Analysis Report Thag3EQkV3.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Startup |
---|
|
Malware Configuration |
---|
Threatname: NanoCore |
---|
{"Version": "1.2.2.0", "Mutex": "46cf722b-bc9c-42c9-8cd2-ffe3d266", "Group": "Guestar", "Domain1": "securityveriservers.ddns.net", "Domain2": "securityveriservers.ddns.net", "Port": 1204, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8"}
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> |
| |
JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security | ||
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
Click to see the 3 entries |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth |
| |
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> |
| |
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
Click to see the 3 entries |
Sigma Overview |
---|
System Summary: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
Sigma detected: Scheduled temp file as task from temp location | Show sources |
Source: | Author: Joe Security: |
Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Multi AV Scanner detection for dropped file | Show sources |
Source: | ReversingLabs: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Networking: |
---|
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) | Show sources |
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
C2 URLs / IPs found in malware configuration | Show sources |
Source: | URLs: |
Uses dynamic DNS services | Show sources |
Source: | DNS query: |
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
E-Banking Fraud: |
---|
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary: |
---|
Malicious sample detected (through community Yara rule) | Show sources |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00C5C124 | |
Source: | Code function: | 0_2_00C5E560 | |
Source: | Code function: | 0_2_00C5E570 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Data Obfuscation: |
---|
.NET source code contains potential unpacker | Show sources |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Boot Survival: |
---|
Uses schtasks.exe or at.exe to add and modify task schedules | Show sources |
Source: | Process created: |
Hooking and other Techniques for Hiding and Protection: |
---|
Hides that the sample has been downloaded from the Internet (zone.identifier) | Show sources |
Source: | File opened: |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion: |
---|
Yara detected AntiVM3 | Show sources |
Source: | File source: | ||
Source: | File source: |
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) | Show sources |
Source: | WMI Queries: |
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) | Show sources |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Registry key queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior | ||
Source: | File opened / queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | |||
Source: | Window / User API: | |||
Source: | Window / User API: | |||
Source: | Window / User API: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion: |
---|
Adds a directory exclusion to Windows Defender | Show sources |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information: |
---|
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality: |
---|
Detected Nanocore Rat | Show sources |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation11 | Scheduled Task/Job1 | Process Injection11 | Masquerading1 | OS Credential Dumping | Query Registry1 | Remote Services | Archive Collected Data1 | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job1 | Boot or Logon Initialization Scripts | Scheduled Task/Job1 | Disable or Modify Tools11 | LSASS Memory | Security Software Discovery321 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Non-Standard Port1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Virtualization/Sandbox Evasion131 | Security Account Manager | Process Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Remote Access Software1 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Process Injection11 | NTDS | Virtualization/Sandbox Evasion131 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Non-Application Layer Protocol1 | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Hidden Files and Directories1 | LSA Secrets | Application Window Discovery1 | SSH | Keylogging | Data Transfer Size Limits | Application Layer Protocol21 | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | Obfuscated Files or Information1 | Cached Domain Credentials | File and Directory Discovery1 | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Software Packing11 | DCSync | System Information Discovery12 | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
43% | Virustotal | Browse | ||
12% | Metadefender | Browse | ||
48% | ReversingLabs | Win32.Infostealer.Racealer |
Dropped Files |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Metadefender | Browse | ||
48% | ReversingLabs | Win32.Infostealer.Racealer |
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
2% | Virustotal | Browse |
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
2% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
securityveriservers.ddns.net | 89.44.9.69 | true | true |
| unknown |
Contacted URLs |
---|
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| low | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high |
Contacted IPs |
---|
General Information |
---|
Joe Sandbox Version: | 32.0.0 Black Diamond |
Analysis ID: | 403510 |
Start date: | 04.05.2021 |
Start time: | 06:51:27 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 10m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | Thag3EQkV3.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 27 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@15/23@14/2 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
06:52:21 | API Interceptor | |
06:53:18 | API Interceptor |
Joe Sandbox View / Context |
---|
IPs |
---|
No context |
---|
Domains |
---|
No context |
---|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
M247GB | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | modified |
Size (bytes): | 1308 |
Entropy (8bit): | 5.345811588615766 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84FsXE8:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzu |
MD5: | 2E016B886BDB8389D2DD0867BE55F87B |
SHA1: | 25D28EF2ACBB41764571E06E11BF4C05DD0E2F8B |
SHA-256: | 1D037CF00A8849E6866603297F85D3DABE09535E72EDD2636FB7D0F6C7DA3427 |
SHA-512: | C100729153954328AA2A77EECB2A3CBD03CB7E8E23D736000F890B17AAA50BA87745E30FB9E2B0D61E16DCA45694C79B4CE09B9F4475220BEB38CAEA546CFC2A |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 14734 |
Entropy (8bit): | 4.996142136926143 |
Encrypted: | false |
SSDEEP: | 384:4NXp5K3EJOdBSib4fdVoGIpN6KQkj2mYoH78kjh4iUx/:4NZs3EJOdBUV3IpNBQkj2mYoH7Vh4iUF |
MD5: | 4289DB95A6CDB207BA517F49C4A24D05 |
SHA1: | 548752FCAA6FF477FCA724F04809A43692B29026 |
SHA-256: | D8BEF607E5237F2BDF202D39986BE376BCCFDE2AEA8DD6226E7CA2D70380FF03 |
SHA-512: | B356277C639B39CA04ADD0BBE0087AFEADD617696F4ACE67AE5E008CD7B65AC681ECFC65BD3DD8061FC292D53FB959672F15EDF21F3DDFA2CB5EA0CC1A63BD9E |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 22312 |
Entropy (8bit): | 5.587388291742761 |
Encrypted: | false |
SSDEEP: | 384:ttCD70Fz/zj2/r3YSBKnyultIaTbWFQ9QDZ1ReR21pMrmIZ+AV7S/Lvj5rkI+C0:L72/DY4KyultzTSC9M1Re1dftP |
MD5: | 754C024678ED1CDF33F3B5803B50C98D |
SHA1: | C2A79BAD448EE0C910B6601E48779287A622525B |
SHA-256: | 2EA18101D538A33919657002B055AF4E57B29CE5452C53350827E91FE1F33853 |
SHA-512: | 354F14CEC24C32828FBA8847E131CFF7014BE67A667FF8CA17E343EE670CE9D58145559FC42EEC8367FEB7E1EEE09D3C8146D99881D64D14C26C54D8B98352D4 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1640 |
Entropy (8bit): | 5.179180318880331 |
Encrypted: | false |
SSDEEP: | 24:2dH4+SEqC/S7hblNMFp//rlMhEMjnGpwjpIgUYODOLD9RJh7h8gKBGNtn:cbhK79lNQR/rydbz9I3YODOLNdq3u |
MD5: | D14D27982BB1E341E6C76DF133118CBA |
SHA1: | 019EB713294FE92A16AFBB02D6D04163C765038A |
SHA-256: | 70BB25C92FD640D49AB95670C5CAC956B1F547B9DE926E7F8AE6BE3D5C135797 |
SHA-512: | 1046D6DE61AA44586CBF2D822132756FD9CDA4A64CCC4DD3925BD7995DD23D96C259286647227BEF8C795F95E5AA728D1F2B52872BFA65D8227D635C7965270E |
Malicious: | true |
Preview: |
|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1944 |
Entropy (8bit): | 7.002255904801018 |
Encrypted: | false |
SSDEEP: | 48:Ik/l4qk/l4qk/l4qk/l4qk/l4qk/l4qk/l4qk/l4qk/l4x:flglglglglglglglglE |
MD5: | F15D8A964EB90E425BE1A8D14737C261 |
SHA1: | EE64B9095C84589881EDD4A317280FC461360209 |
SHA-256: | F68636A717CDEEF69EA7AC43F1FC96DE8010565A16840C0B9924D27560E07BF4 |
SHA-512: | DFC56338D3E813FF0473DE54E4C5AC56810936E086DADE9FC7803C0536A79310D50967F65B47FD3F55EB2E62F3B6035CF6DF89DB9CF3294C64688EBF0A974AFB |
Malicious: | false |
Preview: |
|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8 |
Entropy (8bit): | 3.0 |
Encrypted: | false |
SSDEEP: | 3:xr8n:xr8 |
MD5: | 5E22D59515A7D7900E9D95C1C71BEAE6 |
SHA1: | ADA625A0478EB2762E67565523C833ED8306D5B6 |
SHA-256: | 7BB7A7DAFCB215094BF61420BBC13BE7519DA99902B968BF9D124D56CA16C987 |
SHA-512: | 18BC7F318674BEF1C94E19AA6D542C739140944B569B921942F178E3D14AEAE57BC5FF8510C13D395D6B504DEA2804227081C70A3BD5210BF9835F431174313F |
Malicious: | true |
Preview: |
|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40 |
Entropy (8bit): | 5.153055907333276 |
Encrypted: | false |
