA844142A8131387113F9CA942D2BD620C |
SHA-256: | 4EA27D7EEAF127D67948CD36EA1253C7B2B8F378E5C40B771813AC0C841181E1 |
SHA-512: | 6E01F7A15EDB67704D8A791A3FC56BFE3C05EF608C45BA2EECF24808BE65126CAE5AD382CF37AC4688B5EA82FE9033FEE84F83CFE4467606346CFE991889CC6C |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40259 |
Entropy (8bit): | 7.952041876448999 |
Encrypted: | false |
SSDEEP: | 768:vj//fFIkWPCc+UwxaGRlJoYKLtAOMREp/fOjg2OdSp49GpkH:vT/9I96tUwxaGRlJoYKLt2Y+j7OUewu |
MD5: | FD464BBCF2F136AED1CEDFD5A8335ADB |
SHA1: | C6D41BFCF04645C5E9F252F4459C2E6E1319C138 |
SHA-256: | F01B19A0D1E50B1DFBC9FB63C726D96B21FEA045C4664E14EBD24DA4EB95BB3F |
SHA-512: | B5BCF3E524695F381E2982227155474E7DEB7B271C7888D7E91913C9AA165B504A15F1D097E4F4D8B4034D74C01DA413F4E676A4BF845B90FF8C2A016509BE69 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 444702 |
Entropy (8bit): | 2.648488347981852 |
Encrypted: | false |
SSDEEP: | 3072:5SP3KOgBWE8BkKTBYTJeQDnLIHqBIScByLfhX:5SPBgBWE8qKTBUJeQDLKqBEByLfhX |
MD5: | 003E923806FC8376F500D36B0B05BE30 |
SHA1: | B9B8C97E947227D0EF33CF1B55D1EF27612CF246 |
SHA-256: | 277C60BBE6E2D407EE129B314FB0A6F9DCDAEB37E8E16EBFAF60DEEE77378123 |
SHA-512: | 385596D43758584EB088D097C663E45441CC4EAC165DBEAF46416B621D552959731AC0E1CEF9D7F7ACAF1F7E7917961190CFE245AC29F561E682B5F0BA5184E2 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 214902 |
Entropy (8bit): | 7.487368942112461 |
Encrypted: | false |
SSDEEP: | 3072:FG7h341X9ZHM4tDrGX5rXH//SQsYWjDnDRS9MY9Ddq/gdkd3/HIuYuIhTNmenzDC:Md3assDrGp7nSnA5q/b3/4zP5vzCbOiD |
MD5: | 0F448C11B8AAAC4934B9FC9E2F432A35 |
SHA1: | 6BA5F7658520CADDA40899E3AD33A9E4D15FD57B |
SHA-256: | EDF4A2834DF1E9598E1B019A560843F36381915EEEF4FC6C49CC717F90C82183 |
SHA-512: | 1AD633397BCBDC26F7444D2BE82BE2EAB8E4008B970C4030AB9FA8D194BF94AAE463EEF16F67F45966B55511527D97DBAB54DCDD4A61CF74A065191F366FB620 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 459 |
Entropy (8bit): | 4.432435243733704 |
Encrypted: | false |
SSDEEP: | 12:CF52tlLh2VARXPDKnPLhZBKRWbB/UFBZwvqzTEx3:ftRhSObKnvGWbpKBZnz2 |
MD5: | C3ABBB621BF861C4CAF283BE1271575D |
SHA1: | 439D4085265E02E2796EB641DF825B84AC521263 |
SHA-256: | 2671B868DB88CA59430325392ECC572A70FF593D3226A9DC44471DDED94B59A5 |
SHA-512: | 636FE8A12001BC3F82047662B1F490423F4A63CFD49177585432F4C505CE94962A172BA61BC2471DEB81C6A17910848BC6A2101638EE8F0A7A8DF2231BF7E65C |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\rDatosbancarios.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 79680 |
Entropy (8bit): | 7.968459679324831 |
Encrypted: | false |
SSDEEP: | 1536:lh2SSzAwtkw9d5wNbvZmkPJPu5oBW/x3kX+SQ7ZqXg/:eSSz95YFDPJBhkcXg/ |
MD5: | 17058D8D0F59BAB826B161633E171AB8 |
SHA1: | 84FEB30222153AAA7193DC09D2576C5765F35168 |
SHA-256: | AF68F5E4C4C224C26BE2AE669D5DD8C88F39777521490A15AE4A2B5613784C77 |
SHA-512: | 367109170E67B156157E56B443ED1D7DCFD9EAAEC193E80BD2BA90ABA5AD96FF331AFB78891A97EE54ED8EE25F242C32F0CDC6F6525CC6AD83FBD42D40DA6839 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 6.819942335765569 |
TrID: |
|
File name: | rDatosbancarios.exe |
File size: | 890'069 bytes |
MD5: | ad465ed89a2c85de228c1eca00ad3c21 |
SHA1: | 693a1f701261b57a351587afaabcfd7e9e519db2 |
SHA256: | 05e5731dc9129d9f1019a21fbbb672fa0a01a1bb8e89393e630b75ec38797928 |
SHA512: | 5cc6ebff13d49f15e640fae88db10d4e87a55ea53f9a4eab0db1e834956f6769d64e75bb846a87660b16bf1a20e01c6c0303b47e44c377bd3efef61bf22d2115 |
SSDEEP: | 12288:tgykllhWbCCb3vYt1tyLdoHnDw5C8DKSywPjQ887ZsdsRCX0FIiMW:illhWbCCDy1yqV8DZywPsZsdsIkWY |
TLSH: | 3015121D3544C992C82EC431A5B781520325DD3C9E896B57EF0BBB3EE872558AB0F72D |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...P...P...P..*_...P...P..OP..*_...P...s...P...V...P..Rich.P..........PE..L....c.W.................b...*.......3............@ |
Icon Hash: | 519e261b4d279646 |
Entrypoint: | 0x4033b6 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x57956397 [Mon Jul 25 00:55:51 2016 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 4ea4df5d94204fc550be1874e1b77ea7 |
Instruction |
---|
sub esp, 000002D4h |
push ebx |
push esi |
push edi |
push 00000020h |
pop edi |
xor ebx, ebx |
push 00008001h |
mov dword ptr [esp+14h], ebx |
mov dword ptr [esp+10h], 0040A230h |
mov dword ptr [esp+1Ch], ebx |
call dword ptr [004080B4h] |
call dword ptr [004080B0h] |
cmp ax, 00000006h |
je 00007F1E49B68FD3h |
push ebx |
call 00007F1E49B6C12Ch |
cmp eax, ebx |
je 00007F1E49B68FC9h |
push 00000C00h |
call eax |
mov esi, 004082B8h |
push esi |
call 00007F1E49B6C0A6h |
push esi |
call dword ptr [0040815Ch] |
lea esi, dword ptr [esi+eax+01h] |
cmp byte ptr [esi], 00000000h |
jne 00007F1E49B68FACh |
push ebp |
push 00000009h |
call 00007F1E49B6C0FEh |
push 00000007h |
call 00007F1E49B6C0F7h |
mov dword ptr [0042A244h], eax |
call dword ptr [0040803Ch] |
push ebx |
call dword ptr [004082A4h] |
mov dword ptr [0042A2F8h], eax |
push ebx |
lea eax, dword ptr [esp+34h] |
push 000002B4h |
push eax |
push ebx |
push 004216E8h |
call dword ptr [00408188h] |
push 0040A384h |
push 00429240h |
call 00007F1E49B6BCE0h |
call dword ptr [004080ACh] |
mov ebp, 00435000h |
push eax |
push ebp |
call 00007F1E49B6BCCEh |
push ebx |
call dword ptr [00408174h] |
add word ptr [eax], 0000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8504 | 0xa0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x52000 | 0x42b10 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x8000 | 0x2b4 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x615d | 0x6200 | 0b0812166ebbd0109e7f5e007b182949 | False | 0.6616709183673469 | data | 6.450231726170125 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x8000 | 0x13a4 | 0x1400 | 4ac891d4ddf58633f14436f9f80ac6b6 | False | 0.4529296875 | data | 5.163001655755973 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xa000 | 0x20338 | 0x600 | 66b45fceba0f24d768fb09e0afe23c99 | False | 0.5026041666666666 | data | 3.9824009583068882 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x2b000 | 0x27000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x52000 | 0x42b10 | 0x42c00 | e550e6733de24c79182b96bc7b2532a6 | False | 0.1573362886235955 | data | 2.401521937595081 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x52208 | 0x42028 | Device independent bitmap graphic, 256 x 512 x 32, image size 270336 | English | United States | 0.15390049412669762 |
RT_DIALOG | 0x94230 | 0x100 | data | English | United States | 0.5234375 |
RT_DIALOG | 0x94330 | 0x11c | data | English | United States | 0.6091549295774648 |
RT_DIALOG | 0x94450 | 0xc4 | data | English | United States | 0.5918367346938775 |
RT_DIALOG | 0x94518 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_GROUP_ICON | 0x94578 | 0x14 | data | English | United States | 1.1 |
RT_VERSION | 0x94590 | 0x240 | data | English | United States | 0.5260416666666666 |
RT_MANIFEST | 0x947d0 | 0x33d | XML 1.0 document, ASCII text, with very long lines (829), with no line terminators | English | United States | 0.5536791314837153 |
DLL | Import |
---|---|
KERNEL32.dll | SetCurrentDirectoryW, GetFileAttributesW, GetFullPathNameW, Sleep, GetTickCount, CreateFileW, GetFileSize, MoveFileW, SetFileAttributesW, GetModuleFileNameW, CopyFileW, ExitProcess, SetEnvironmentVariableW, GetWindowsDirectoryW, GetTempPathW, GetCommandLineW, GetVersion, SetErrorMode, WaitForSingleObject, GetCurrentProcess, CompareFileTime, GlobalUnlock, GlobalLock, CreateThread, GetLastError, CreateDirectoryW, CreateProcessW, RemoveDirectoryW, lstrcmpiA, GetTempFileNameW, WriteFile, lstrcpyA, lstrcpyW, MoveFileExW, lstrcatW, GetSystemDirectoryW, GetProcAddress, GetModuleHandleA, GlobalFree, GlobalAlloc, GetShortPathNameW, SearchPathW, lstrcmpiW, SetFileTime, CloseHandle, ExpandEnvironmentStringsW, lstrcmpW, GetDiskFreeSpaceW, lstrlenW, lstrcpynW, GetExitCodeProcess, FindFirstFileW, FindNextFileW, DeleteFileW, SetFilePointer, ReadFile, FindClose, MulDiv, MultiByteToWideChar, lstrlenA, WideCharToMultiByte, GetPrivateProfileStringW, WritePrivateProfileStringW, FreeLibrary, LoadLibraryExW, GetModuleHandleW |
USER32.dll | GetSystemMenu, SetClassLongW, IsWindowEnabled, EnableMenuItem, SetWindowPos, GetSysColor, GetWindowLongW, SetCursor, LoadCursorW, CheckDlgButton, GetMessagePos, LoadBitmapW, CallWindowProcW, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, wsprintfW, ScreenToClient, GetWindowRect, GetSystemMetrics, SetDlgItemTextW, GetDlgItemTextW, MessageBoxIndirectW, CharPrevW, CharNextA, wsprintfA, DispatchMessageW, PeekMessageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, GetClientRect, FillRect, EndDialog, RegisterClassW, SystemParametersInfoW, CreateWindowExW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, LoadImageW, SetTimer, SetWindowTextW, PostQuitMessage, ShowWindow, GetDlgItem, IsWindow, SetWindowLongW, FindWindowExW, TrackPopupMenu, AppendMenuW, CreatePopupMenu, DrawTextW, EndPaint, CreateDialogParamW, SendMessageTimeoutW, SetForegroundWindow |
GDI32.dll | SelectObject, SetBkMode, CreateFontIndirectW, SetTextColor, DeleteObject, GetDeviceCaps, CreateBrushIndirect, SetBkColor |
SHELL32.dll | SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHBrowseForFolderW, SHGetFileInfoW, ShellExecuteW, SHFileOperationW |
ADVAPI32.dll | RegDeleteKeyW, SetFileSecurityW, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, RegOpenKeyExW, RegEnumValueW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegEnumKeyW |
COMCTL32.dll | ImageList_AddMasked, ImageList_Destroy, ImageList_Create |
ole32.dll | OleUninitialize, OleInitialize, CoTaskMemFree, CoCreateInstance |
Description | Data |
---|---|
CompanyName | skrigenes |
LegalTrademarks | bombardements skattereformen |
OriginalFilename | dolcan.exe |
ProductName | ummps vinkelhastighedernes |
ProductVersion | 1.1.0.0 |
Translation | 0x0409 0x04e4 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-11T08:02:55.349179+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.5 | 49713 | 172.217.16.142 | 443 | TCP |
2025-03-11T08:03:02.458220+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | TCP |
2025-03-11T08:03:05.223981+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | TCP |
2025-03-11T08:03:09.275038+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49717 | 104.21.96.1 | 443 | TCP |
2025-03-11T08:03:09.911374+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49718 | 158.101.44.242 | 80 | TCP |
2025-03-11T08:03:12.958256+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49720 | 158.101.44.242 | 80 | TCP |
2025-03-11T08:03:20.166172+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49723 | 104.21.96.1 | 443 | TCP |
2025-03-11T08:03:30.111896+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49727 | 104.21.96.1 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 11, 2025 08:02:51.027288914 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:51.027333975 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:51.027420044 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:51.036103010 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:51.036117077 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:54.657250881 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:54.657355070 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:54.658325911 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:54.658392906 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:54.708220005 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:54.708240986 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:54.708664894 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:54.708729029 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:54.711179972 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:54.756318092 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:55.349322081 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:55.349417925 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:55.349442959 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:55.349495888 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:55.349505901 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:55.349550962 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:55.349584103 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:55.350852966 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:55.352615118 CET | 49713 | 443 | 192.168.2.5 | 172.217.16.142 |
Mar 11, 2025 08:02:55.352632046 CET | 443 | 49713 | 172.217.16.142 | 192.168.2.5 |
Mar 11, 2025 08:02:55.382184982 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:02:55.382210970 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:02:55.382298946 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:02:55.382540941 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:02:55.382559061 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:02:57.314465046 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:02:57.314574003 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:02:57.319263935 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:02:57.319272995 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:02:57.319673061 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:02:57.319739103 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:02:57.320272923 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:02:57.364331007 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.552167892 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.552310944 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.581140995 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.581233025 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.613120079 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.613183975 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.613231897 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.613276005 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.656461954 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.656548023 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.659912109 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.659972906 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.659984112 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.660032034 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.669471025 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.669553041 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.669562101 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.669605017 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.674781084 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.674854994 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.679758072 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.679824114 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.679847956 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.679896116 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.690392971 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.690454960 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.690520048 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.690565109 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.690589905 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.690634012 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.702919006 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.702964067 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.703577042 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.703628063 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.706676960 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.706718922 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.706772089 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.706813097 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.719259024 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.719310999 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.719357014 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.719398975 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.726197004 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.726239920 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.726288080 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.726329088 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.726397038 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.726442099 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.736083984 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.736131907 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.736176968 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.736219883 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.741578102 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.741621017 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.741661072 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.741698027 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.741761923 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.741816044 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.754048109 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.754098892 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.765871048 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.765913963 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.765994072 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.766033888 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.775557041 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.775602102 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.775679111 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.775732040 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.775779963 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.775829077 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.784677029 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.784723997 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.784774065 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.784816980 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.786827087 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.786875963 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.786921978 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.786962032 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.793324947 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.793371916 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.793430090 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.793472052 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.793540001 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.793586969 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.803529978 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.803575993 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.803617001 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.803657055 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.805917025 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.805957079 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.806030989 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.806071997 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.811270952 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.811319113 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.811412096 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.811460018 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.816620111 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.816674948 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.816718102 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.816759109 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.822530985 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.822587013 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.822666883 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.822705984 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.827261925 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.827306986 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.827378988 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.827430964 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.832367897 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.832410097 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.832559109 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.832601070 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.837404966 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.837455034 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.837496042 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.837543011 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.847395897 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.847471952 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.847506046 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.847557068 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.851160049 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.851223946 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.851260900 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.851301908 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.853827953 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.853889942 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.853945971 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.853993893 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.861814022 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.861893892 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.861910105 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.861953974 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.862004995 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.862050056 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.866300106 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.866364956 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.866413116 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.866461039 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.869122028 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.869187117 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.869211912 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.869263887 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.874171019 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.874238968 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.874327898 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.874391079 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.880397081 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.880461931 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.880508900 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.880564928 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.884999990 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.885060072 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.885094881 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.885134935 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.890551090 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.890625954 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.890674114 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.890729904 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.892468929 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.892523050 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.894323111 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.894366026 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.894432068 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.894486904 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.894520044 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.894567966 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.896888971 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.896955013 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.896970034 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.897006035 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.899568081 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.899616003 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.899684906 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.899728060 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.902116060 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.902156115 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.902209044 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.902250051 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.906344891 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.906394958 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.906426907 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.906471968 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.907282114 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.907322884 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.907366991 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.907418966 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.910902023 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.910973072 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.911001921 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.911050081 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.913734913 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.913786888 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.917903900 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.917963028 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.918004036 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.918041945 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.918973923 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.919038057 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.923809052 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.923866034 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.923902035 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.923949003 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.924909115 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.924957991 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.925023079 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.925065041 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.927202940 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.927253962 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.927294016 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.927335978 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.929486990 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.929536104 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.929575920 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.929624081 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.931723118 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.931771994 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.931827068 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.931869030 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.933999062 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.934072971 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.934107065 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.934154987 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.937407970 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.937463045 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.937505960 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.937549114 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.938570023 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.938622952 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.938714027 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.938760996 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.942198038 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.942251921 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.942312002 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.942361116 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.944864035 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.944926977 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.944961071 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.945012093 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.946532965 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.946590900 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.946657896 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.946717024 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.946738005 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.946782112 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.946825981 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.946885109 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.952982903 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.953047037 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.954230070 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.954282999 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.954343081 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.954386950 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.954436064 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.954479933 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.960135937 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.960195065 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.960246086 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.960292101 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.963148117 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.963212967 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.963253021 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.963294029 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.963335037 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.963380098 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.963450909 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.963499069 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.965558052 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.965620041 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.965666056 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.965711117 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.967927933 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.967978954 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.968014002 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.968055964 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.968138933 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.968193054 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.969008923 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.969052076 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.969100952 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.969147921 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.972563982 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.972615957 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.972743034 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.972784042 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.974251986 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.974322081 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.976152897 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.976217985 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.976253986 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.976329088 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.976363897 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.976404905 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.978005886 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.978065968 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.978101015 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.978147984 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.981231928 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.981291056 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.986332893 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.986397028 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.986419916 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.986466885 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.986535072 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.986588955 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.988157988 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.988217115 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.988250971 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.988296986 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.994158030 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.994204998 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.994266987 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.994309902 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:00.994457960 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:00.994503975 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.000693083 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.000773907 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.000799894 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.000847101 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.000890970 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.000938892 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.002726078 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.002770901 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.002814054 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.002859116 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.004770041 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.004816055 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.007500887 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.007555962 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.007592916 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.007637978 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.007699966 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.007742882 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.009027958 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.009076118 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.009156942 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.009198904 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.013556004 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.013626099 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.013643980 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.013686895 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.013725042 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.013777018 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.013808966 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.013853073 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.013897896 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.013941050 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.014858007 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.014900923 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.014945030 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.014990091 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.016447067 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.016510010 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.016567945 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.016611099 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.017230034 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.017277956 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.017652035 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.017692089 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.019128084 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.019181013 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.019212008 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.019253016 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.020837069 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.020895004 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.021004915 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.021059990 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.023554087 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.023613930 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.023639917 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.023686886 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.028862953 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.028920889 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.028960943 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.029009104 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.040998936 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.041075945 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.041094065 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.041136980 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.041630030 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.041683912 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.046787024 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.046859026 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.047856092 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.047928095 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.047950029 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.047993898 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.052460909 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.052529097 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.052573919 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.052620888 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.062819958 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.062902927 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.062915087 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.063119888 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.063325882 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.063369989 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.083420992 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.083475113 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.084378004 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.084427118 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.084476948 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.084525108 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.084652901 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.084693909 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.084738016 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.084784031 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.084876060 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.084924936 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.086611986 CET | 49714 | 443 | 192.168.2.5 | 172.217.16.193 |
Mar 11, 2025 08:03:01.086633921 CET | 443 | 49714 | 172.217.16.193 | 192.168.2.5 |
Mar 11, 2025 08:03:01.636465073 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:01.641766071 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:01.641824007 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:01.641990900 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:01.647362947 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:02.244139910 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:02.247921944 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:02.253396988 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:02.406353951 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:02.458220005 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:02.740009069 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:02.740046024 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:02.740109921 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:02.742228031 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:02.742242098 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:04.524490118 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:04.524578094 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:04.527903080 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:04.527913094 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:04.528485060 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:04.532341957 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:04.576366901 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:04.989244938 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:04.989411116 CET | 443 | 49716 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:04.989480972 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:04.995924950 CET | 49716 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:05.001833916 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:05.006688118 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:05.177953005 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:05.179819107 CET | 49717 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:05.179864883 CET | 443 | 49717 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:05.179951906 CET | 49717 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:05.180213928 CET | 49717 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:05.180233002 CET | 443 | 49717 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:05.223980904 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:07.312479019 CET | 443 | 49717 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:07.314883947 CET | 49717 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:07.314908028 CET | 443 | 49717 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:09.275101900 CET | 443 | 49717 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:09.275295019 CET | 443 | 49717 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:09.275348902 CET | 49717 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:09.275680065 CET | 49717 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:09.278776884 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:09.279756069 CET | 49718 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:09.283786058 CET | 80 | 49715 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:09.283834934 CET | 49715 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:09.284634113 CET | 80 | 49718 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:09.284713030 CET | 49718 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:09.284790993 CET | 49718 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:09.289525032 CET | 80 | 49718 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:09.864269018 CET | 80 | 49718 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:09.865737915 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:09.865796089 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:09.865861893 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:09.866091967 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:09.866110086 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:09.911374092 CET | 49718 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:11.780015945 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:11.781708956 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:11.781732082 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:12.273931026 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:12.274097919 CET | 443 | 49719 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:12.274175882 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:12.274550915 CET | 49719 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:12.277987957 CET | 49718 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:12.279252052 CET | 49720 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:12.282947063 CET | 80 | 49718 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:12.283015013 CET | 49718 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:12.284118891 CET | 80 | 49720 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:12.284194946 CET | 49720 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:12.284264088 CET | 49720 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:12.289015055 CET | 80 | 49720 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:12.905452013 CET | 80 | 49720 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:12.906641006 CET | 49721 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:12.906748056 CET | 443 | 49721 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:12.906855106 CET | 49721 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:12.907072067 CET | 49721 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:12.907095909 CET | 443 | 49721 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:12.958256006 CET | 49720 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:16.710800886 CET | 443 | 49721 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:16.733583927 CET | 49721 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:16.733678102 CET | 443 | 49721 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:17.174097061 CET | 443 | 49721 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:17.187551975 CET | 443 | 49721 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:17.187634945 CET | 49721 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:17.189979076 CET | 49721 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:17.224287033 CET | 49722 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:17.229264975 CET | 80 | 49722 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:17.229402065 CET | 49722 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:17.229463100 CET | 49722 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:17.234268904 CET | 80 | 49722 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:17.835716009 CET | 80 | 49722 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:17.836836100 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:17.836879015 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:17.836992979 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:17.837240934 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:17.837255955 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:17.880145073 CET | 49722 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:19.688405991 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:19.702826023 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:19.702843904 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:20.166229963 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:20.166398048 CET | 443 | 49723 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:20.166455984 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:20.167007923 CET | 49723 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:20.171375990 CET | 49722 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:20.172785044 CET | 49724 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:20.176485062 CET | 80 | 49722 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:20.176547050 CET | 49722 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:20.177578926 CET | 80 | 49724 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:20.177711964 CET | 49724 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:20.177789927 CET | 49724 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:20.182518959 CET | 80 | 49724 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:20.774971008 CET | 80 | 49724 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:20.780008078 CET | 49725 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:20.780108929 CET | 443 | 49725 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:20.780262947 CET | 49725 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:20.783982038 CET | 49725 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:20.784014940 CET | 443 | 49725 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:20.817670107 CET | 49724 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:24.472847939 CET | 443 | 49725 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:24.474380016 CET | 49725 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:24.474417925 CET | 443 | 49725 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:24.966706991 CET | 443 | 49725 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:24.966795921 CET | 443 | 49725 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:24.966897011 CET | 49725 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:24.967322111 CET | 49725 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:24.974162102 CET | 49724 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:24.974893093 CET | 49726 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:24.979487896 CET | 80 | 49724 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:24.979569912 CET | 49724 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:24.979701042 CET | 80 | 49726 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:24.979903936 CET | 49726 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:24.980058908 CET | 49726 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:24.984853029 CET | 80 | 49726 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:25.578213930 CET | 80 | 49726 | 158.101.44.242 | 192.168.2.5 |
Mar 11, 2025 08:03:25.579556942 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:25.579602957 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:25.579823971 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:25.580133915 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:25.580159903 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:25.630171061 CET | 49726 | 80 | 192.168.2.5 | 158.101.44.242 |
Mar 11, 2025 08:03:27.280376911 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:27.333995104 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:28.944253922 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Mar 11, 2025 08:03:28.944283009 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:30.112008095 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:30.112200975 CET | 443 | 49727 | 104.21.96.1 | 192.168.2.5 |
Mar 11, 2025 08:03:30.112258911 CET | 49727 | 443 | 192.168.2.5 | 104.21.96.1 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 11, 2025 08:02:51.013919115 CET | 58558 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 08:02:51.021012068 CET | 53 | 58558 | 1.1.1.1 | 192.168.2.5 |
Mar 11, 2025 08:02:55.373943090 CET | 54484 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 08:02:55.381290913 CET | 53 | 54484 | 1.1.1.1 | 192.168.2.5 |
Mar 11, 2025 08:03:01.624563932 CET | 57335 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 08:03:01.632842064 CET | 53 | 57335 | 1.1.1.1 | 192.168.2.5 |
Mar 11, 2025 08:03:02.731826067 CET | 54220 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 11, 2025 08:03:02.739332914 CET | 53 | 54220 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 11, 2025 08:02:51.013919115 CET | 192.168.2.5 | 1.1.1.1 | 0x78d8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2025 08:02:55.373943090 CET | 192.168.2.5 | 1.1.1.1 | 0x1c91 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2025 08:03:01.624563932 CET | 192.168.2.5 | 1.1.1.1 | 0xb454 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2025 08:03:02.731826067 CET | 192.168.2.5 | 1.1.1.1 | 0xf1d4 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 11, 2025 08:02:51.021012068 CET | 1.1.1.1 | 192.168.2.5 | 0x78d8 | No error (0) | 172.217.16.142 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:02:55.381290913 CET | 1.1.1.1 | 192.168.2.5 | 0x1c91 | No error (0) | 172.217.16.193 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:01.632842064 CET | 1.1.1.1 | 192.168.2.5 | 0xb454 | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:01.632842064 CET | 1.1.1.1 | 192.168.2.5 | 0xb454 | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:01.632842064 CET | 1.1.1.1 | 192.168.2.5 | 0xb454 | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:01.632842064 CET | 1.1.1.1 | 192.168.2.5 | 0xb454 | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:01.632842064 CET | 1.1.1.1 | 192.168.2.5 | 0xb454 | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:01.632842064 CET | 1.1.1.1 | 192.168.2.5 | 0xb454 | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:02.739332914 CET | 1.1.1.1 | 192.168.2.5 | 0xf1d4 | No error (0) | 104.21.96.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:02.739332914 CET | 1.1.1.1 | 192.168.2.5 | 0xf1d4 | No error (0) | 104.21.64.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:02.739332914 CET | 1.1.1.1 | 192.168.2.5 | 0xf1d4 | No error (0) | 104.21.48.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:02.739332914 CET | 1.1.1.1 | 192.168.2.5 | 0xf1d4 | No error (0) | 104.21.80.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:02.739332914 CET | 1.1.1.1 | 192.168.2.5 | 0xf1d4 | No error (0) | 104.21.32.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:02.739332914 CET | 1.1.1.1 | 192.168.2.5 | 0xf1d4 | No error (0) | 104.21.112.1 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2025 08:03:02.739332914 CET | 1.1.1.1 | 192.168.2.5 | 0xf1d4 | No error (0) | 104.21.16.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49715 | 158.101.44.242 | 80 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 08:03:01.641990900 CET | 151 | OUT | |
Mar 11, 2025 08:03:02.244139910 CET | 321 | IN | |
Mar 11, 2025 08:03:02.247921944 CET | 127 | OUT | |
Mar 11, 2025 08:03:02.406353951 CET | 321 | IN | |
Mar 11, 2025 08:03:05.001833916 CET | 127 | OUT | |
Mar 11, 2025 08:03:05.177953005 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49718 | 158.101.44.242 | 80 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 08:03:09.284790993 CET | 127 | OUT | |
Mar 11, 2025 08:03:09.864269018 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49720 | 158.101.44.242 | 80 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 08:03:12.284264088 CET | 127 | OUT | |
Mar 11, 2025 08:03:12.905452013 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49722 | 158.101.44.242 | 80 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 08:03:17.229463100 CET | 151 | OUT | |
Mar 11, 2025 08:03:17.835716009 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49724 | 158.101.44.242 | 80 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 08:03:20.177789927 CET | 151 | OUT | |
Mar 11, 2025 08:03:20.774971008 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49726 | 158.101.44.242 | 80 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 11, 2025 08:03:24.980058908 CET | 151 | OUT | |
Mar 11, 2025 08:03:25.578213930 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49713 | 172.217.16.142 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:02:54 UTC | 216 | OUT | |
2025-03-11 07:02:55 UTC | 1610 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49714 | 172.217.16.193 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:02:57 UTC | 258 | OUT | |
2025-03-11 07:03:00 UTC | 5016 | IN | |
2025-03-11 07:03:00 UTC | 5016 | IN | |
2025-03-11 07:03:00 UTC | 4663 | IN | |
2025-03-11 07:03:00 UTC | 1325 | IN | |
2025-03-11 07:03:00 UTC | 1378 | IN | |
2025-03-11 07:03:00 UTC | 1378 | IN | |
2025-03-11 07:03:00 UTC | 1378 | IN | |
2025-03-11 07:03:00 UTC | 1378 | IN | |
2025-03-11 07:03:00 UTC | 1378 | IN | |
2025-03-11 07:03:00 UTC | 1378 | IN | |
2025-03-11 07:03:00 UTC | 1378 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49716 | 104.21.96.1 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:03:04 UTC | 85 | OUT | |
2025-03-11 07:03:04 UTC | 863 | IN | |
2025-03-11 07:03:04 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49717 | 104.21.96.1 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:03:07 UTC | 61 | OUT | |
2025-03-11 07:03:09 UTC | 860 | IN | |
2025-03-11 07:03:09 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49719 | 104.21.96.1 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:03:11 UTC | 85 | OUT | |
2025-03-11 07:03:12 UTC | 857 | IN | |
2025-03-11 07:03:12 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49721 | 104.21.96.1 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:03:16 UTC | 85 | OUT | |
2025-03-11 07:03:17 UTC | 853 | IN | |
2025-03-11 07:03:17 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49723 | 104.21.96.1 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:03:19 UTC | 61 | OUT | |
2025-03-11 07:03:20 UTC | 863 | IN | |
2025-03-11 07:03:20 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49725 | 104.21.96.1 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:03:24 UTC | 85 | OUT | |
2025-03-11 07:03:24 UTC | 857 | IN | |
2025-03-11 07:03:24 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49727 | 104.21.96.1 | 443 | 7148 | C:\Users\user\Desktop\rDatosbancarios.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-11 07:03:28 UTC | 61 | OUT | |
2025-03-11 07:03:30 UTC | 860 | IN | |
2025-03-11 07:03:30 UTC | 362 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 03:01:21 |
Start date: | 11/03/2025 |
Path: | C:\Users\user\Desktop\rDatosbancarios.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 890'069 bytes |
MD5 hash: | AD465ED89A2C85DE228C1ECA00AD3C21 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 03:02:45 |
Start date: | 11/03/2025 |
Path: | C:\Users\user\Desktop\rDatosbancarios.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 890'069 bytes |
MD5 hash: | AD465ED89A2C85DE228C1ECA00AD3C21 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |