Play interactive tourEdit tour
Windows Analysis Report 2u2mgtylJy.dll
Overview
General Information
Detection
Ursnif
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Sigma detected: Powershell run code from registry
Yara detected Ursnif
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Sigma detected: Encoded IEX
Maps a DLL or memory area into another process
Writes to foreign memory regions
Writes or reads registry keys via WMI
Suspicious powershell command line found
Allocates memory in foreign processes
Self deletion via cmd delete
Sigma detected: MSHTA Spawning Windows Shell
Injects code into the Windows Explorer (explorer.exe)
Modifies the context of a thread in another process (thread injection)
Sigma detected: Mshta Spawning Windows Shell
Creates a thread in another existing process (thread injection)
Sigma detected: Suspicious Csc.exe Source File Folder
Writes registry values via WMI
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Queries the installation date of Windows
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to call native functions
Found dropped PE file which has not been started or loaded
Contains long sleeps (>= 3 min)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
PE file does not import any functions
Sample file is different than original file name gathered from version info
PE file contains an invalid checksum
Searches for the Microsoft Outlook file path
Drops PE files
Uses a known web browser user agent for HTTP communication
Compiles C# or VB.Net code
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: Ursnif |
---|
{"lang_id": "RU, CN", "RSA Public Key": "TQcvS5IrBIzT3+zGJZ6/B2cbmD8QQfXWsXQyoKLnldUl+fxloKcyGDdinb2QDD2PXD9XpRc5HbwrNqmPhmWJ0e/UBRwWUbictoSBMJ4aPIlTym7tmGSfnad7IPv5Srn06Y3XBZuYQ1Xys1ZxJwHplzKU0w90/qyyPVRqKOq/MLuCVIMXJCRzYsm45jCi3wlMV3wGL62NM3woVBhffjDDamQ53wj1axbnrsRRrHGvT3qf401ulwz8Ta2wR4uBYmHqgQhJz/9sbeghYJb5FWrjfTJDZcpuOb/2rXGCjZzLO89NTeNJJsLx8uenN3zhb+nnl/3yl1tkz3umoGAvkIUnqQXKMRLBu54y8WHgbT1gdAw=", "c2_domain": ["init.icecreambob.com", "app.updatebrouser.com", "fun.lakeofgold.com"], "botnet": "3500", "server": "580", "serpent_key": "34V2LBzJE8iG98YR", "sleep_time": "5", "CONF_TIMEOUT": "20", "SetWaitableTimer_value": "1"}
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Ursnif | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_2 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif | Yara detected Ursnif | Joe Security | ||
Click to see the 55 entries |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_2 | Yara detected Ursnif | Joe Security | ||
Click to see the 16 entries |
Sigma Overview |
---|
System Summary: |
---|
Sigma detected: Encoded IEX | Show sources |
Source: | Author: Florian Roth: |
Sigma detected: MSHTA Spawning Windows Shell | Show sources |
Source: | Author: Michael Haag: |
Sigma detected: Mshta Spawning Windows Shell | Show sources |
Source: | Author: Florian Roth: |
Sigma detected: Suspicious Csc.exe Source File Folder | Show sources |
Source: | Author: Florian Roth: |
Sigma detected: Non Interactive PowerShell | Show sources |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Sigma detected: T1086 PowerShell Execution | Show sources |
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Data Obfuscation: |
---|
Sigma detected: Powershell run code from registry | Show sources |
Source: | Author: Joe Security: |
Jbx Signature Overview |
---|
Click to jump to signature section
Show All Signature Results
AV Detection: |
---|
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Antivirus detection for URL or domain | Show sources |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Code function: | 0_2_00F33FAB | |
Source: | Code function: | 3_2_032E3FAB |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Networking: |
---|
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) | Show sources |
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
System process connects to network (likely due to code injection or exploit) | Show sources |
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior |
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
E-Banking Fraud: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_00F33FAB | |
Source: | Code function: | 3_2_032E3FAB |
System Summary: |
---|
Writes or reads registry keys via WMI | Show sources |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Writes registry values via WMI | Show sources |
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00F32654 | |
Source: | Code function: | 0_2_00F37E30 | |
Source: | Code function: | 0_2_00F34FA7 | |
Source: | Code function: | 3_2_032E4FA7 | |
Source: | Code function: | 3_2_032E7E30 | |
Source: | Code function: | 3_2_032E2654 | |
Source: | Code function: | 6_2_031B4FA7 | |
Source: | Code function: | 6_2_031B7E30 | |
Source: | Code function: | 6_2_031B2654 | |
Source: | Code function: | 31_2_00A0F2F0 | |
Source: | Code function: | 31_2_00A0B530 | |
Source: | Code function: | 31_2_00A040B4 | |
Source: | Code function: | 31_2_00A1508C | |
Source: | Code function: | 31_2_00A1E0CF | |
Source: | Code function: | 31_2_00A07834 | |
Source: | Code function: | 31_2_009FE008 | |
Source: | Code function: | 31_2_009F3804 | |
Source: | Code function: | 31_2_00A03074 | |
Source: | Code function: | 31_2_00A1C874 | |
Source: | Code function: | 31_2_009F9074 | |
Source: | Code function: | 31_2_00A159A8 | |
Source: | Code function: | 31_2_00A0D9AC | |
Source: | Code function: | 31_2_00A14988 | |
Source: | Code function: | 31_2_009FB1D8 | |
Source: | Code function: | 31_2_00A0C9F0 | |
Source: | Code function: | 31_2_00A0C1D4 | |
Source: | Code function: | 31_2_00A0D150 | |
Source: | Code function: | 31_2_00A132EC | |
Source: | Code function: | 31_2_00A1D2DC | |
Source: | Code function: | 31_2_00A08218 | |
Source: | Code function: | 31_2_00A09268 | |
Source: | Code function: | 31_2_00A1AA6C | |
Source: | Code function: | 31_2_00A07278 | |
Source: | Code function: | 31_2_009F6A68 | |
Source: | Code function: | 31_2_00A1EB10 | |
Source: | Code function: | 31_2_00A06B1C | |
Source: | Code function: | 31_2_009F2B74 | |
Source: | Code function: | 31_2_00A164F4 | |
Source: | Code function: | 31_2_00A03C24 | |
Source: | Code function: | 31_2_00A00474 | |
Source: | Code function: | 31_2_00A0ED94 | |
Source: | Code function: | 31_2_00A1DD9C | |
Source: | Code function: | 31_2_00A08DF4 | |
Source: | Code function: | 31_2_00A085CC | |
Source: | Code function: | 31_2_00A19524 | |
Source: | Code function: | 31_2_00A0FD6C | |
Source: | Code function: | 31_2_00A07D44 | |
Source: | Code function: | 31_2_009FC6F4 | |
Source: | Code function: | 31_2_00A16E34 | |
Source: | Code function: | 31_2_009F8628 | |
Source: | Code function: | 31_2_009F779C | |
Source: | Code function: | 31_2_00A0DFB8 | |
Source: | Code function: | 31_2_00A0179C | |
Source: | Code function: | 31_2_00A13F08 | |
Source: | Code function: | 31_2_00A09770 |
Source: | Code function: | 0_2_00F322EC | |
Source: | Code function: | 0_2_00F33C64 | |
Source: | Code function: | 0_2_00F337E0 | |
Source: | Code function: | 0_2_00F38055 | |
Source: | Code function: | 3_2_032E37E0 | |
Source: | Code function: | 3_2_032E3C64 | |
Source: | Code function: | 3_2_032E22EC | |
Source: | Code function: | 3_2_032E8055 | |
Source: | Code function: | 6_2_031B22EC | |
Source: | Code function: | 6_2_031B8055 | |
Source: | Code function: | 31_2_00A0FAA8 | |
Source: | Code function: | 31_2_009F1A58 | |
Source: | Code function: | 31_2_009F2B08 | |
Source: | Code function: | 31_2_00A2F00B |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Key value queried: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Code function: | 0_2_00F311B8 |
Source: | Process created: |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Data Obfuscation: |
---|
Suspicious powershell command line found | Show sources |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: |
Source: | Code function: | 0_2_00F37AB9 | |
Source: | Code function: | 0_2_00F37E2F | |
Source: | Code function: | 3_2_032E7E2F | |
Source: | Code function: | 3_2_032E7AB9 | |
Source: | Code function: | 6_2_031B7E2F | |
Source: | Code function: | 6_2_031B7AB9 | |
Source: | Code function: | 31_2_00A0B1BA |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Self deletion via cmd delete | Show sources |
Source: | Process created: | ||
Source: | Process created: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep time: |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | |||
Source: | Window / User API: |
Source: | Process information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
HIPS / PFW / Operating System Protection Evasion: |
---|
System process connects to network (likely due to code injection or exploit) | Show sources |
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior |
Maps a DLL or memory area into another process | Show sources |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Writes to foreign memory regions | Show sources |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Allocates memory in foreign processes | Show sources |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Injects code into the Windows Explorer (explorer.exe) | Show sources |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Modifies the context of a thread in another process (thread injection) | Show sources |
Source: | Thread register set: | Jump to behavior | ||
Source: | Thread register set: | Jump to behavior |
Creates a thread in another existing process (thread injection) | Show sources |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | |||
Source: | Thread created: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 0_2_00F32E33 |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 0_2_00F36632 |
Source: | Code function: | 0_2_00F36F10 |
Source: | Code function: | 0_2_00F32E33 |
Stealing of Sensitive Information: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation2 | Path Interception | Process Injection712 | Obfuscated Files or Information1 | OS Credential Dumping | System Time Discovery1 | Remote Services | Archive Collected Data11 | Exfiltration Over Other Network Medium | Ingress Tool Transfer1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Data Encrypted for Impact1 |
Default Accounts | Command and Scripting Interpreter1 | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | File Deletion1 | LSASS Memory | Account Discovery1 | Remote Desktop Protocol | Email Collection1 | Exfiltration Over Bluetooth | Encrypted Channel2 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | PowerShell1 | Logon Script (Windows) | Logon Script (Windows) | Masquerading1 | Security Account Manager | File and Directory Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Non-Application Layer Protocol2 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Virtualization/Sandbox Evasion21 | NTDS | System Information Discovery35 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Application Layer Protocol12 | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Process Injection712 | LSA Secrets | Security Software Discovery1 | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | Rundll321 | Cached Domain Credentials | Virtualization/Sandbox Evasion21 | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Compile After Delivery | DCSync | Process Discovery3 | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | Application Window Discovery1 | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue | |
Exploit Public-Facing Application | PowerShell | At (Linux) | At (Linux) | Masquerading | /etc/passwd and /etc/shadow | System Owner/User Discovery1 | Software Deployment Tools | Data Staged | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Web Protocols | Rogue Cellular Base Station | Data Destruction | |
Supply Chain Compromise | AppleScript | At (Windows) | At (Windows) | Invalid Code Signature | Network Sniffing | Remote System Discovery1 | Taint Shared Content | Local Data Staging | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | File Transfer Protocols | Data Encrypted for Impact |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
4% | Virustotal | Browse | ||
0% | ReversingLabs |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | HEUR/AGEN.1108168 | Download File | ||
100% | Avira | HEUR/AGEN.1108168 | Download File | ||
100% | Avira | HEUR/AGEN.1108168 | Download File |
Domains |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
3% | Virustotal | Browse |
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | URL Reputation | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | URL Reputation | safe |
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
init.icecreambob.com | 194.147.86.221 | true | true |
| unknown |
Contacted URLs |
---|
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| low | ||
false |
| unknown | ||
false |
| unknown |
Contacted IPs |
---|
General Information |
---|
Joe Sandbox Version: | 33.0.0 White Diamond |
Analysis ID: | 498331 |
Start date: | 06.10.2021 |
Start time: | 23:35:08 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 12m 30s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | 2u2mgtylJy.dll |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 42 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.troj.evad.winDLL@42/36@6/2 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
23:37:09 | API Interceptor | |
23:37:27 | API Interceptor | |
23:37:28 | API Interceptor |
Joe Sandbox View / Context |
---|
IPs |
---|
No context |
---|
Domains |
---|
No context |
---|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
NETRACK-ASRU | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | modified |
Size (bytes): | 11606 |
Entropy (8bit): | 4.883977562702998 |
Encrypted: | false |
SSDEEP: | 192:Axoe5FpOMxoe5Pib4GVsm5emdKVFn3eGOVpN6K3bkkjo5HgkjDt4iWN3yBGHh9sO:6fib4GGVoGIpN6KQkj2Akjh4iUxs14fr |
MD5: | 1F1446CE05A385817C3EF20CBD8B6E6A |
SHA1: | 1E4B1EE5EFCA361C9FB5DC286DD7A99DEA31F33D |
SHA-256: | 2BCEC12B7B67668569124FED0E0CEF2C1505B742F7AE2CF86C8544D07D59F2CE |
SHA-512: | 252AD962C0E8023419D756A11F0DDF2622F71CBC9DAE31DC14D9C400607DF43030E90BCFBF2EE9B89782CC952E8FB2DADD7BDBBA3D31E33DA5A589A76B87C514 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 421 |
Entropy (8bit): | 5.017019370437066 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJzLHMRSRa+eNMjSSRrLypSRHq1oZ6laAkKFM+Qy:V/DTLDfuxLP9eg5rLy4uMaLXjQy |
MD5: | 7504862525C83E379C573A3C2BB810C6 |
SHA1: | 3C7E3F89955F07E061B21107DAEF415E0D0C5F5E |
SHA-256: | B81B8E100611DBCEC282117135F47C781087BD95A01DC5496CAC6BE334A8B0CC |
SHA-512: | BC8C4EAD30E12FB619762441B9E84A4E7DF15D23782F80284378129F95FAD5A133D10C975795EEC6DA2564EC4D7F75430C45CA7113A8BFF2D1AFEE0331F13E76 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 351 |
Entropy (8bit): | 5.2890926348275284 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2WXp+N23f+RTzxs7+AEszIWXp+N23f+ROn:p37Lvkmb6KHmTWZE8mOn |
MD5: | 8FC90C4D6A2706126C41F727D11FBD52 |
SHA1: | D1EBD58F91659A26B5C69D14B97B2A3E6AD27728 |
SHA-256: | 8C83ED2AAED6EC932ADF13463895D45BB446BB27209F70D9F46FBFA611C6AD62 |
SHA-512: | AE46B4D3B92C3E87315905FA899F70D54698E384FF76169889FB2CA6A1EE2FD20CE230D0AF66BAA926A6E5E13F89E27C1F2C4BCDBE2D131D5AC71730831E1021 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.651581357643275 |
Encrypted: | false |
SSDEEP: | 24:etGSMtWMOWEey8MTz7X8daP0eWQOAnDdWSWtJ0DtkZfX4BHi7XI+ycuZhNkZakSv:6EA7KMTcd6qhAxWPVJX4W1ulkZa3Hyq |
MD5: | 9E16190C660AF44884D3A20D2DB521DE |
SHA1: | 0E6DF2A913AEDB9EF9D2EFFC9FB54413203A8684 |
SHA-256: | E813E9373EFA3BB329CBC9059D2CA97EF0D8CC569302A3D9E50B3282EDC9482A |
SHA-512: | 4B6F765E9A664BCF5934D63A038982B29D041E3CDA816838C011FD64873EE3B267AD36132DB0AD9F854F473FF85D90DDCFE4F07850CDA8C9EB258FA3CF001D0C |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.1193526271992367 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryyEGak7YnqqHEXPN5Dlq5J:+RI+ycuZhNkZakSHuPNnqX |
MD5: | F2111C8D788B0504CE3B5E69BE25A5BC |
SHA1: | A16335D62AAF2464B65F812D13BF0C7E18CAD0C1 |
SHA-256: | F11D639ADECA16987F821BD3BD77C2595FCB402743062ABADAB4A653D3F766DC |
SHA-512: | 478F3405818545AEFA6EB6E2EA797A722AABF2E119706CDCD246FA47D5F2E9DE4D2862864D39110799CA2FC3387162E1EA3D3AD164DF61AEAE2A8C5B838979D1 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.1087309196116686 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gry+Ikaak7YnqqVIkrPN5Dlq5J:+RI+ycuZhNhakS/PNnqX |
MD5: | E8996C2370A7943B2766C61E76F371D2 |
SHA1: | 7B31CFB3EE2759BB5A9893ECC270F273A3F08342 |
SHA-256: | 1512CDBDE6487FB0B82F7DA0AAE5B4C7F96D7A1EA74B23BF8C258995A8B7AD07 |
SHA-512: | 4A98F53B84785E08B4DBB4B456488E3F814D8559AB22B22EB1A19D405E81CA3D0EDCF80855A4AC6B660D21FEAA076F81AC617C7343885C3A9453E5AE87986267 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.1114363318957032 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryAdak7YnqqRyPN5Dlq5J:+RI+ycuZhNYakS0PNnqX |
MD5: | 502B95C27F132CCC3583302C5A7FBE6E |
SHA1: | 4A8604EEB4EFA898CE9DB57DD01025E2CCDEFA56 |
SHA-256: | 78DD28902BDBAD19E59A84C9DAEBDB3DED2C20C1CACA228B278E635381B5ABFF |
SHA-512: | B1D7E25E9195CCD9F9CF6C593C53A6E5E5FA471869C02389A6A155BC70B7665F931CDF1398FB1B40C19667CD7C63015A82980B37D7D23CD7B491D69FC3E58C6B |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.0883071319418574 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryvak7YnqqrPN5Dlq5J:+RI+ycuZhNNakSrPNnqX |
MD5: | 40C51362AF24E4CE30B71B7DA330BC4B |
SHA1: | 3C033941EE43D535466FB0C0A61E28B43749FFD2 |
SHA-256: | AF8EA12FDFC377C9F388AA66ABD1BDF818BD6FD0B1C47FC04E1A489B6AFD5A44 |
SHA-512: | 8AA52B715242A2B6804E357255EC168627BAC1A64D306CFEA53DAD349134B84D4322E97B9725433EEA7328ADBC96CAE53582B62360A7B0566367C84AEBA6177F |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2176 |
Entropy (8bit): | 2.694088221698292 |
Encrypted: | false |
SSDEEP: | 24:43ghHMhKdNNI+ycuZhNkZakSHuPNnq9hgpMnW9s:438+Kd31ulkZa3Hyq9d5 |
MD5: | 0D84ED11E06D16A9FA6D14C7A43EF89B |
SHA1: | E643775F1544E920E205364C56B986A7F9790DC5 |
SHA-256: | C5E33912ABDA72A82A04606DE28C60F5E03509F56CB933FE8E585EADBC19BB32 |
SHA-512: | B663B0697FABA0640EBBF228ED197512F2F145AD8D49DE7F31666E995BF96ADE7F911EF55EA465D04F1B24131D0C7C30D36551B7DB1EE157F66CA121C740FFFE |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2176 |
Entropy (8bit): | 2.680138845786254 |
Encrypted: | false |
SSDEEP: | 24:43lnttHduhKdNfI+ycuZhNNakSrPNnq9hgpInW9s:43lntt9EKd91ulNa3Bq9h5 |
MD5: | 42A2426827D0BF1745B4C01234190489 |
SHA1: | 37AEF007832FD83B189AD96B474CE4A3280BFE53 |
SHA-256: | BDE70F2FC46C01A2A77CAFD981992B7AB92A540B1F3D09B67552091C0D4EA59B |
SHA-512: | 03C33E64F028DF50F47021773A1272F8EF7F0F5B3B124B3326CF5DF79D33FB7CF73F051798F9B108297BD0CF9C7190A19746E18A9098984D3ABFF4F5E50203C9 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2176 |
Entropy (8bit): | 2.6888266288241707 |
Encrypted: | false |
SSDEEP: | 24:jQT9dhHJhKdNNI+ycuZhNYakS0PNnq9hgpBnW9s:jQTV3Kd31ulYa3Uq9C5 |
MD5: | DF4B62F1B2EAD15713A93DC23C3D7372 |
SHA1: | 82F39E14EF88C5ADB0CE31A6B6DD80FAC34B3C50 |
SHA-256: | 31458A39DA23AAF12D404A5E2BF84907C28E148EC7C67157D20614AFE8233A02 |
SHA-512: | 99B3CA704559A73F0E22DE9A8464286BAAE2B3DF19EC9665BFBE091717009CF03834DC4647F1EF86D6D555F15BEA3DBBD0C634DDDF0009D6C4F30A1AA531C9BC |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2176 |
Entropy (8bit): | 2.6899833131564934 |
Encrypted: | false |
SSDEEP: | 24:jUKhHBWhKdNNI+ycuZhNhakS/PNnq9hgpXnW9s:jUO+Kd31ulha3dq9Y5 |
MD5: | 2B4D5AEAABCD2ADD027E20E22DC5CA4D |
SHA1: | 3D804773EA152BAEEC4C2281B2640D0F19AC90AB |
SHA-256: | 788D5F9136552BD8DAC9B09700B44584BED8B91040465AB983D65007FD4E592C |
SHA-512: | F6EBB8B14FB8D901CAA55ABC53B16978B79699FE3AB1545D94BA3F810A2C2D7718E49B35EA1D7283E14B31CC5CC593C524C4F87705CCF88D05EE0684085AB2EE |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 398 |
Entropy (8bit): | 4.993655904789625 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJWLPMRSR7a1MIq+ZXIO1SRa+rVSSRnA/fHJGF0y:V/DTLDfu0LnQs9rV5nA/Ra0y |
MD5: | C08AF9BD048D4864677C506B609F368E |
SHA1: | 23B8F42A01326DC612E4205B08115A4B68677045 |
SHA-256: | EA46497ADAE53B5568188564F92E763040A350603555D9AA5AE9A371192D7AE7 |
SHA-512: | 9688FD347C664335C40C98A3F0F8D8AF75ABA212A75908A96168D3AEBFC2FEAAB25DD62B63233EB70066DD7F8FB297F422871153901142DB6ECD83D1D345E3C2 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 351 |
Entropy (8bit): | 5.296454290518873 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2WXp+N23fLdB0zxs7+AEszIWXp+N23fLdbn:p37Lvkmb6KH0WZE8x |
MD5: | 287BB516C2BCFDD37D7E4BFB66661711 |
SHA1: | EEB51BA616F3E34C49E47E926856BBAA38426229 |
SHA-256: | EC0F04B7B44B20570934588B7B0528D2CF8D0F3CE7663B260B0428C9A4130903 |
SHA-512: | 297FA7748ED474E569B58117DAF74964D39B229DE44B8D9FAB4730093F41FBC87BA989E1C1C68F1564CA761ECC7915D65EF52E7D7D73F6D34713B4FA11513121 |
Malicious: | true |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.6006009045126377 |
Encrypted: | false |
SSDEEP: | 24:etGSFW/u2Dg85lxlok3JgpiY4MatkZfU0aUI+ycuZhNYakS0PNnq:6FDWb5lxF1AJUM1ulYa3Uq |
MD5: | 58BDEE2E4D27C32158790C1954FB8FD3 |
SHA1: | 3CB023B1BCC4AC2481144C415E774C75DAA86DEF |
SHA-256: | 3CDC28CC0455851012BA00A4B4EFC085667FB3F155E10F9413F47727F74D028A |
SHA-512: | 7916722AD1919B58175B1FA1E2123914FCF44F2AADF5AFC5149A6A504FA88D9A0C6B284A608615D8A261ADDA2FF330DB8B9F1E4F36E2540834D80BDC1F79D92A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 421 |
Entropy (8bit): | 5.017019370437066 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJzLHMRSRa+eNMjSSRrLypSRHq1oZ6laAkKFM+Qy:V/DTLDfuxLP9eg5rLy4uMaLXjQy |
MD5: | 7504862525C83E379C573A3C2BB810C6 |
SHA1: | 3C7E3F89955F07E061B21107DAEF415E0D0C5F5E |
SHA-256: | B81B8E100611DBCEC282117135F47C781087BD95A01DC5496CAC6BE334A8B0CC |
SHA-512: | BC8C4EAD30E12FB619762441B9E84A4E7DF15D23782F80284378129F95FAD5A133D10C975795EEC6DA2564EC4D7F75430C45CA7113A8BFF2D1AFEE0331F13E76 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 351 |
Entropy (8bit): | 5.276060635109324 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2WXp+N23fJc+zxs7+AEszIWXp+N23fJG:p37Lvkmb6KHBrWZE8BG |
MD5: | 5491255ADA6DF7A9D435D2F1DC186E31 |
SHA1: | A7400C7A02A55D6BF31A89AFA6F2295263938A17 |
SHA-256: | CFA49F131C2079FEE4E347E580BAE5F182DDF88AC995C1FEE324F6C9C3E25D13 |
SHA-512: | DE62B8491CA07D26F25AEA42EA3D98FF274D2F06E2AD46D023651184338F19AC9B8B45813E49DF7C46E87B9411BB2512FB778B97113155AFFAA55839D4844F7D |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.641419442648237 |
Encrypted: | false |
SSDEEP: | 24:etGSeWMOWEey8MTz7X8daP0eWQzQDdWSWtJ0DtkZfxH1BxO7XI+ycuZhNhakS/PE:6eA7KMTcd6qPWPVJbw1ulha3dq |
MD5: | F81B50C2AEED90D46EDACA3CD171E8AF |
SHA1: | 45069DB458E4751EA1F0B8D1C0983BDE5A3138EB |
SHA-256: | D19ADA0CED6CFF9A121DDB0601039A20B278AC929EB63C1B3822716A9D0E1E7F |
SHA-512: | C0E9BFAE309F1B8AF23660DDE2F3D5367DF159AE4A75E07F8984D733D95E52EA9B1C7A40A428EF3150329D2D6A1F240A906A1857EA95B8D9A9FF18743138287C |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 398 |
Entropy (8bit): | 4.993655904789625 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJWLPMRSR7a1MIq+ZXIO1SRa+rVSSRnA/fHJGF0y:V/DTLDfu0LnQs9rV5nA/Ra0y |
MD5: | C08AF9BD048D4864677C506B609F368E |
SHA1: | 23B8F42A01326DC612E4205B08115A4B68677045 |
SHA-256: | EA46497ADAE53B5568188564F92E763040A350603555D9AA5AE9A371192D7AE7 |
SHA-512: | 9688FD347C664335C40C98A3F0F8D8AF75ABA212A75908A96168D3AEBFC2FEAAB25DD62B63233EB70066DD7F8FB297F422871153901142DB6ECD83D1D345E3C2 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 351 |
Entropy (8bit): | 5.2430343624692 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2WXp+N23fXZWH0zxs7+AEszIWXp+N23fXZiH:p37Lvkmb6KHUUWZE8wH |
MD5: | 76CA224A1B576103C736A1A4F35D0E6A |
SHA1: | 8F587DE2EFC63C827D81E8E69EDDA20FF299D6DD |
SHA-256: | 49C432F1AE482DCF36F38E47A77B185BB245C741267A09DF161728CB7763A957 |
SHA-512: | 3938710A7B82D82F932D8D2767F67DBEE8A673D77FF81EE25A6DAEA8B98DEFFC3008BB626D52226AB8520809E077FF9DF6672B42579B53F7DBE361C53135E22D |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.5930122712204606 |
Encrypted: | false |
SSDEEP: | 24:etGSIW/u2Dg85lxlok3JgpiY84MatkZf1UaUI+ycuZhNNakSrPNnq:6IDWb5lxF1YUJ1s1ulNa3Bq |
MD5: | D1FE2A39BB21C65A15FD34094F05CEC4 |
SHA1: | 1A86A58A74256F54FCC0999EA86094CDCB0216B7 |
SHA-256: | D96DC8D0083A0BA18DFFEE0787FAE78474FE633E64B384AAED41A4E94157E063 |
SHA-512: | 76CA975896CE0A3BC5022066B0B1C2217DC3BC99E6756E369E179C6CE0F8E6081764CCAF81BB16767589A898D2391094E142C0F13E9A14D6CA120677D47F92D2 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 976 |
Entropy (8bit): | 5.489287202485614 |
Encrypted: | false |
SSDEEP: | 24:BxSA5ixvBn7v+x2DOXUWOLCHGIYBtBCW3HjeTKKjX4CIym1ZJX+OLCHGIYBtBW:BZ5evhKoORFeV3qDYB1ZwFeW |
MD5: | BE3E0A05CBB97B5E3C63E289F73A6E51 |
SHA1: | 71D754F2D1E30013F7A32900EB7306CBD5054B8F |
SHA-256: | 1ADA2D50B3E794CF15184DEE6749EB3431DBF2D2040668192EB38A0236BFC007 |
SHA-512: | 91D2C6AC446ACD3AAD10FF393A0385357CCADB039E79DB48AE0DDF83343077AC29006A03490CB472E5FD8ADC49DD9BBEC8558D9BC7270924D476576F988B1C24 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 976 |
Entropy (8bit): | 5.487691637776839 |
Encrypted: | false |
SSDEEP: | 24:BxSA1xvBn7v+x2DOXUWOLCHGIYBtBCWeHjeTKKjX4CIym1ZJXHOLCHGIYBtBW:BZHvhKoORFeVeqDYB1ZzFeW |
MD5: | 944BB1CE69757AE8D60452103E6F4D0E |
SHA1: | 95E8BC125371DCE5D88EEC28456CCF53F5025561 |
SHA-256: | A5A74BD8F1557CECFAF4C97B182C5FACAD17666A71AB75C4B65AEB86F8C92473 |
SHA-512: | B475358D3995AB5D15F78B3C2C82C630E8FF14FE55E5D8587B1176E44F3A768A0CBFFE6D235645BD088EC7CF818D6265C8B91AC857E82112F96BBBCC65728330 |
Malicious: | false |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.647087156964417 |
TrID: |
|
File name: | 2u2mgtylJy.dll |
File size: | 453130 |
MD5: | 503edcfec2262373e36deaa37f640332 |
SHA1: | 37648e8ced69d8adc7be8bde5a61138cbb0f9e6a |
SHA256: | 3ef3beaa49e07f171927a772a417109df6f137c4fa321dbd17daaa7cb47392be |
SHA512: | 95a7f1d087d66e5ac627605c1dd91dca3a282fd8c8c2ad3fafa222ce0600032e417617cc2cfa6a6c2b383f6f737db9c96835f074527e84fbd3515f2990b3d8ca |
SSDEEP: | 12288:kHlAiJHCwjXvMHk37t4Mv//IfN/YoyL8ozF0nxatQB:kHltJHCkvH/IJvUWxata |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............g...g...g....l..g..K.8..g...9...g...9...g....0..g...9...g....4..g...g...f...9...g...9..(g...9...g...9...g...9...g..Rich.g. |
File Icon |
---|
Icon Hash: | 74f0e4ecccdce0e4 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x10007197 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x10000000 |
Subsystem: | windows gui |
Image File Characteristics: | 32BIT_MACHINE, EXECUTABLE_IMAGE, DLL |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x57EEB746 [Fri Sep 30 19:04:38 2016 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 3a94ffcdb86144f7d0b6d92dd3393d93 |
Entrypoint Preview |
---|
Instruction |
---|
push ebp |
mov ebp, esp |
cmp dword ptr [ebp+0Ch], 01h |
jne 00007F698080ECA7h |
call 00007F698080F43Bh |
push dword ptr [ebp+10h] |
push dword ptr [ebp+0Ch] |
push dword ptr [ebp+08h] |
call 00007F698080EB5Ah |
add esp, 0Ch |
pop ebp |
retn 000Ch |
push ebp |
mov ebp, esp |
push 00000000h |
call dword ptr [1004F06Ch] |
push dword ptr [ebp+08h] |
call dword ptr [1004F068h] |
push C0000409h |
call dword ptr [1004F060h] |
push eax |
call dword ptr [1004F070h] |
pop ebp |
ret |
push ebp |
mov ebp, esp |
sub esp, 00000324h |
push 00000017h |
call 00007F6980842C5Fh |
test eax, eax |
je 00007F698080ECA7h |
push 00000002h |
pop ecx |
int 29h |
mov dword ptr [1006CD98h], eax |
mov dword ptr [1006CD94h], ecx |
mov dword ptr [1006CD90h], edx |
mov dword ptr [1006CD8Ch], ebx |
mov dword ptr [1006CD88h], esi |
mov dword ptr [1006CD84h], edi |
mov word ptr [1006CDB0h], ss |
mov word ptr [1006CDA4h], cs |
mov word ptr [1006CD80h], ds |
mov word ptr [1006CD7Ch], es |
mov word ptr [1006CD78h], fs |
mov word ptr [1006CD74h], gs |
pushfd |
pop dword ptr [1006CDA8h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [1006CD9Ch], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [1006CDA0h], eax |
Rich Headers |
---|
Programming Language: |
|
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x6ae90 | 0xb0 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x6af40 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x109000 | 0x440 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x10a000 | 0x2cbc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x69140 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x69198 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x4f000 | 0x19c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4d48c | 0x4d600 | False | 0.541116594305 | data | 6.75100933622 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rdata | 0x4f000 | 0x1c8ec | 0x1ca00 | False | 0.58397584607 | data | 5.72385266985 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x6c000 | 0x9b7e8 | 0xe00 | False | 0.204520089286 | data | 2.89792338491 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.gfids | 0x108000 | 0x228 | 0x400 | False | 0.2529296875 | data | 1.74193986935 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x109000 | 0x440 | 0x600 | False | 0.292317708333 | data | 2.5339353314 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x10a000 | 0x2cbc | 0x2e00 | False | 0.777513586957 | data | 6.63564333671 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_VERSION | 0x109060 | 0x3dc | data | English | United States |
Imports |
---|
DLL | Import |
---|---|
KERNEL32.dll | TlsAlloc, LoadLibraryW, VirtualProtectEx, GetModuleHandleW, CreateSemaphoreW, GetTempPathW, WriteConsoleW, CloseHandle, CreateFileW, OutputDebugStringW, ReadConsoleW, GetEnvironmentVariableW, InitializeCriticalSection, GetModuleFileNameW, RemoveDirectoryW, DeviceIoControl, GetCurrentProcess, EnterCriticalSection, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, EncodePointer, RaiseException, InterlockedPushEntrySList, InterlockedFlushSList, GetLastError, SetLastError, RtlUnwind, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, ExitProcess, GetModuleHandleExW, HeapFree, HeapAlloc, GetCurrentThread, GetDateFormatW, GetTimeFormatW, CompareStringW, LCMapStringW, GetLocaleInfoW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, GetTimeZoneInformation, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, GetProcessHeap, GetStdHandle, GetFileType, SetConsoleCtrlHandler, GetStringTypeW, HeapSize, HeapReAlloc, SetStdHandle, FlushFileBuffers, WriteFile, GetConsoleCP, GetConsoleMode, GetFileSizeEx, SetFilePointerEx, ReadFile, DecodePointer |
ole32.dll | CoUninitialize, CoTaskMemAlloc, CoInitialize, CoTaskMemFree |
CRYPTUI.dll | CryptUIDlgViewContext, CryptUIDlgViewCertificateW, CryptUIWizDigitalSign, CryptUIWizFreeDigitalSignContext, CryptUIWizImport, CryptUIWizExport, CryptUIDlgSelectCertificateFromStore |
Exports |
---|
Name | Ordinal | Address |
---|---|---|
Bonebegin | 1 | 0x1003f370 |
Father | 2 | 0x1003f4d0 |
Ratherdesign | 3 | 0x1003f680 |
Scorematch | 4 | 0x1003f6f0 |
Silverwere | 5 | 0x1003f6d0 |
StoneNumeral | 6 | 0x1003f7e0 |
Version Infos |
---|
Description | Data |
---|---|
LegalCopyright | Fig Governhear suggest Corporation. All rights reserved |
InternalName | Ropemother Smellclean |
FileVersion | 5.6.0.165 |
CompanyName | Fig Governhear suggest Corporation Alsoheld |
ProductName | Fig Governhear suggest Shoecould Quietfrom |
ProductVersion | 5.6.0.165 |
FileDescription | Fig Governhear suggest Shoecould Quietfrom |
OriginalFilename | Soon.dll |
Translation | 0x0409 0x04b0 |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
Snort IDS Alerts |
---|
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
10/06/21-23:37:16.298952 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:16.298952 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:17.579708 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:19.683931 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49762 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:26.468012 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:26.468012 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:27.934050 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:27.934050 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
10/06/21-23:37:30.444689 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49765 | 80 | 192.168.2.3 | 194.147.86.221 |
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 6, 2021 23:37:16.249272108 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.298382998 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.298571110 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.298952103 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.393974066 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812170029 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812239885 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812288046 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812330008 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812367916 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812392950 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.812397957 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812448025 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812490940 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812508106 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.812526941 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812530041 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.812563896 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.812566996 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.812675953 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.861551046 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861622095 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861677885 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861725092 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.861731052 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861769915 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861808062 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861854076 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861870050 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.861907005 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.861913919 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861958027 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.861994028 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862005949 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.862030983 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862071037 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862090111 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.862108946 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862147093 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862180948 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.862184048 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862231970 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862276077 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862294912 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.862313032 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862348080 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.862350941 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862389088 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.862392902 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.862461090 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.911348104 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.911401987 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.911442995 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.911583900 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.912559986 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912604094 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912641048 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912686110 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.912689924 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912719965 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.912734032 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912772894 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912811995 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912849903 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912889004 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912919044 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912956953 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912974119 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.912991047 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.912992954 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913002968 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913029909 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913049936 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913067102 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913106918 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913124084 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913144112 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913188934 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913192034 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913233995 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913270950 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913274050 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913309097 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913346052 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913393021 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913395882 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913430929 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913441896 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913469076 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913506031 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913513899 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913542986 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913579941 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913619995 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913625956 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913669109 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913676023 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913705111 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913743019 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913769007 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913779974 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913816929 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913836956 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913855076 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913892984 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913899899 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.913939953 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.913981915 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.914021015 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.914077997 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.960414886 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.960459948 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.960496902 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.960530996 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.960555077 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.960565090 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.960583925 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.960587978 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.960624933 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963032961 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963084936 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963123083 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963139057 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963156939 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963196039 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963226080 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963236094 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963258028 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963273048 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963310003 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963331938 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963346958 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963359118 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963377953 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963406086 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963406086 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963448048 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963485003 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963505030 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963531971 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963537931 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963573933 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963609934 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963622093 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963649035 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963653088 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963686943 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963706970 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963722944 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963741064 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963761091 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963782072 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963799000 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963809967 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963845968 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963860035 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963887930 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963907957 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963924885 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963943005 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.963963032 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.963973999 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964000940 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964018106 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964036942 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964073896 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964097977 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964109898 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964118958 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964124918 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964158058 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964162111 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964199066 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964215994 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964236021 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964261055 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964273930 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964293003 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964312077 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964334011 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964349031 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964365959 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964386940 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964401007 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964427948 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:16.964443922 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:16.964485884 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.009552956 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.009619951 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.009673119 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.009708881 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.009727001 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.009783030 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.009982109 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.010008097 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.016921997 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.017015934 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.017059088 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.017220974 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.017266035 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.017451048 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.058505058 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.058680058 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.058737993 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.058743000 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.058779001 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.058805943 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.058871984 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.058921099 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.058928013 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.058969975 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059046984 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059067011 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059103966 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059163094 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059175968 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059190989 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059233904 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059257984 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059287071 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059322119 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059334993 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059376001 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059385061 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059437037 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059441090 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059489965 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059495926 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059539080 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059580088 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059592962 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059624910 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059649944 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059700966 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059710026 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059750080 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059791088 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059798956 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059835911 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059868097 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059883118 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059907913 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.059952974 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.059957981 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.060024977 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.060070992 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.111337900 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.111468077 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.111506939 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.111546040 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.111584902 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.111596107 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.111660004 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.111677885 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.111691952 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.111864090 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.160629034 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.160842896 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.161163092 CEST | 49759 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.210030079 CEST | 80 | 49759 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.529506922 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.578692913 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:17.578984976 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.579708099 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:17.669866085 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.058892965 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.058944941 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.058983088 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.058990002 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.059022903 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.059062958 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.059088945 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.059099913 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.059150934 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.059161901 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.059201002 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.059236050 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.059257030 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.059283972 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.059328079 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126216888 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126329899 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126384020 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126384974 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126421928 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126461983 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126463890 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126499891 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126538038 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126543999 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126575947 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126590014 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126615047 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126629114 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126657963 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126662970 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126705885 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126710892 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126744986 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126748085 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126782894 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126794100 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126821995 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126832008 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126857996 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.126885891 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.126912117 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176029921 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176090956 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176132917 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176124096 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176163912 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176171064 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176184893 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176211119 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176249027 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176250935 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176280022 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176285982 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176310062 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176333904 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.176337004 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176403999 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.176462889 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.219244003 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.225600958 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225630999 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225651026 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225717068 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.225730896 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225775957 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.225784063 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225812912 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225884914 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225900888 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225922108 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.225933075 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.225955963 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.225991964 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.226007938 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.226054907 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.226090908 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.226105928 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.226155043 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.226162910 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.226165056 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.226166010 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.227247953 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.231235027 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.268486023 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.268524885 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.268596888 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.274842024 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.274884939 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.274910927 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.274936914 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.274960995 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.274986029 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275011063 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275033951 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275057077 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275080919 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275103092 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275146961 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275149107 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.275168896 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275190115 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.275218010 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.275247097 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.280239105 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.280267000 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.280343056 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.317579985 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.317611933 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.317663908 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.317704916 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.324971914 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325011969 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325032949 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325050116 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325052977 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.325073957 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325095892 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325119019 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325139999 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325160980 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325166941 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.325182915 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325206041 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325225115 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325247049 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325248957 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.325268030 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.325289011 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.325314999 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.329438925 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.329476118 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.329513073 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.329547882 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.367219925 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.367254019 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.367315054 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.367372990 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.374425888 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.374458075 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.374476910 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.374500036 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.374517918 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.374521971 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.374542952 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.374552965 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.374583960 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.374600887 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.378453016 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.378479958 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.378535986 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.378561974 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.417409897 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.417473078 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.417486906 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.417534113 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.423751116 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.423788071 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.423813105 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.423836946 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.423865080 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.423902035 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.423923969 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.424180031 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.427409887 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.427438974 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.427512884 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.467978001 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.468009949 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.468036890 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.473263025 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.473326921 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.473352909 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.473359108 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.473396063 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.473539114 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.473650932 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.473819971 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.517187119 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.517225027 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.517296076 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.523242950 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.523288965 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.523314953 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.523340940 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.523354053 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.523394108 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.523644924 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.523688078 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.523710012 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.523788929 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.569379091 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.569426060 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.569564104 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.573705912 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.573767900 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.573786974 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.573813915 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.573843956 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.573851109 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.573869944 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.573884964 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.573906898 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.573947906 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.623781919 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.623811960 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.623823881 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.623836994 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.623848915 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.623867035 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.623886108 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.623960972 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.624007940 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.673157930 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673187971 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673209906 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673281908 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673341036 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673363924 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673384905 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673407078 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.673408031 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.673460007 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.673513889 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.722515106 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722702026 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722759962 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722793102 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722814083 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722836018 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722861052 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722862959 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.722882986 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.722927094 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.723018885 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.772646904 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.773659945 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.773684978 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.773703098 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.773721933 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.774029016 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.774055004 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.823216915 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.823261976 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.823287964 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.823308945 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.823333025 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.823381901 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.823803902 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.823914051 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.872401953 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.872437954 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.872462034 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.872469902 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.872505903 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.872514009 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.872554064 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.872916937 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.922353983 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.922385931 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.922410011 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.922415018 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.922437906 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.969391108 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:18.971244097 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.973714113 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.973742962 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:18.973799944 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.018300056 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.018332005 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.018376112 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.018455029 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.022818089 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.022846937 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.022877932 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.022907972 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.073703051 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.073770046 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.073792934 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.073852062 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.074039936 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.123661995 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.123687983 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.123801947 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.123864889 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.123867035 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.124016047 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.181539059 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.181603909 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.181626081 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.181648016 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.181667089 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.181781054 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.181881905 CEST | 49760 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.230628967 CEST | 80 | 49760 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.633964062 CEST | 49762 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.682775974 CEST | 80 | 49762 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:19.683021069 CEST | 49762 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.683931112 CEST | 49762 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:19.777654886 CEST | 80 | 49762 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:20.141684055 CEST | 80 | 49762 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:20.141721964 CEST | 80 | 49762 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:20.141881943 CEST | 49762 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:20.142112970 CEST | 49762 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:20.192210913 CEST | 80 | 49762 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.418103933 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.466969967 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.467097044 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.468012094 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.571445942 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.945975065 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946033001 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946074963 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946115971 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946156979 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946194887 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946194887 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.946233034 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946237087 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.946254015 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.946284056 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946327925 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946366072 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.946367025 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.946430922 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.998142004 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998177052 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998199940 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998219967 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998239994 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998260975 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998275995 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.998284101 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998310089 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998311996 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.998317957 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.998333931 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998353958 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:26.998372078 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:26.998400927 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.060723066 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060755968 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060775042 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060796976 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060813904 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060837030 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060858011 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060882092 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060894966 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.060903072 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060920000 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.060925961 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060950041 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.060966969 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.061029911 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.120858908 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.120913029 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.120949984 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.120996952 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121028900 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.121040106 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121062994 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.121077061 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121117115 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121155977 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121181965 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.121191978 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121229887 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121243954 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.121268034 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.121323109 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.171706915 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.171772003 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.171813965 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.171816111 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.171854019 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.171890020 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.171892881 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.171931028 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.171948910 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.171967030 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.172004938 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.172043085 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.172090054 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.172102928 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.172132015 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.172169924 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.172209024 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.219957113 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.221076012 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221113920 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221149921 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221174002 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221204042 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221229076 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221251965 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221275091 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221298933 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221321106 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221343994 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.221343040 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.221383095 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.221389055 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.221393108 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.266851902 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.269121885 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.270083904 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.270147085 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.270209074 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.270221949 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.270267963 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.270277023 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.270323992 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.270375967 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.270440102 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.271390915 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.271452904 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.271461964 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.271502972 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.271555901 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.271564007 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.271620035 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.271671057 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.315781116 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.319133043 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.319185972 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.319224119 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.319261074 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.319264889 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.319299936 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.319302082 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.319339991 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.319395065 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.321039915 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.321082115 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.321120024 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.321157932 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.321161032 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.321171999 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.321269989 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.321310043 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.321453094 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.373574018 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373615980 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373645067 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373682976 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373716116 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373723984 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.373745918 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373755932 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.373776913 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373811960 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.373828888 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373858929 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373889923 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373919010 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373920918 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.373955965 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.373960018 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.373990059 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.374021053 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.374057055 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.374070883 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.425914049 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.425951004 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.425977945 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426002979 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426035881 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426064968 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426079035 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.426091909 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426119089 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426145077 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426171064 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426175117 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.426198006 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426223993 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426239014 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.426256895 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.426295042 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.426352024 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475228071 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475298882 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475347042 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475388050 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475403070 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475429058 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475460052 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475470066 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475507975 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475507975 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475547075 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475548029 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475586891 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475600958 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475616932 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475635052 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.475639105 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.475852013 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.525316000 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525377035 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525419950 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525459051 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525496006 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525533915 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525573015 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525571108 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.525619984 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525665045 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525691032 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.525702953 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.525754929 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.525806904 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.575007915 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575062037 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575102091 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575191975 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575229883 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575261116 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.575278997 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575295925 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.575321913 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575340033 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.575362921 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575400114 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.575426102 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.575459957 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.575917959 CEST | 49763 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.624968052 CEST | 80 | 49763 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.882507086 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.933276892 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:27.933415890 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:27.934050083 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.025999069 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.396986961 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.397047043 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.397098064 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.397142887 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.397233009 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.397265911 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.400204897 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.400263071 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.400301933 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.400341988 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.400379896 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.400388956 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.400419950 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.400427103 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.400482893 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.447943926 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.448009968 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.448049068 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.448086977 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.448172092 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.448474884 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.449127913 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.449194908 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.449239016 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.449275970 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.449315071 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.449321032 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.449354887 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.449364901 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.449435949 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.496861935 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.496917963 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.496957064 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.496995926 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.497159958 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.497839928 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.497880936 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.497919083 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.497956991 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.497994900 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.498013020 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.498028994 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.498030901 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.498070002 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.498137951 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.546693087 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546724081 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546740055 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546757936 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546770096 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546789885 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546808958 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546827078 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546845913 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546855927 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.546861887 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546878099 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.546895981 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.546901941 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.546906948 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.546935081 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.595818043 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.595880032 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.595922947 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.595959902 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.595980883 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.596007109 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.596034050 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.596051931 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.596088886 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.596118927 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.596127987 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.596165895 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.596204042 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.596242905 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.596246958 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.596322060 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.648123026 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648181915 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648221016 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648258924 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648297071 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648319006 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.648344994 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648355961 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.648363113 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.648367882 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.648387909 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648391008 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.648428917 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648473024 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648483038 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.648513079 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.648561001 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.697149992 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697206974 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697247982 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697263956 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.697287083 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697309017 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.697329998 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.697336912 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697381020 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697396040 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.697419882 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697460890 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.697520971 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.745944023 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.745995045 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.746042013 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.746085882 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.746118069 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.746124029 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.746162891 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.746190071 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.746201992 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.746239901 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.746278048 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.794858932 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.794917107 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.794954062 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.794956923 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.794998884 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.795020103 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.795037985 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.795089006 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.795161963 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.795190096 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.795206070 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.795279980 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.844723940 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.844782114 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.844820023 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.844867945 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.844911098 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.844926119 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.844948053 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.844960928 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.844975948 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.844990015 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.845029116 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.845102072 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.893796921 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.893840075 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.893870115 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.893897057 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.893925905 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.893951893 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.893982887 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.893989086 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.894011974 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.894012928 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.894015074 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.894041061 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.894063950 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.894071102 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.894098997 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.894129992 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.938970089 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.955722094 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.955776930 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.955811024 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.955854893 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.955897093 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.955928087 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.955934048 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.955965042 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.955965996 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.955982924 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.955998898 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.956032038 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.956079960 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:28.956113100 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:28.956175089 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.022552967 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.023189068 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.023221016 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.023298979 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.023302078 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.023335934 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.023339987 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.023348093 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.023485899 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.023500919 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.023520947 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.023578882 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.071930885 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.071959972 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.071976900 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.071993113 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.072012901 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.072031021 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.072062016 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.072103977 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.072109938 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.072114944 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.072119951 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.072124958 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.122941017 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.122984886 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.123012066 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.123039007 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.123065948 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.123094082 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.123152971 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.123213053 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.123264074 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.171797991 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.171855927 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.171895027 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.171933889 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.171941042 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.171972990 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.172004938 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.172013044 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.172029018 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.172044039 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.172080994 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.172107935 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.220166922 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.220664978 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.220750093 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.220817089 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.220824957 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.220890045 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.220951080 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.220983028 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.221009970 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.221066952 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.221071005 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.267096043 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.268778086 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.269349098 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.269372940 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.269392967 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.269409895 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.269428968 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.269445896 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.269507885 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.269524097 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.269526958 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.314069033 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.316162109 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.318068981 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.318118095 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.318156958 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.318196058 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.318233967 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.318239927 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.318269014 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.318281889 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.318398952 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.363302946 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.368329048 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.368354082 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.368370056 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.368422031 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.368429899 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.368473053 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.368490934 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.368518114 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.368577003 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.417777061 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.417804003 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.417818069 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.417835951 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.417850018 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.417860985 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.417917013 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.417964935 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.417973042 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.417977095 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.497390985 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.497436047 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.497479916 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.497509003 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.513231993 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.513330936 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.513350010 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.513387918 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.513447046 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.513487101 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.545928001 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.595170021 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.773627996 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.773716927 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.961678028 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:29.961764097 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:29.962080002 CEST | 49764 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:30.022803068 CEST | 80 | 49764 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:30.395617008 CEST | 49765 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:30.444135904 CEST | 80 | 49765 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:30.444247007 CEST | 49765 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:30.444689035 CEST | 49765 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:30.535753012 CEST | 80 | 49765 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:31.128501892 CEST | 80 | 49765 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:31.128535032 CEST | 80 | 49765 | 194.147.86.221 | 192.168.2.3 |
Oct 6, 2021 23:37:31.128624916 CEST | 49765 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:31.128815889 CEST | 49765 | 80 | 192.168.2.3 | 194.147.86.221 |
Oct 6, 2021 23:37:31.177395105 CEST | 80 | 49765 | 194.147.86.221 | 192.168.2.3 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 6, 2021 23:37:15.940881968 CEST | 56009 | 53 | 192.168.2.3 | 8.8.8.8 |
Oct 6, 2021 23:37:16.233791113 CEST | 53 | 56009 | 8.8.8.8 | 192.168.2.3 |
Oct 6, 2021 23:37:17.216804981 CEST | 59026 | 53 | 192.168.2.3 | 8.8.8.8 |
Oct 6, 2021 23:37:17.524298906 CEST | 53 | 59026 | 8.8.8.8 | 192.168.2.3 |
Oct 6, 2021 23:37:19.335506916 CEST | 60823 | 53 | 192.168.2.3 | 8.8.8.8 |
Oct 6, 2021 23:37:19.630645037 CEST | 53 | 60823 | 8.8.8.8 | 192.168.2.3 |
Oct 6, 2021 23:37:26.108618975 CEST | 52130 | 53 | 192.168.2.3 | 8.8.8.8 |
Oct 6, 2021 23:37:26.409832954 CEST | 53 | 52130 | 8.8.8.8 | 192.168.2.3 |
Oct 6, 2021 23:37:27.863996983 CEST | 55102 | 53 | 192.168.2.3 | 8.8.8.8 |
Oct 6, 2021 23:37:27.880599022 CEST | 53 | 55102 | 8.8.8.8 | 192.168.2.3 |
Oct 6, 2021 23:37:30.098999023 CEST | 56236 | 53 | 192.168.2.3 | 8.8.8.8 |
Oct 6, 2021 23:37:30.393604994 CEST | 53 | 56236 | 8.8.8.8 | 192.168.2.3 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Oct 6, 2021 23:37:15.940881968 CEST | 192.168.2.3 | 8.8.8.8 | 0xa7c1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 6, 2021 23:37:17.216804981 CEST | 192.168.2.3 | 8.8.8.8 | 0x2245 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 6, 2021 23:37:19.335506916 CEST | 192.168.2.3 | 8.8.8.8 | 0x7fe0 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 6, 2021 23:37:26.108618975 CEST | 192.168.2.3 | 8.8.8.8 | 0xb073 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 6, 2021 23:37:27.863996983 CEST | 192.168.2.3 | 8.8.8.8 | 0xf77e | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 6, 2021 23:37:30.098999023 CEST | 192.168.2.3 | 8.8.8.8 | 0x94b4 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Oct 6, 2021 23:37:16.233791113 CEST | 8.8.8.8 | 192.168.2.3 | 0xa7c1 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 6, 2021 23:37:17.524298906 CEST | 8.8.8.8 | 192.168.2.3 | 0x2245 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 6, 2021 23:37:19.630645037 CEST | 8.8.8.8 | 192.168.2.3 | 0x7fe0 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 6, 2021 23:37:26.409832954 CEST | 8.8.8.8 | 192.168.2.3 | 0xb073 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 6, 2021 23:37:27.880599022 CEST | 8.8.8.8 | 192.168.2.3 | 0xf77e | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 6, 2021 23:37:30.393604994 CEST | 8.8.8.8 | 192.168.2.3 | 0x94b4 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) |
HTTP Request Dependency Graph |
---|
|
HTTP Packets |
---|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.3 | 49759 | 194.147.86.221 | 80 | C:\Windows\System32\loaddll32.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Oct 6, 2021 23:37:16.298952103 CEST | 1055 | OUT | |
Oct 6, 2021 23:37:16.812170029 CEST | 1056 | IN |