SSDEEP: | 3:9bzY6oRDT6P2bfVn1:RzWDT621 |
MD5: | 4E5E92E2369688041CC82EF9650EDED2 |
SHA1: | 15E44F2F3194EE232B44E9684163B6F66472C862 |
SHA-256: | F8098A6290118F2944B9E7C842BD014377D45844379F863B00D54515A8A64B48 |
SHA-512: | 1B368018907A3BC30421FDA2C935B39DC9073B9B1248881E70AD48EDB6CAA256070C1A90B97B0F64BBE61E316DBB8D5B2EC8DBABCD0B0B2999AB50B933671ECB |
Malicious: | false |
Preview: |
|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 297592 |
Entropy (8bit): | 7.999366200245906 |
Encrypted: | true |
SSDEEP: | 6144:b23o8kGKvpIJIA9PT4kFq4Bm5Tb9dfoCjKjpdHUz5QGPqxjQ3VxsnnUC+GeNIa:58kLp9YPT4ks7TOCWjpd0zWrGS8X |
MD5: | 27C5226E10AC55C8A6CEA5328C87F82A |
SHA1: | 25A1EDE5EA110A07BCCD617C233277614AEF93D1 |
SHA-256: | 6C2E803D5ABEC40BC313078A3A8F319D24F3975ACC04F39A47852B5F9AA12117 |
SHA-512: | 62522485FC3BE164394673627BD52AE6CC81B6A151F05102630761DFE81E2F40CB04F0FF938DA9B4C5A75A95D628EAE25D106509BCFF415A98FA706AE1031A28 |
Malicious: | false |
Preview: |
|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1311744 |
Entropy (8bit): | 7.035004480483992 |
Encrypted: | false |
SSDEEP: | 12288:eDyZy/oX9DtB9lovcsB4AGbIkDH3CPKkm2QoktltFFxiHC6gQLPqSE:AyZy6DnpsBHa6KP+gtfxOTPqN |
MD5: | 46596598EE9FE7C1B4677CBBFE8A00BF |
SHA1: | 59EAE73C4D6519A70F0BE2DF462AF90C8F53A5B0 |
SHA-256: | 01049EDAF2CE6F350D8309ED530221C8371FAAC224E408C778BEB56C7211DF19 |
SHA-512: | 960951EB58367493640E5363B40E33AA24F39A195B54F26D36E11DBBC89DF618223AF6FFF7B641C5E7441C73A18705C263CE3A97F2D4A4D2EA6405B54276A2E7 |
Malicious: | true |
Antivirus: |
|
Preview: |
|
Process: | C:\Users\user\Desktop\Thag3EQkV3.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5777 |
Entropy (8bit): | 5.402523674305656 |
Encrypted: | false |
SSDEEP: | 96:BZujGNOqDo1Z1ZijGNOqDo1ZidLVjZxjGNOqDo1ZnYlljZ4:I |
MD5: | AE80BB0969755834B22C49E2710C1879 |
SHA1: | 5E4D56A8ED215622758F13EF4FF40EE49B94667A |
SHA-256: | 6D1D5D8D917C8AF594DD6C5B2D914F90B619CD5F4EC9452E455092FEDC4F19FB |
SHA-512: | 31B8BD4451D13897FF81A3EA100AEE50FBD42868C64A47660BAEFBADF1735EE80900F59E38997995F4D7CB6C3727B646DC94B59C374BD52FDF8A9A56AAEE6EC7 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5733 |
Entropy (8bit): | 5.39470775499149 |
Encrypted: | false |
SSDEEP: | 96:BZCjGNhqDo1ZIZTjGNhqDo1ZVYuAjZgjGNhqDo1ZI9QQrTZBq:u |
MD5: | 3AFDFFF2BA546E1410B6BA47B9435731 |
SHA1: | 96FC4BCE1BA6E26C8EB5608BDEF077F3E3D5B285 |
SHA-256: | 773E323B92C6F78BB31EB941A8E7C80B18276A7611F88310B5AC8900DFA8EBBB |
SHA-512: | C21914E26ED1885A2E140C03BE7AF010779053FB17DCC04CABA8FBCA123FC652471CCAC1294745BCBCFC9708DE5049E0100ADF6F5FFC463AAEFB3D959B6D407D |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5777 |
Entropy (8bit): | 5.399592740502258 |
Encrypted: | false |
SSDEEP: | 96:BZnjGNQqDo1ZeZ2jGNQqDo1Z+dLVjZ8jGNQqDo1ZEYllrZc:A |
MD5: | 09A6D1ABE1086CECD57807AFC96A0203 |
SHA1: | 7D7A2726E2F54C62C88C4957FC4EDB106CDECC29 |
SHA-256: | 6827BA8FAE92650D3A7D1D91EDD8D1022C089DEAE3A985658BF736882A30FB6F |
SHA-512: | 09671B1FAE168F2B66E95A2F42D09F54E75AFC7A05FFE2416C74C9003950A31D5C3FBBA9628E637509B9B0798EC56E5E61B9AC68F116816F81B6EAB528EFF4AF |
Malicious: | false |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 7.035004480483992 |
TrID: |
|
File name: | Thag3EQkV3.exe |
File size: | 1311744 |
MD5: | 46596598ee9fe7c1b4677cbbfe8a00bf |
SHA1: | 59eae73c4d6519a70f0be2df462af90c8f53a5b0 |
SHA256: | 01049edaf2ce6f350d8309ed530221c8371faac224e408c778beb56c7211df19 |
SHA512: | 960951eb58367493640e5363b40e33aa24f39a195b54f26d36e11dbbc89df618223af6fff7b641c5e7441c73a18705c263ce3a97f2d4a4d2ea6405b54276a2e7 |
SSDEEP: | 12288:eDyZy/oX9DtB9lovcsB4AGbIkDH3CPKkm2QoktltFFxiHC6gQLPqSE:AyZy6DnpsBHa6KP+gtfxOTPqN |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......`..............0..~............... ........@.. .......................`............@................................ |
File Icon |
---|
Icon Hash: | d2d2d2f2f2d2cad2 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x519d96 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | 32BIT_MACHINE, EXECUTABLE_IMAGE |
DLL Characteristics: | NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x608BDEB0 [Fri Apr 30 10:40:48 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | v4.0.30319 |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Entrypoint Preview |
---|
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x119d44 | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x11a000 | 0x28054 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x144000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x117d9c | 0x117e00 | False | 0.615071251117 | data | 7.17004938449 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rsrc | 0x11a000 | 0x28054 | 0x28200 | False | 0.196596329829 | data | 5.52128689383 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x144000 | 0xc | 0x200 | False | 0.044921875 | data | 0.101910425663 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x11a280 | 0x10828 | dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0 | ||
RT_ICON | 0x12aaa8 | 0x94a8 | data | ||
RT_ICON | 0x133f50 | 0x5488 | data | ||
RT_ICON | 0x1393d8 | 0x4228 | dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 4294967295, next used block 4294967295 | ||
RT_ICON | 0x13d600 | 0x25a8 | data | ||
RT_ICON | 0x13fba8 | 0x10a8 | data | ||
RT_ICON | 0x140c50 | 0x988 | data | ||
RT_ICON | 0x1415d8 | 0x468 | GLS_BINARY_LSB_FIRST | ||
RT_GROUP_ICON | 0x141a40 | 0x76 | data | ||
RT_VERSION | 0x141ab8 | 0x3b0 | data | ||
RT_MANIFEST | 0x141e68 | 0x1ea | XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
Imports |
---|
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Version Infos |
---|
Description | Data |
---|---|
Translation | 0x0000 0x04b0 |
LegalCopyright | Copyright 2018 Pointers |
Assembly Version | 2.0.0.0 |
InternalName | SuppressMessageAttribute.exe |
FileVersion | 2.0.0.0 |
CompanyName | Pointers LTD |
LegalTrademarks | Pointers |
Comments | |
ProductName | KatmanliMimari |
ProductVersion | 2.0.0.0 |
FileDescription | KatmanliMimari |
OriginalFilename | SuppressMessageAttribute.exe |
Network Behavior |
---|
Snort IDS Alerts |
---|
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
05/04/21-06:52:35.691617 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:52:46.315666 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:52:57.613869 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:53:11.216231 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:53:27.511572 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:53:37.218154 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:53:46.102076 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:54:00.921342 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:54:08.453123 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:54:15.214826 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:54:22.087740 | ICMP | 402 | ICMP Destination Unreachable Port Unreachable | 192.168.2.4 | 8.8.8.8 | ||
05/04/21-06:54:22.252566 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
05/04/21-06:54:28.311488 | TCP | 2025019 | ET TROJAN Possible NanoCore C2 60B | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 4, 2021 06:52:35.491203070 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:35.560121059 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:35.561686039 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:35.691617012 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:35.769012928 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:35.809966087 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:36.396981955 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:36.465771914 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:36.606942892 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:36.781653881 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:36.892478943 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:36.892548084 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.001183987 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033832073 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033859968 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033875942 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033895016 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033914089 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033929110 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033946037 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033956051 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.033962965 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033979893 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.033982038 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.034025908 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.035512924 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.035581112 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.103682995 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103702068 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103722095 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103739977 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103756905 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103774071 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103790045 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103806019 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103809118 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.103823900 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.103852034 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.103884935 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.106355906 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106383085 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106399059 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106415987 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106416941 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.106431961 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106451035 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106467009 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106486082 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106503010 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.106504917 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.106638908 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.109445095 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.109472036 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.109544992 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.172991991 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173026085 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173042059 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173054934 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173182964 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.173284054 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173301935 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173378944 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.173876047 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173897982 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.173981905 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.174207926 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174228907 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174246073 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174263000 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174278975 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174292088 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.174299002 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174318075 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174334049 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174350977 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174355984 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.174369097 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.174396038 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.174431086 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.175620079 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175646067 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175676107 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175695896 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175714016 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175729990 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175772905 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.175812960 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.175851107 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175870895 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175889015 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175905943 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175921917 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175939083 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175941944 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.175956964 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175973892 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.175987005 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.175990105 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.176012039 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.176016092 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.176031113 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.176047087 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.176075935 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.176120043 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.179569960 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.179591894 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.179610968 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.179629087 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.179671049 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.179692030 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.243503094 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243529081 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243550062 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243567944 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243585110 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243593931 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.243626118 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.243721962 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243740082 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243772030 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243789911 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243803024 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.243807077 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243830919 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243846893 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243858099 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.243863106 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.243891001 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.244152069 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244196892 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244206905 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.244215965 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244231939 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244267941 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.244680882 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244703054 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244719982 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244735003 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244766951 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244771004 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.244784117 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.244806051 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.244831085 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.245017052 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.245034933 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.245064974 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.245434999 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.245457888 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.245488882 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.245589972 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.245630980 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.245649099 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.245651007 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.245690107 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.246217966 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246242046 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246258974 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246274948 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246292114 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246298075 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.246313095 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246332884 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.246452093 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.246501923 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246551991 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246572018 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246593952 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.246778011 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246794939 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246841908 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.246867895 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246885061 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246901989 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.246937990 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.246951103 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.248203039 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.248230934 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.248311996 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.248326063 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.248332024 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.248380899 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.311333895 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.311366081 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.311428070 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.311578989 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.311810017 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.311829090 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.311861038 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.312594891 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.312622070 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.312653065 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.312663078 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.312683105 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.312728882 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.312768936 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.312786102 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.312815905 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.313148022 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.313165903 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.313230991 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.313682079 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.313699961 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.313716888 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.313762903 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.314138889 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314234018 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314250946 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314280987 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.314325094 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314342022 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314359903 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314371109 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.314376116 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314402103 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.314570904 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314588070 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314618111 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.314760923 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314779043 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.314807892 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.314981937 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315011024 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315031052 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315031052 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.315083981 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.315181017 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315502882 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315522909 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315540075 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315556049 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315576077 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.315609932 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.315705061 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315752983 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.315932989 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.315951109 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.316004038 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.316003084 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.316025019 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.316066980 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.316864967 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.316884995 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.316986084 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.317161083 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.317178965 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.317234993 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.318666935 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.321103096 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.321129084 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.321146011 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.321162939 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.321187973 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.321264982 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.379760027 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.379792929 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.379884958 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.380163908 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.380181074 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.380222082 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.381256104 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.381279945 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.381335020 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.381545067 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.381562948 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.381582022 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.381598949 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.381606102 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.381652117 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.381933928 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.381964922 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.382000923 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.382129908 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.382150888 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.382169962 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.382181883 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.382188082 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.382226944 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.382354021 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.382378101 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.382412910 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.383192062 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383220911 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383239031 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383256912 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383270979 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.383272886 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383291006 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383327007 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.383382082 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383399010 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383429050 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.383605957 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383631945 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383660078 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.383881092 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383900881 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.383941889 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.384690046 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384723902 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384747982 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384773016 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384774923 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.384795904 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384815931 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.384819031 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384841919 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384865046 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384875059 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.384888887 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.384928942 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.384958982 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.385123968 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.385157108 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.385201931 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.385759115 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.385778904 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.385839939 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.391679049 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.391721964 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.391742945 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.391758919 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.391776085 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.391822100 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456168890 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456208944 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456233978 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456257105 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456279993 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456304073 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456327915 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456347942 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456360102 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456373930 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456398964 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456423044 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456439972 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456450939 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456478119 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456479073 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456502914 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456526041 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456535101 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456551075 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456572056 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456573009 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456598043 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456610918 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456621885 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456650972 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456664085 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456676960 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456701994 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456721067 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456727028 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456751108 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456765890 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.456772089 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456794024 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:37.456811905 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:37.497647047 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:38.168520927 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:38.619600058 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:38.732036114 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:40.633016109 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:40.810400963 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:40.853120089 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:40.961617947 CEST | 1204 | 49740 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:41.714883089 CEST | 49740 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:46.232172012 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:46.299386978 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:46.299757957 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:46.315665960 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:46.394694090 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:46.414989948 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:46.483139038 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:46.490730047 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:46.604209900 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:46.706515074 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:46.810971022 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:46.878736973 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:47.002705097 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:47.076047897 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:47.184163094 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:47.184452057 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:47.304866076 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:47.305376053 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:47.373372078 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:47.373475075 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:47.442584991 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:47.501111984 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:48.173137903 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:48.284779072 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:48.285408974 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:48.393176079 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:48.393286943 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:48.501290083 CEST | 1204 | 49745 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:49.451256990 CEST | 49745 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:57.545671940 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:57.612907887 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:57.613814116 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:57.613868952 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:57.697540045 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:57.720973969 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:57.793394089 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:57.796173096 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:57.908742905 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:58.007234097 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:58.008512020 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:58.076405048 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:58.124399900 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:58.178662062 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:58.249135971 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:58.249376059 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:58.317272902 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:52:58.358789921 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:59.252650023 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:52:59.373501062 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:00.289082050 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:00.342820883 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:00.405827999 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:00.408273935 CEST | 1204 | 49746 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:01.903224945 CEST | 49746 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:10.929858923 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:10.993899107 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:10.994031906 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:11.216231108 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:11.289298058 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:11.344266891 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:11.529098034 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:11.593524933 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:11.641120911 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:11.794648886 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:11.904603004 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:12.127938986 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:12.232786894 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:12.335633993 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:12.377758980 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:12.419106007 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:12.445350885 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:12.501635075 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:12.525865078 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:12.901041031 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:13.007975101 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:13.008714914 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:13.073458910 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:13.073646069 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:13.138786077 CEST | 1204 | 49749 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:13.188806057 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:13.951378107 CEST | 49749 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:27.435270071 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:27.502469063 CEST | 1204 | 49755 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:27.502593994 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:27.511571884 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:27.591355085 CEST | 1204 | 49755 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:27.642564058 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:28.099154949 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:28.167917967 CEST | 1204 | 49755 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:28.220628023 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:28.796838045 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:28.925685883 CEST | 1204 | 49755 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:29.649704933 CEST | 49755 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:36.905026913 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:36.968735933 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:36.968888044 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:37.218153954 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:37.300997972 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:37.346492052 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:37.454842091 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:37.568762064 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:37.568870068 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:37.634685993 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:37.690179110 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:37.926220894 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:38.031299114 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:38.130388021 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:38.174726009 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:38.239795923 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:38.284037113 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:38.491312027 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:38.597199917 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:39.046555996 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:39.151981115 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:39.357856035 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:39.422492981 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:39.422697067 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:39.464077950 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:39.487119913 CEST | 1204 | 49762 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:39.487246037 CEST | 49762 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:45.672123909 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:45.735991001 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:45.736134052 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.102076054 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.178654909 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:46.178924084 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.243328094 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:46.243462086 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.348309994 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:46.348401070 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.454900980 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:46.550573111 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:46.597146034 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.599492073 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.661988974 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:46.706543922 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:46.709376097 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:48.146815062 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:48.212903023 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:48.212975025 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:48.277606010 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:48.277795076 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:48.387741089 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:48.559736967 CEST | 1204 | 49763 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:48.612977028 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:49.381495953 CEST | 49763 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:56.101785898 CEST | 49764 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:56.169095039 CEST | 1204 | 49764 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:53:56.169260979 CEST | 49764 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:56.324098110 CEST | 49764 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:53:56.391787052 CEST | 1204 | 49764 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:00.852543116 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:00.920010090 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:00.920140982 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:00.921341896 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:01.001076937 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:01.020622969 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:01.088555098 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:01.129616022 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:01.672348976 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:01.780565977 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:01.780724049 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:01.881478071 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:01.926635027 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:01.952238083 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:01.994373083 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:02.035986900 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:02.110683918 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:02.110810041 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:02.198746920 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:02.254786968 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:02.331031084 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:02.434952974 CEST | 1204 | 49765 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:02.489145994 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:03.724477053 CEST | 49765 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.220510960 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.288276911 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:08.290035009 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.453123093 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.534425020 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:08.534749031 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.603375912 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:08.604897022 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.713562012 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:08.764432907 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.820703983 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:08.832149982 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:08.834104061 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:08.961545944 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:09.069113016 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:09.210412025 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:09.280204058 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:09.280339003 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:09.348495960 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:09.395973921 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:09.930505991 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:10.037915945 CEST | 1204 | 49766 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:10.975117922 CEST | 49766 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.148572922 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.214135885 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.214277029 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.214826107 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.279702902 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.333894014 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.398487091 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.405915022 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.472532034 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.474013090 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.581523895 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.689707994 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.701209068 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.765680075 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.788692951 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.857310057 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.858334064 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:15.923360109 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:15.923541069 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:16.034842014 CEST | 1204 | 49771 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:16.038151979 CEST | 49771 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.187760115 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.251663923 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.251827002 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.252566099 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.327446938 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.333709002 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.398215055 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.437448025 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.548134089 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.644144058 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.670923948 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.736665964 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.737962008 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.802411079 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.802486897 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.868388891 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:22.912703991 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:22.929492950 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:23.050714970 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:23.147660971 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:23.264214039 CEST | 1204 | 49777 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:24.165575981 CEST | 49777 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.239888906 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.307215929 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.308080912 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.311487913 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.391191959 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.406194925 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.474184036 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.486093044 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.595830917 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.694439888 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.695931911 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.766254902 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.819437027 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.889107943 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.911396027 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:28.979672909 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:28.979866982 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:29.049014091 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:29.052000046 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:29.159461975 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:33.380392075 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:33.429177046 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:36.851210117 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:36.898224115 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:38.379756927 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:38.429615974 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:43.391854048 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:43.523832083 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:44.891895056 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:45.023938894 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:48.407455921 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:48.524202108 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:52.939146996 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:53.024576902 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:53.407818079 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:53.524599075 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:54:58.422418118 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:54:58.525043011 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:55:00.985512018 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:55:01.025305986 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
May 4, 2021 06:55:03.430908918 CEST | 1204 | 49779 | 89.44.9.69 | 192.168.2.4 |
May 4, 2021 06:55:03.525459051 CEST | 49779 | 1204 | 192.168.2.4 | 89.44.9.69 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 4, 2021 06:52:14.400979996 CEST | 54531 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:14.449677944 CEST | 53 | 54531 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:15.109172106 CEST | 49714 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:15.168134928 CEST | 53 | 49714 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:15.378720999 CEST | 58028 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:15.427373886 CEST | 53 | 58028 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:16.750510931 CEST | 53097 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:16.799173117 CEST | 53 | 53097 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:18.013556957 CEST | 49257 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:18.070765972 CEST | 53 | 49257 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:19.156615019 CEST | 62389 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:19.205136061 CEST | 53 | 62389 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:20.582920074 CEST | 49910 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:20.636848927 CEST | 53 | 49910 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:21.561728954 CEST | 55854 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:21.614970922 CEST | 53 | 55854 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:22.900630951 CEST | 64549 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:22.949564934 CEST | 53 | 64549 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:23.937971115 CEST | 63153 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:23.986418962 CEST | 53 | 63153 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:25.497857094 CEST | 52991 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:25.549484015 CEST | 53 | 52991 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:26.880570889 CEST | 53700 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:26.930425882 CEST | 53 | 53700 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:28.479382992 CEST | 51726 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:28.530997992 CEST | 53 | 51726 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:29.842281103 CEST | 56794 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:29.890939951 CEST | 53 | 56794 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:30.807148933 CEST | 56534 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:30.857218027 CEST | 53 | 56534 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:32.316198111 CEST | 56627 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:32.367845058 CEST | 53 | 56627 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:33.552509069 CEST | 56621 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:33.601248026 CEST | 53 | 56621 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:34.760373116 CEST | 63116 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:34.811897993 CEST | 53 | 63116 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:35.404788017 CEST | 64078 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:35.468126059 CEST | 53 | 64078 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:36.360310078 CEST | 64801 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:36.418663025 CEST | 53 | 64801 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:38.334563971 CEST | 61721 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:38.387707949 CEST | 53 | 61721 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:45.283684015 CEST | 51255 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:45.335408926 CEST | 53 | 51255 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:46.168754101 CEST | 61522 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:46.229815960 CEST | 53 | 61522 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:52:57.483375072 CEST | 52337 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:52:57.540606976 CEST | 53 | 52337 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:02.054086924 CEST | 55046 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:02.113373041 CEST | 53 | 55046 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:09.059365034 CEST | 49612 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:09.119601011 CEST | 53 | 49612 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:10.240042925 CEST | 49285 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:10.301357031 CEST | 53 | 49285 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:20.489739895 CEST | 50601 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:20.552572966 CEST | 53 | 50601 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:21.600878000 CEST | 60875 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:21.660672903 CEST | 53 | 60875 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:22.130163908 CEST | 56448 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:22.187254906 CEST | 53 | 56448 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:24.781240940 CEST | 59172 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:24.829933882 CEST | 53 | 59172 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:26.124466896 CEST | 62420 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:26.174361944 CEST | 53 | 62420 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:26.579637051 CEST | 60579 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:26.628335953 CEST | 53 | 60579 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:27.820656061 CEST | 50183 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:27.882646084 CEST | 53 | 50183 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:29.356823921 CEST | 61531 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:29.413820028 CEST | 53 | 61531 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:30.166075945 CEST | 49228 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:30.223148108 CEST | 53 | 49228 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:33.601983070 CEST | 59794 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:33.659370899 CEST | 53 | 59794 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:35.273822069 CEST | 55916 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:35.323287964 CEST | 53 | 55916 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:36.299180031 CEST | 52752 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:36.356385946 CEST | 53 | 52752 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:36.466579914 CEST | 60542 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:36.529876947 CEST | 53 | 60542 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:45.569412947 CEST | 60689 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:45.629180908 CEST | 53 | 60689 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:53:55.506566048 CEST | 64206 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:53:55.567790031 CEST | 53 | 64206 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:00.605639935 CEST | 50904 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:00.662633896 CEST | 53 | 50904 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:08.090348005 CEST | 57525 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:08.147878885 CEST | 53 | 57525 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:11.248502016 CEST | 53814 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:11.339107037 CEST | 53 | 53814 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:12.005081892 CEST | 53418 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:12.063267946 CEST | 53 | 53418 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:15.088542938 CEST | 62833 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:15.147207975 CEST | 53 | 62833 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:16.576061010 CEST | 59260 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:16.634821892 CEST | 53 | 59260 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:20.248930931 CEST | 49944 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:21.288027048 CEST | 49944 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:22.086838961 CEST | 53 | 49944 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:22.087651014 CEST | 53 | 49944 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:28.185599089 CEST | 63300 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:28.234452963 CEST | 53 | 63300 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:49.843718052 CEST | 61449 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:49.895464897 CEST | 53 | 61449 | 8.8.8.8 | 192.168.2.4 |
May 4, 2021 06:54:52.928936005 CEST | 51275 | 53 | 192.168.2.4 | 8.8.8.8 |
May 4, 2021 06:54:52.996159077 CEST | 53 | 51275 | 8.8.8.8 | 192.168.2.4 |
ICMP Packets |
---|
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
May 4, 2021 06:54:22.087739944 CEST | 192.168.2.4 | 8.8.8.8 | d010 | (Port unreachable) | Destination Unreachable |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
May 4, 2021 06:52:35.404788017 CEST | 192.168.2.4 | 8.8.8.8 | 0x87ae | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:52:46.168754101 CEST | 192.168.2.4 | 8.8.8.8 | 0xdf48 | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:52:57.483375072 CEST | 192.168.2.4 | 8.8.8.8 | 0x12fe | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:53:10.240042925 CEST | 192.168.2.4 | 8.8.8.8 | 0xe000 | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:53:26.579637051 CEST | 192.168.2.4 | 8.8.8.8 | 0xa845 | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:53:36.466579914 CEST | 192.168.2.4 | 8.8.8.8 | 0x4313 | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:53:45.569412947 CEST | 192.168.2.4 | 8.8.8.8 | 0xa9ad | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:53:55.506566048 CEST | 192.168.2.4 | 8.8.8.8 | 0xb816 | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:54:00.605639935 CEST | 192.168.2.4 | 8.8.8.8 | 0x933 | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:54:08.090348005 CEST | 192.168.2.4 | 8.8.8.8 | 0xb99f | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:54:15.088542938 CEST | 192.168.2.4 | 8.8.8.8 | 0x89f | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:54:20.248930931 CEST | 192.168.2.4 | 8.8.8.8 | 0x56fa | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:54:21.288027048 CEST | 192.168.2.4 | 8.8.8.8 | 0x56fa | Standard query (0) | A (IP address) | IN (0x0001) | |
May 4, 2021 06:54:28.185599089 CEST | 192.168.2.4 | 8.8.8.8 | 0x1829 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
May 4, 2021 06:52:35.468126059 CEST | 8.8.8.8 | 192.168.2.4 | 0x87ae | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:52:46.229815960 CEST | 8.8.8.8 | 192.168.2.4 | 0xdf48 | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:52:57.540606976 CEST | 8.8.8.8 | 192.168.2.4 | 0x12fe | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:53:10.301357031 CEST | 8.8.8.8 | 192.168.2.4 | 0xe000 | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:53:26.628335953 CEST | 8.8.8.8 | 192.168.2.4 | 0xa845 | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:53:36.529876947 CEST | 8.8.8.8 | 192.168.2.4 | 0x4313 | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:53:45.629180908 CEST | 8.8.8.8 | 192.168.2.4 | 0xa9ad | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:53:55.567790031 CEST | 8.8.8.8 | 192.168.2.4 | 0xb816 | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:54:00.662633896 CEST | 8.8.8.8 | 192.168.2.4 | 0x933 | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:54:08.147878885 CEST | 8.8.8.8 | 192.168.2.4 | 0xb99f | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:54:11.339107037 CEST | 8.8.8.8 | 192.168.2.4 | 0xec56 | No error (0) | www.tm.a.prd.aadg.akadns.net | CNAME (Canonical name) | IN (0x0001) | ||
May 4, 2021 06:54:15.147207975 CEST | 8.8.8.8 | 192.168.2.4 | 0x89f | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:54:22.086838961 CEST | 8.8.8.8 | 192.168.2.4 | 0x56fa | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:54:22.087651014 CEST | 8.8.8.8 | 192.168.2.4 | 0x56fa | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) | ||
May 4, 2021 06:54:28.234452963 CEST | 8.8.8.8 | 192.168.2.4 | 0x1829 | No error (0) | 89.44.9.69 | A (IP address) | IN (0x0001) |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
High Level Behavior Distribution |
---|
back
Click to dive into process behavior distribution
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 06:52:20 |
Start date: | 04/05/2021 |
Path: | C:\Users\user\Desktop\Thag3EQkV3.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2b0000 |
File size: | 1311744 bytes |
MD5 hash: | 46596598EE9FE7C1B4677CBBFE8A00BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
General |
---|
Start time: | 06:52:22 |
Start date: | 04/05/2021 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1070000 |
File size: | 430592 bytes |
MD5 hash: | DBA3E6449E97D4E3DF64527EF7012A10 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Reputation: | high |
General |
---|
Start time: | 06:52:23 |
Start date: | 04/05/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff724c50000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 06:52:24 |
Start date: | 04/05/2021 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1070000 |
File size: | 430592 bytes |
MD5 hash: | DBA3E6449E97D4E3DF64527EF7012A10 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Reputation: | high |
General |
---|
Start time: | 06:52:24 |
Start date: | 04/05/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff724c50000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 06:52:24 |
Start date: | 04/05/2021 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd10000 |
File size: | 185856 bytes |
MD5 hash: | 15FF7D8324231381BAD48A052F85DF04 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 06:52:24 |
Start date: | 04/05/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff724c50000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 06:52:25 |
Start date: | 04/05/2021 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1070000 |
File size: | 430592 bytes |
MD5 hash: | DBA3E6449E97D4E3DF64527EF7012A10 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Reputation: | high |
General |
---|
Start time: | 06:52:26 |
Start date: | 04/05/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff724c50000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 06:52:26 |
Start date: | 04/05/2021 |
Path: | C:\Users\user\Desktop\Thag3EQkV3.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xcf0000 |
File size: | 1311744 bytes |
MD5 hash: | 46596598EE9FE7C1B4677CBBFE8A00BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Reputation: | low |
Disassembly |
---|
Code Analysis |
---|
Executed Functions |
---|
APIs |
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5FCF7, Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5FCF8, Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C55364, Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C53DE4, Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5B97A, Relevance: 1.6, APIs: 1, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5B8B0, Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5B8B8, Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C59869, Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5FF38, Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C59870, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5FF40, Relevance: 1.5, APIs: 1, Instructions: 44COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 00C5E570, Relevance: .3, Instructions: 315COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5C124, Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C5E560, Relevance: .2, Instructions: 221COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |