Play interactive tourEdit tour
Windows Analysis Report data.dll
Overview
General Information
Detection
Ursnif
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Ursnif
System process connects to network (likely due to code injection or exploit)
Antivirus detection for URL or domain
Found malware configuration
Sigma detected: Powershell run code from registry
Multi AV Scanner detection for submitted file
Multi AV Scanner detection for domain / URL
Sigma detected: Encoded IEX
Hooks registry keys query functions (used to hide registry keys)
Maps a DLL or memory area into another process
Compiles code for process injection (via .Net compiler)
Uses nslookup.exe to query domains
Writes or reads registry keys via WMI
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Allocates memory in foreign processes
May check the online IP address of the machine
Sigma detected: MSHTA Spawning Windows Shell
Creates a thread in another existing process (thread injection)
Disables SPDY (HTTP compression, likely to perform web injects)
Modifies the export address table of user mode modules (user mode EAT hooks)
Writes registry values via WMI
Tries to steal Mail credentials (via file access)
Writes to foreign memory regions
Changes memory attributes in foreign processes to executable or writable
Suspicious powershell command line found
Modifies the prolog of user mode functions (user mode inline hooks)
Injects code into the Windows Explorer (explorer.exe)
Modifies the context of a thread in another process (thread injection)
Sigma detected: Mshta Spawning Windows Shell
Sigma detected: Suspicious Csc.exe Source File Folder
Modifies the import address table of user mode modules (user mode IAT hooks)
Contains functionality to query locales information (e.g. system language)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Queries the installation date of Windows
Detected potential crypto function
Contains functionality to launch a process as a different user
Sample execution stops while process was sleeping (likely an evasion)
Contains functionality to dynamically determine API calls
Contains long sleeps (>= 3 min)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Searches for the Microsoft Outlook file path
Drops PE files
Tries to load missing DLLs
Uses a known web browser user agent for HTTP communication
Compiles C# or VB.Net code
Creates a process in suspended mode (likely to inject code)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Rundll32 Activity
Internet Provider seen in connection with other malware
Contains functionality to query CPU information (cpuid)
Contains functionality to call native functions
Found dropped PE file which has not been started or loaded
Enables debug privileges
PE file does not import any functions
Sample file is different than original file name gathered from version info
PE file contains an invalid checksum
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Uses Microsoft's Enhanced Cryptographic Provider
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: Ursnif |
---|
{"lang_id": "RU, CN", "RSA Public Key": "TQcvS5IrBIzT3+zGJZ6/B2cbmD8QQfXWsXQyoKLnldUl+fxloKcyGDdinb2QDD2PXD9XpRc5HbwrNqmPhmWJ0e/UBRwWUbictoSBMJ4aPIlTym7tmGSfnad7IPv5Srn06Y3XBZuYQ1Xys1ZxJwHplzKU0w90/qyyPVRqKOq/MLuCVIMXJCRzYsm45jCi3wlMV3wGL62NM3woVBhffjDDamQ53wj1axbnrsRRrHGvT3qf401ulwz8Ta2wR4uBYmHqgQhJz/9sbeghYJb5FWrjfTJDZcpuOb/2rXGCjZzLO89NTeNJJsLx8uenN3zhb+nnl/3yl1tkz3umoGAvkIUnqQXKMRLBu54y8WHgbT1gdAw=", "c2_domain": ["init.icecreambob.com", "app.updatebrouser.com", "fun.lakeofgold.com"], "botnet": "3500", "server": "580", "serpent_key": "34V2LBzJE8iG98YR", "sleep_time": "5", "CONF_TIMEOUT": "20", "SetWaitableTimer_value": "1"}
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_2 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif | Yara detected Ursnif | Joe Security | ||
Click to see the 98 entries |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
JoeSecurity_Ursnif_1 | Yara detected Ursnif | Joe Security | ||
Click to see the 19 entries |
Sigma Overview |
---|
System Summary: |
---|
Sigma detected: Encoded IEX | Show sources |
Source: | Author: Florian Roth: |
Sigma detected: MSHTA Spawning Windows Shell | Show sources |
Source: | Author: Michael Haag: |
Sigma detected: Mshta Spawning Windows Shell | Show sources |
Source: | Author: Florian Roth: |
Sigma detected: Suspicious Csc.exe Source File Folder | Show sources |
Source: | Author: Florian Roth: |
Sigma detected: Suspicious Rundll32 Activity | Show sources |
Source: | Author: juju4, Jonhnathan Ribeiro, oscd.community: |
Sigma detected: Non Interactive PowerShell | Show sources |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Sigma detected: T1086 PowerShell Execution | Show sources |
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Data Obfuscation: |
---|
Sigma detected: Powershell run code from registry | Show sources |
Source: | Author: Joe Security: |
Jbx Signature Overview |
---|
Click to jump to signature section
Show All Signature Results
AV Detection: |
---|
Antivirus detection for URL or domain | Show sources |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link |
Multi AV Scanner detection for domain / URL | Show sources |
Source: | Virustotal: | Perma Link |
Source: | Code function: | 0_2_00DD3FAB |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_0457A5F6 |
Source: | Code function: | 0_2_0457CC4A | |
Source: | Code function: | 0_2_0457198F | |
Source: | Code function: | 0_2_04580BC5 | |
Source: | Code function: | 3_2_04BBCC4A | |
Source: | Code function: | 3_2_04BB198F | |
Source: | Code function: | 3_2_04BC0BC5 | |
Source: | Code function: | 49_2_0097198F | |
Source: | Code function: | 49_2_00980BC5 | |
Source: | Code function: | 49_2_0097CC4A |
Networking: |
---|
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) | Show sources |
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
System process connects to network (likely due to code injection or exploit) | Show sources |
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior |
Uses nslookup.exe to query domains | Show sources |
Source: | Process created: | ||
Source: | Process created: |
May check the online IP address of the machine | Show sources |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
E-Banking Fraud: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Disables SPDY (HTTP compression, likely to perform web injects) | Show sources |
Source: | Registry key value created / modified: |
Source: | Code function: | 0_2_00DD3FAB |
System Summary: |
---|
Writes or reads registry keys via WMI | Show sources |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Writes registry values via WMI | Show sources |
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: | ||
Source: | WMI Registry write: |
Source: | Code function: | 0_2_6E4B2274 | |
Source: | Code function: | 0_2_00DD2654 | |
Source: | Code function: | 0_2_00DD7E30 | |
Source: | Code function: | 0_2_00DD4FA7 | |
Source: | Code function: | 0_2_04572C07 | |
Source: | Code function: | 0_2_04572499 | |
Source: | Code function: | 0_2_04565518 | |
Source: | Code function: | 0_2_0456AD2E | |
Source: | Code function: | 0_2_0457C5F4 | |
Source: | Code function: | 0_2_04574658 | |
Source: | Code function: | 0_2_0456279B | |
Source: | Code function: | 0_2_045788BB | |
Source: | Code function: | 0_2_0456E9BD | |
Source: | Code function: | 0_2_04564AFE | |
Source: | Code function: | 0_2_045852A0 | |
Source: | Code function: | 0_2_04582339 | |
Source: | Code function: | 3_2_04BB2499 | |
Source: | Code function: | 3_2_04BB2C07 | |
Source: | Code function: | 3_2_04BBC5F4 | |
Source: | Code function: | 3_2_04BAAD2E | |
Source: | Code function: | 3_2_04BA5518 | |
Source: | Code function: | 3_2_04BB4658 | |
Source: | Code function: | 3_2_04BA279B | |
Source: | Code function: | 3_2_04BB88BB | |
Source: | Code function: | 3_2_04BAE9BD | |
Source: | Code function: | 3_2_04BC52A0 | |
Source: | Code function: | 3_2_04BA4AFE | |
Source: | Code function: | 3_2_04BC2339 | |
Source: | Code function: | 5_2_04A77E30 | |
Source: | Code function: | 5_2_04A72654 | |
Source: | Code function: | 5_2_04A74FA7 | |
Source: | Code function: | 34_2_0093F2F0 | |
Source: | Code function: | 34_2_0093B530 | |
Source: | Code function: | 34_2_0093179C | |
Source: | Code function: | 34_2_0094508C | |
Source: | Code function: | 34_2_009340B4 | |
Source: | Code function: | 34_2_0094E0CF | |
Source: | Code function: | 34_2_00923804 | |
Source: | Code function: | 34_2_0092E008 | |
Source: | Code function: | 34_2_00937834 | |
Source: | Code function: | 34_2_0094C874 | |
Source: | Code function: | 34_2_00929074 | |
Source: | Code function: | 34_2_00933074 | |
Source: | Code function: | 34_2_00944988 | |
Source: | Code function: | 34_2_009459A8 | |
Source: | Code function: | 34_2_0093D9AC | |
Source: | Code function: | 34_2_0093C1D4 | |
Source: | Code function: | 34_2_0092B1D8 | |
Source: | Code function: | 34_2_0093C9F0 | |
Source: | Code function: | 34_2_0093D150 | |
Source: | Code function: | 34_2_0094D2DC | |
Source: | Code function: | 34_2_009432EC | |
Source: | Code function: | 34_2_00938218 | |
Source: | Code function: | 34_2_00937278 | |
Source: | Code function: | 34_2_0094AA6C | |
Source: | Code function: | 34_2_00926A68 | |
Source: | Code function: | 34_2_00939268 | |
Source: | Code function: | 34_2_0094EB10 | |
Source: | Code function: | 34_2_00936B1C | |
Source: | Code function: | 34_2_00922B74 | |
Source: | Code function: | 34_2_009464F4 | |
Source: | Code function: | 34_2_00933C24 | |
Source: | Code function: | 34_2_00930474 | |
Source: | Code function: | 34_2_0093ED94 | |
Source: | Code function: | 34_2_0094DD9C | |
Source: | Code function: | 34_2_009385CC | |
Source: | Code function: | 34_2_00938DF4 | |
Source: | Code function: | 34_2_00949524 | |
Source: | Code function: | 34_2_00937D44 | |
Source: | Code function: | 34_2_0093FD6C | |
Source: | Code function: | 34_2_0092C6F4 | |
Source: | Code function: | 34_2_00946E34 | |
Source: | Code function: | 34_2_00928628 | |
Source: | Code function: | 34_2_0092779C | |
Source: | Code function: | 34_2_0093DFB8 | |
Source: | Code function: | 34_2_00943F08 | |
Source: | Code function: | 34_2_00939770 | |
Source: | Code function: | 45_2_000002D2D67DF2F0 | |
Source: | Code function: | 45_2_000002D2D67DB530 | |
Source: | Code function: | 45_2_000002D2D67C6A68 | |
Source: | Code function: | 45_2_000002D2D67EEB10 | |
Source: | Code function: | 45_2_000002D2D67E3F08 | |
Source: | Code function: | 45_2_000002D2D67CC6F4 | |
Source: | Code function: | 45_2_000002D2D67E32EC | |
Source: | Code function: | 45_2_000002D2D67ED2DC | |
Source: | Code function: | 45_2_000002D2D67C2B74 | |
Source: | Code function: | 45_2_000002D2D67D9770 | |
Source: | Code function: | 45_2_000002D2D67D6B1C | |
Source: | Code function: | 45_2_000002D2D67CE008 | |
Source: | Code function: | 45_2_000002D2D67C3804 | |
Source: | Code function: | 45_2_000002D2D67DDFB8 | |
Source: | Code function: | 45_2_000002D2D67C779C | |
Source: | Code function: | 45_2_000002D2D67D179C | |
Source: | Code function: | 45_2_000002D2D67E508C | |
Source: | Code function: | 45_2_000002D2D67EC874 | |
Source: | Code function: | 45_2_000002D2D67C9074 | |
Source: | Code function: | 45_2_000002D2D67D3074 | |
Source: | Code function: | 45_2_000002D2D67D0474 | |
Source: | Code function: | 45_2_000002D2D67D7834 | |
Source: | Code function: | 45_2_000002D2D67D3C24 | |
Source: | Code function: | 45_2_000002D2D67E64F4 | |
Source: | Code function: | 45_2_000002D2D67EE0CF | |
Source: | Code function: | 45_2_000002D2D67D40B4 | |
Source: | Code function: | 45_2_000002D2D67E4988 | |
Source: | Code function: | 45_2_000002D2D67DFD6C | |
Source: | Code function: | 45_2_000002D2D67DD150 | |
Source: | Code function: | 45_2_000002D2D67D7D44 | |
Source: | Code function: | 45_2_000002D2D67E9524 | |
Source: | Code function: | 45_2_000002D2D67D8DF4 | |
Source: | Code function: | 45_2_000002D2D67DC9F0 | |
Source: | Code function: | 45_2_000002D2D67CB1D8 | |
Source: | Code function: | 45_2_000002D2D67DC1D4 | |
Source: | Code function: | 45_2_000002D2D67D85CC | |
Source: | Code function: | 45_2_000002D2D67DD9AC | |
Source: | Code function: | 45_2_000002D2D67E59A8 | |
Source: | Code function: | 45_2_000002D2D67EDD9C | |
Source: | Code function: | 45_2_000002D2D67DED94 | |
Source: | Code function: | 45_2_000002D2D67D7278 | |
Source: | Code function: | 45_2_000002D2D67EAA6C | |
Source: | Code function: | 45_2_000002D2D67D9268 | |
Source: | Code function: | 45_2_000002D2D67E6E34 | |
Source: | Code function: | 45_2_000002D2D67C8628 | |
Source: | Code function: | 45_2_000002D2D67D8218 | |
Source: | Code function: | 49_2_009788BB | |
Source: | Code function: | 49_2_0096E9BD | |
Source: | Code function: | 49_2_009852A0 | |
Source: | Code function: | 49_2_00964AFE | |
Source: | Code function: | 49_2_00982339 | |
Source: | Code function: | 49_2_00972499 | |
Source: | Code function: | 49_2_00972C07 | |
Source: | Code function: | 49_2_0097C5F4 | |
Source: | Code function: | 49_2_00965518 | |
Source: | Code function: | 49_2_0096AD2E | |
Source: | Code function: | 49_2_00974658 | |
Source: | Code function: | 49_2_0096279B |
Source: | Code function: | 0_2_0456D1F8 |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Code function: | 0_2_6E4B121F | |
Source: | Code function: | 0_2_6E4B1A1C | |
Source: | Code function: | 0_2_6E4B2013 | |
Source: | Code function: | 0_2_6E4B2495 | |
Source: | Code function: | 0_2_00DD22EC | |
Source: | Code function: | 0_2_00DD3C64 | |
Source: | Code function: | 0_2_00DD37E0 | |
Source: | Code function: | 0_2_00DD8055 | |
Source: | Code function: | 0_2_0456DE77 | |
Source: | Code function: | 0_2_04566EB0 | |
Source: | Code function: | 0_2_04567FDD | |
Source: | Code function: | 0_2_04570FA5 | |
Source: | Code function: | 0_2_045692F3 | |
Source: | Code function: | 0_2_04575AED | |
Source: | Code function: | 0_2_04561305 | |
Source: | Code function: | 0_2_04577419 | |
Source: | Code function: | 0_2_0457A42B | |
Source: | Code function: | 0_2_045736C0 | |
Source: | Code function: | 0_2_04576F70 | |
Source: | Code function: | 0_2_04564851 | |
Source: | Code function: | 0_2_0456D812 | |
Source: | Code function: | 0_2_0456D00C | |
Source: | Code function: | 0_2_04564173 | |
Source: | Code function: | 0_2_04579180 | |
Source: | Code function: | 0_2_0457DBCE | |
Source: | Code function: | 3_2_04BBA42B | |
Source: | Code function: | 3_2_04BA6EB0 | |
Source: | Code function: | 3_2_04BB969C | |
Source: | Code function: | 3_2_04BADE77 | |
Source: | Code function: | 3_2_04BB0FA5 | |
Source: | Code function: | 3_2_04BA7FDD | |
Source: | Code function: | 3_2_04BB680B | |
Source: | Code function: | 3_2_04BA4173 | |
Source: | Code function: | 3_2_04BA92F3 | |
Source: | Code function: | 3_2_04BB5AED | |
Source: | Code function: | 3_2_04BBA21F | |
Source: | Code function: | 3_2_04BA1305 | |
Source: | Code function: | 3_2_04BB7419 | |
Source: | Code function: | 3_2_04BB36C0 | |
Source: | Code function: | 3_2_04BB6F70 | |
Source: | Code function: | 3_2_04BAD812 | |
Source: | Code function: | 3_2_04BAD00C | |
Source: | Code function: | 3_2_04BA4851 | |
Source: | Code function: | 3_2_04BB9180 | |
Source: | Code function: | 3_2_04BBDBCE | |
Source: | Code function: | 5_2_04A722EC | |
Source: | Code function: | 5_2_04A78055 | |
Source: | Code function: | 34_2_0092A8D4 | |
Source: | Code function: | 34_2_0092B92C | |
Source: | Code function: | 34_2_0093FAA8 | |
Source: | Code function: | 34_2_009252DC | |
Source: | Code function: | 34_2_00921A58 | |
Source: | Code function: | 34_2_00922B08 | |
Source: | Code function: | 34_2_0092A444 | |
Source: | Code function: | 34_2_00947DAC | |
Source: | Code function: | 34_2_00940DE0 | |
Source: | Code function: | 34_2_0093179C | |
Source: | Code function: | 34_2_0095F002 | |
Source: | Code function: | 45_2_000002D2D67C2B08 | |
Source: | Code function: | 45_2_000002D2D67C1A58 | |
Source: | Code function: | 45_2_000002D2D67FF002 | |
Source: | Code function: | 49_2_00961305 | |
Source: | Code function: | 49_2_0096DE77 | |
Source: | Code function: | 49_2_00970FA5 | |
Source: | Code function: | 49_2_00967FDD | |
Source: | Code function: | 49_2_0096D812 | |
Source: | Code function: | 49_2_0096D00C | |
Source: | Code function: | 49_2_00977419 | |
Source: | Code function: | 49_2_00976F70 |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | File created: |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | Virustotal: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Key value queried: | Jump to behavior |
Source: | File created: |
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: |
Source: | Code function: | 0_2_00DD11B8 |
Source: | Process created: |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | |||
Source: | File read: |
Source: | Key opened: | Jump to behavior |
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: |
Source: | File opened: |
Source: | Window detected: |
Source: | File opened: |
Source: | Key opened: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Data Obfuscation: |
---|
Suspicious powershell command line found | Show sources |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_6E4B2273 | |
Source: | Code function: | 0_2_6E4B2219 | |
Source: | Code function: | 0_2_00DD7AB9 | |
Source: | Code function: | 0_2_00DD7E2F | |
Source: | Code function: | 0_2_04584EE9 | |
Source: | Code function: | 0_2_045679B7 | |
Source: | Code function: | 0_2_0458529F | |
Source: | Code function: | 3_2_04BC4EE9 | |
Source: | Code function: | 3_2_04BA79B7 | |
Source: | Code function: | 3_2_04BC529F | |
Source: | Code function: | 5_2_04A77AB9 | |
Source: | Code function: | 5_2_04A77E2F | |
Source: | Code function: | 34_2_0093B1BA | |
Source: | Code function: | 45_2_000002D2D67DB1BA | |
Source: | Code function: | 49_2_009679B7 | |
Source: | Code function: | 49_2_0098529F | |
Source: | Code function: | 49_2_00984EE9 |
Source: | Code function: | 0_2_6E4B1552 |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Hooks registry keys query functions (used to hide registry keys) | Show sources |
Source: | IAT, EAT, inline or SSDT hook detected: |
Modifies the export address table of user mode modules (user mode EAT hooks) | Show sources |
Source: | IAT of a user mode module has changed: |
Modifies the prolog of user mode functions (user mode inline hooks) | Show sources |
Source: | User mode code has changed: |
Modifies the import address table of user mode modules (user mode IAT hooks) | Show sources |
Source: | EAT of a user mode module has changed: |
Source: | Registry key monitored for changes: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion: |
---|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) | Show sources |
Source: | Binary or memory string: |
Source: | Thread sleep time: | ||
Source: | Thread sleep time: |
Source: | Last function: |
Source: | Thread delayed: | ||
Source: | Thread delayed: |
Source: | Window / User API: | ||
Source: | Window / User API: | ||
Source: | Window / User API: | ||
Source: | Window / User API: |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread delayed: | ||
Source: | Thread delayed: |
Source: | Code function: | 0_2_0457A5F6 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_0457CC4A | |
Source: | Code function: | 0_2_0457198F | |
Source: | Code function: | 0_2_04580BC5 | |
Source: | Code function: | 3_2_04BBCC4A | |
Source: | Code function: | 3_2_04BB198F | |
Source: | Code function: | 3_2_04BC0BC5 | |
Source: | Code function: | 49_2_0097198F | |
Source: | Code function: | 49_2_00980BC5 | |
Source: | Code function: | 49_2_0097CC4A |
Source: | Code function: | 0_2_6E4B1552 |
Source: | Process token adjusted: | ||
Source: | Process token adjusted: |
Source: | Code function: | 0_2_045737F9 | |
Source: | Code function: | 3_2_04BB37F9 | |
Source: | Code function: | 49_2_009737F9 |
HIPS / PFW / Operating System Protection Evasion: |
---|
System process connects to network (likely due to code injection or exploit) | Show sources |
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior |
Maps a DLL or memory area into another process | Show sources |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Compiles code for process injection (via .Net compiler) | Show sources |
Source: | File written: | Jump to dropped file |
Allocates memory in foreign processes | Show sources |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: |
Creates a thread in another existing process (thread injection) | Show sources |
Source: | Thread created: | ||
Source: | Thread created: | ||
Source: | Thread created: | ||
Source: | Thread created: | ||
Source: | Thread created: | ||
Source: | Thread created: | ||
Source: | Thread created: | ||
Source: | Thread created: |
Writes to foreign memory regions | Show sources |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: | |||
Source: | Memory written: |
Changes memory attributes in foreign processes to executable or writable | Show sources |
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: | ||
Source: | Memory protected: |
Injects code into the Windows Explorer (explorer.exe) | Show sources |
Source: | Memory written: | ||
Source: | Memory written: | ||
Source: | Memory written: | ||
Source: | Memory written: | ||
Source: | Memory written: | ||
Source: | Memory written: | ||
Source: | Memory written: |
Modifies the context of a thread in another process (thread injection) | Show sources |
Source: | Thread register set: | Jump to behavior | ||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: | |||
Source: | Thread register set: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_6E4B105E |
Source: | Key value queried: | Jump to behavior |
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: |
Source: | Code function: | 0_2_00DD2E33 |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 0_2_6E4B109B |
Source: | Code function: | 0_2_00DD2E33 |
Source: | Code function: | 0_2_0457D8BC |
Source: | Code function: | 0_2_6E4B1C6F |
Stealing of Sensitive Information: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Tries to steal Mail credentials (via file access) | Show sources |
Source: | Key opened: | ||
Source: | Key opened: |
Remote Access Functionality: |
---|
Yara detected Ursnif | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts1 | Windows Management Instrumentation2 | DLL Side-Loading1 | DLL Side-Loading1 | Obfuscated Files or Information1 | Credential API Hooking3 | System Time Discovery1 | Remote Services | Archive Collected Data11 | Exfiltration Over Other Network Medium | Ingress Tool Transfer3 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Data Encrypted for Impact1 |
Default Accounts | Native API1 | Valid Accounts1 | Valid Accounts1 | DLL Side-Loading1 | LSASS Memory | Account Discovery1 | Remote Desktop Protocol | Email Collection11 | Exfiltration Over Bluetooth | Encrypted Channel2 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | Command and Scripting Interpreter1 | Logon Script (Windows) | Access Token Manipulation1 | Rootkit4 | Security Account Manager | File and Directory Discovery3 | SMB/Windows Admin Shares | Credential API Hooking3 | Automated Exfiltration | Non-Application Layer Protocol4 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | PowerShell1 | Logon Script (Mac) | Process Injection913 | Masquerading1 | NTDS | System Information Discovery46 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Application Layer Protocol14 | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Valid Accounts1 | LSA Secrets | Query Registry1 | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | Access Token Manipulation1 | Cached Domain Credentials | Security Software Discovery11 | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Virtualization/Sandbox Evasion21 | DCSync | Virtualization/Sandbox Evasion21 | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | Process Injection913 | Proc Filesystem | Process Discovery3 | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue | |
Exploit Public-Facing Application | PowerShell | At (Linux) | At (Linux) | Rundll321 | /etc/passwd and /etc/shadow | Application Window Discovery1 | Software Deployment Tools | Data Staged | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Web Protocols | Rogue Cellular Base Station | Data Destruction | |
Supply Chain Compromise | AppleScript | At (Windows) | At (Windows) | Invalid Code Signature | Network Sniffing | System Owner/User Discovery1 | Taint Shared Content | Local Data Staging | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | File Transfer Protocols | Data Encrypted for Impact | ||
Compromise Software Dependencies and Development Tools | Windows Command Shell | Cron | Cron | Right-to-Left Override | Input Capture | Remote System Discovery1 | Replication Through Removable Media | Remote Data Staging | Exfiltration Over Physical Medium | Mail Protocols | Service Stop | ||
Compromise Software Supply Chain | Unix Shell | Launchd | Launchd | Rename System Utilities | Keylogging | System Network Configuration Discovery2 | Component Object Model and Distributed COM | Screen Capture | Exfiltration over USB | DNS | Inhibit System Recovery |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
7% | Virustotal | Browse |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | HEUR/AGEN.1108168 | Download File | ||
100% | Avira | HEUR/AGEN.1108168 | Download File | ||
100% | Avira | HEUR/AGEN.1108168 | Download File |
Domains |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
3% | Virustotal | Browse | ||
10% | Virustotal | Browse | ||
2% | Virustotal | Browse |
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
100% | Avira URL Cloud | malware | ||
0% | URL Reputation | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware |
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
myip.opendns.com | 102.129.143.57 | true | false | high | |
resolver1.opendns.com | 208.67.222.222 | true | false | high | |
init.icecreambob.com | 194.147.86.221 | true | true |
| unknown |
art.microsoftsofymicrosoftsoft.at | 194.147.86.221 | true | true |
| unknown |
222.222.67.208.in-addr.arpa | unknown | unknown | true |
| unknown |
Contacted URLs |
---|
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
true |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| low | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
true |
| unknown | ||
false | high | |||
true |
| unknown | ||
false |
| unknown | ||
false | high |
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
---|
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
194.147.86.221 | init.icecreambob.com | Russian Federation | 61400 | NETRACK-ASRU | true |
General Information |
---|
Joe Sandbox Version: | 33.0.0 White Diamond |
Analysis ID: | 498359 |
Start date: | 07.10.2021 |
Start time: | 01:30:08 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 14m 17s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | data.dll |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 46 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.bank.troj.spyw.evad.winDLL@53/41@12/1 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
01:32:09 | API Interceptor | |
01:32:19 | API Interceptor | |
01:32:30 | API Interceptor |
Joe Sandbox View / Context |
---|
IPs |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
194.147.86.221 | Get hash | malicious | Browse |
Domains |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
myip.opendns.com | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
resolver1.opendns.com | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
NETRACK-ASRU | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 11606 |
Entropy (8bit): | 4.8910535897909355 |
Encrypted: | false |
SSDEEP: | 192:Dxoe5IpObxoe5lib4LVsm5emdYVFn3eGOVpN6K3bkkjo5UgkjDt4iWN3yBGHc9so:Wwib4LEVoGIpN6KQkj2jkjh4iUxm44Q2 |
MD5: | 7A57D8959BFD0B97B364F902ACD60F90 |
SHA1: | 7033B83A6B8A6C05158BC2AD220D70F3E6F74C8F |
SHA-256: | 47B441C2714A78F9CFDCB7E85A4DE77042B19A8C4FA561F435471B474B57A4C2 |
SHA-512: | 83D8717841E22BB5CB2E0924E5162CF5F51643DFBE9EE88F524E7A81B8A4B2F770ED7BFE4355866AFB106C499AB7CD210FA3642B0424813EB03BB68715E650CC |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1192 |
Entropy (8bit): | 5.325275554903011 |
Encrypted: | false |
SSDEEP: | 24:3aEPpQrLAo4KAxCoOu42B15qRPNnCvK39tOBPnKdirh:qEPerB4BOu/9qRVnCvO9tOBfuit |
MD5: | D9D42CC091BE79AB1496C649F5585767 |
SHA1: | 5E23D29ACD70EE17F01DA4AB54BE562E33CC7980 |
SHA-256: | 5C0BFCE56791BB95902AF0280D2DED2FB46EEA5899AB08CB4A0955ABE86F08EA |
SHA-512: | 6B962EDA66C17B5F531F6370C3B4567AC0CD23EE2F140B9352C4C178115C7E54CA456644D200E888AFF1A67D038E9605C8557B272377E99C2358FB856C67CFE0 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\cmd.exe |
File Type: | |
Category: | modified |
Size (bytes): | 11 |
Entropy (8bit): | 1.2776134368191157 |
Encrypted: | false |
SSDEEP: | 3:111Qv:Luv |
MD5: | 5B3345909519932D6670D92F16496463 |
SHA1: | 6CCABAAC9315486C106AB1BBB7E6F153F5C1A3BD |
SHA-256: | 0B5C0F6FFAC14107357E2C1BFE0DEA06932FD2AA5C8BD598A73F25655F0ABFD5 |
SHA-512: | B41A0E9BA8A092E134E9403EA3C1B080B8F2D1030CE14AFA2647B282F66A76C48A4419D5D0F7C3C78412A427F4B84B8B48349B76FF2C3FD1DA9EC80D2AB14A6B |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2184 |
Entropy (8bit): | 2.707958824120458 |
Encrypted: | false |
SSDEEP: | 24:p+fpt6nfHuhKdNfI+ycuZhNbWakSyHPNnq9qp0e9Ep:cOfkKd91ulqa3+q9H |
MD5: | 9F22A8320D7A071B76FDC69EC539ECCB |
SHA1: | 14333BA5399DAD87A67A7C9A7AFEB8740FCFEECE |
SHA-256: | 9394AC09F500EBF590CEF7AA960C5BA829D34107A3156FD9258CB42DB78240DB |
SHA-512: | 615184C6FB055548483C213F1B47960804AED79DC425C4387446B496D2C6948196D17408F2013694B44711163F2881F878BBAAF2AE292EDDD0BFF10711287AC9 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2184 |
Entropy (8bit): | 2.7147512751024414 |
Encrypted: | false |
SSDEEP: | 24:p+fqnfHuhKdNfI+ycuZhNRakSfPNnq9qpxe9Ep:cqfkKd91ulRa39q9e |
MD5: | 56C427E4F156501570F09F60C71B4FFC |
SHA1: | E95259B5A9D2A7D6985794796C7D50E44F2ED54E |
SHA-256: | 0DF94A4553794E9745768309E3143BF27364A91D236F4B7B3078172745404A9D |
SHA-512: | 4DF6DE36B39C6AE6F8ECD8ACC31EEB1659FB4C75981086D5BD9D89560F7D7EAE4EE946E0E07BEC9F8095F15BA16CAB2679D500EB40C959B0452B3482FCBA76F8 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2184 |
Entropy (8bit): | 2.704757091617058 |
Encrypted: | false |
SSDEEP: | 24:bZfF7LDfHvV0QhKdNNI+ycuZhNkqakS1bPNnq9qp1e9Ep:bBptdKd31ul3a37q9a |
MD5: | A19900A27924406D8B8C2B3967F7549E |
SHA1: | 67086C00C8F2AD154A30F03F3B7B7FCC5CCA26AB |
SHA-256: | B10D3F322BEEB34F99285BE39628DEB06F88269B1C71D5AB201C1D4C873107B6 |
SHA-512: | B24F2FA68DDBDDB024C3439363F240E98390EEC262BF791B83F9E032429B41F9610641EAD8BE66589E698765AE895B07D4CAD7324583854FBD7F363B7AB41818 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2184 |
Entropy (8bit): | 2.702279321283148 |
Encrypted: | false |
SSDEEP: | 24:p+fiijCDfHv6hKdNNI+ycuZhNxakSPPNnq9qp1e9Ep:ct44Kd31ulxa3Nq9a |
MD5: | 68F64E91D72B2B0F972BCD7336F2A9CC |
SHA1: | 2B4DA3BF145E15313E6796912E46193EC0CB0542 |
SHA-256: | 5AEBE77361A5E69CD2F4E5A7FD83CE17FEEFEFBC6C29E429A92471903DE78A00 |
SHA-512: | 7D6DD472E15D32B947CD7C7CC98073D00E05FAD1397E0B5BF4A00280DD0C9729F1B9783E8713C429AD221C12C1C76867E6EED624A266467D2C180868C97CF8A2 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.1118070987658872 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryuqak7Ynqq1bPN5Dlq5J:+RI+ycuZhNkqakS1bPNnqX |
MD5: | 7C5651680CDC7C8F38DD72F6EFF7FCC1 |
SHA1: | 48F3B58D5CF23B80248D1220D2781699720AB0FC |
SHA-256: | 5E443A37A5A1A69715E0C8D1C58A98CB0CEDAB7B9F9CF4F043FC43A37F4A2155 |
SHA-512: | 009D6016851CEC3F44A2664E385461C377E9179517BB89707B0C47093C358D583FD0E08367FF693CDC6B6B84DFF7F2E7D4DEBB4BAFB1003228945811C467985A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 398 |
Entropy (8bit): | 4.993655904789625 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJWLPMRSR7a1MIq+ZXIO1SRa+rVSSRnA/fHJGF0y:V/DTLDfu0LnQs9rV5nA/Ra0y |
MD5: | C08AF9BD048D4864677C506B609F368E |
SHA1: | 23B8F42A01326DC612E4205B08115A4B68677045 |
SHA-256: | EA46497ADAE53B5568188564F92E763040A350603555D9AA5AE9A371192D7AE7 |
SHA-512: | 9688FD347C664335C40C98A3F0F8D8AF75ABA212A75908A96168D3AEBFC2FEAAB25DD62B63233EB70066DD7F8FB297F422871153901142DB6ECD83D1D345E3C2 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 369 |
Entropy (8bit): | 5.249748564356388 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2wkn23ftqhzxs7+AEszIwkn23ftqq9:p37Lvkmb6KRfFqhWZEifFqq9 |
MD5: | 1F903E4C6488F96BEFF8106212BB1FB8 |
SHA1: | F83BA87CDA88445647CBC5287FEB88FB745303D9 |
SHA-256: | 9AE5B2762E43566A26D39530831229138A3DE4407243A22BF1CACA6DDC8C5EC1 |
SHA-512: | 72685413AF01FC6EFF547B0E3F7A18A2F3FA655FCF33566E7EA1368A9684DB674AFACD57FC30F1D010B54C0D1991A1CE1A079A0CBB84ADB231546E382457E871 |
Malicious: | true |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.597551467700443 |
Encrypted: | false |
SSDEEP: | 24:etGSXW/u2Dg85lxlok3Jgpi94MatkZfltUaUI+ycuZhNkqakS1bPNnq:6XDWb5lxF1hJl61ul3a37q |
MD5: | C46F8C61C8CB705DF757CCCA39C5B679 |
SHA1: | AF738C88BB2A7C2CF9D18F0A68179DCE724C13D7 |
SHA-256: | DD862D783A4E8A31034B21655E7F80366CF2A745E821AB0E4D7EB0DD2749D3E2 |
SHA-512: | 9938809F33099A04070BC942239CF9C48B2F99CD2E7D77851939AEB1FA9A5DF6DCA46F7FF584E4183BC7ACEB2BFB7C88B3747ACE7ABC5A9481DA678590D01F9E |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.0863679805822777 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryBVak7Ynqq4aPN5Dlq5J:+RI+ycuZhNxakSPPNnqX |
MD5: | A84E3090E4FC8017918EF55DA63D009A |
SHA1: | E15976679755FDC7CC21F13701703C98E72E7187 |
SHA-256: | 6CD9F5821875D9A6795771EEC4553888DCAEED39D713D8AAFD886594B22CDAC3 |
SHA-512: | 0BCECD1BFFAA5F7AAF3C1A402AAFF92770676B19B91A2EF3F785FB58F2993B9BAC01A55B3E39AEF19B43928ED008D1C468A0518CAD499E2E3C24AE14128E28AE |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 398 |
Entropy (8bit): | 4.993655904789625 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJWLPMRSR7a1MIq+ZXIO1SRa+rVSSRnA/fHJGF0y:V/DTLDfu0LnQs9rV5nA/Ra0y |
MD5: | C08AF9BD048D4864677C506B609F368E |
SHA1: | 23B8F42A01326DC612E4205B08115A4B68677045 |
SHA-256: | EA46497ADAE53B5568188564F92E763040A350603555D9AA5AE9A371192D7AE7 |
SHA-512: | 9688FD347C664335C40C98A3F0F8D8AF75ABA212A75908A96168D3AEBFC2FEAAB25DD62B63233EB70066DD7F8FB297F422871153901142DB6ECD83D1D345E3C2 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 369 |
Entropy (8bit): | 5.22823213171567 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2wkn23fx1CokCLGzxs7+AEszIwkn23fx1CokC:p37Lvkmb6KRfZ1jkHWZEifZ1jkC |
MD5: | FA407420BBC7FCEC54DFA5F57B2D7BFB |
SHA1: | 5964FDCA13AB3C97EE75C4D5D15DEA6ED75A6FDC |
SHA-256: | E30540BE2C4911E47BBDF06B9F3DB165CD98DD7A4D77D028767C546DC3B50342 |
SHA-512: | DE73CCC9D3540D976AA4E27DCA7ABA5D44DC8ABBA0810229DF904B1C52D51EA84AE908487E61E4C5E29B78546634DC52BBFFE3CE15052611093048A77A896307 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.590972462431772 |
Encrypted: | false |
SSDEEP: | 24:etGSXW/u2Dg85lxlok3Jgpiea4MatkZf28zaUI+ycuZhNxakSPPNnq:6XDWb5lxF11JVr1ulxa3Nq |
MD5: | 2C829AD936178D4534050E2CF39B3F90 |
SHA1: | 5096E288CE9F5699BB3BB57930ED2B749692CA5B |
SHA-256: | E7ACFB204936BB5A36A6E11EC33A50BE09C01CF0104A556C03247B227F590B37 |
SHA-512: | CD552B4F18D42DAB7B5E63FAE29715C3518CC9B26FB7DD08D12FFD1416585E734E650F8E5228C3E6F0115FC9A84BCE3ED9136A79CC2C2FBA204DF9E5B572EC0D |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.1040997079419537 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryRWak7YnqqyHPN5Dlq5J:+RI+ycuZhNbWakSyHPNnqX |
MD5: | 9907C63C948829AE092C374047EE5A7F |
SHA1: | 16272A7ED54545B9C5EB9DB21BAF114DBBEBA3F6 |
SHA-256: | 67EDC019440BEAB697297DA6152E19A52C0FE9B6E19A60C6CE235A60C7ECC9A4 |
SHA-512: | B4D72964DF5A8CFC8CFAA248BD4F05F6C578EF47CEBFBD240AE15E3123088CE88CFFD212265D836A2B3EB6784762CDBDA5AEE08C13FC77F38C3807E61C6EAF16 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 421 |
Entropy (8bit): | 5.017019370437066 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJzLHMRSRa+eNMjSSRrLypSRHq1oZ6laAkKFM+Qy:V/DTLDfuxLP9eg5rLy4uMaLXjQy |
MD5: | 7504862525C83E379C573A3C2BB810C6 |
SHA1: | 3C7E3F89955F07E061B21107DAEF415E0D0C5F5E |
SHA-256: | B81B8E100611DBCEC282117135F47C781087BD95A01DC5496CAC6BE334A8B0CC |
SHA-512: | BC8C4EAD30E12FB619762441B9E84A4E7DF15D23782F80284378129F95FAD5A133D10C975795EEC6DA2564EC4D7F75430C45CA7113A8BFF2D1AFEE0331F13E76 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 369 |
Entropy (8bit): | 5.260808918395778 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2wkn23fpvJUzxs7+AEszIwkn23fpF9:p37Lvkmb6KRfhv+WZEifhr |
MD5: | 0330280B07D13A01DEC77E2EDC601878 |
SHA1: | D0F5CBC44E5B7DDD673F51164A68DE0C47E7EC74 |
SHA-256: | A6904C47757F5AC51C966E7BC9D0BC5B6EB9F09C53FC843CD3B28ACF44DA2F37 |
SHA-512: | 6E6B2A6F74845D5207AA9D57558E701B842392CB1D89B02ECAFEACAB746C22054E9A92F7AB9D7A5B8C9A7C7764CEB054F6CA17AF7DE9A6A54C8F28C0110EEB87 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.6445805370692286 |
Encrypted: | false |
SSDEEP: | 24:etGSi/WMOWEey8MTz7X8daP0eWQyaDdWSWtJ0DtkZfgB/7XI+ycuZhNbWakSyHPE:6i/A7KMTcd6qZkWPVJgh1ulqa3+q |
MD5: | A4133BB77D49BF5FE87ABE8507B3EBD7 |
SHA1: | 1871D83D9E0E0850DF8F2146693135C4F7770EE5 |
SHA-256: | 365D9862EAB5F5F08A5926E86058C33BE06692E309FD3D5F53085BF7636CD97F |
SHA-512: | 17EDADBCD3E5AE487E6652567B5A046AD4955084458B5951A9C365C9BC43E43A7EF67D5109F4E4319A98695CF30FF18046F8796F3042BC82D30605BF209FA36C |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.1124345771696067 |
Encrypted: | false |
SSDEEP: | 12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryTak7YnqqfPN5Dlq5J:+RI+ycuZhNRakSfPNnqX |
MD5: | B7D8E5C3BC81D5C419A478823788E0F7 |
SHA1: | CCF5C55CAC587EBB0C20A4FB2D615BA1746EB793 |
SHA-256: | 570747FD73BC71FF18100C1F1F58F31127BB6497396718176BDE33882C949C36 |
SHA-512: | 5B42A169F5F8A6D9EF707BFF46CFF188027473576C4FA1E0C5E1C4D214AFAB5FD92131DA1F7CF2276985A6B514511C08241BDF300B6B763E6CAF43823CF24912 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 421 |
Entropy (8bit): | 5.017019370437066 |
Encrypted: | false |
SSDEEP: | 6:V/DsYLDS81zuJzLHMRSRa+eNMjSSRrLypSRHq1oZ6laAkKFM+Qy:V/DTLDfuxLP9eg5rLy4uMaLXjQy |
MD5: | 7504862525C83E379C573A3C2BB810C6 |
SHA1: | 3C7E3F89955F07E061B21107DAEF415E0D0C5F5E |
SHA-256: | B81B8E100611DBCEC282117135F47C781087BD95A01DC5496CAC6BE334A8B0CC |
SHA-512: | BC8C4EAD30E12FB619762441B9E84A4E7DF15D23782F80284378129F95FAD5A133D10C975795EEC6DA2564EC4D7F75430C45CA7113A8BFF2D1AFEE0331F13E76 |
Malicious: | true |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 369 |
Entropy (8bit): | 5.271207229716755 |
Encrypted: | false |
SSDEEP: | 6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2wkn23fCN5WNDJH0zxs7+AEszIwkn23fCN5W5:p37Lvkmb6KRfJB+WZEifJrFH |
MD5: | 6CF8D7A784B60B520B01D64CFDEC3508 |
SHA1: | CD91CFE9EF2EDA8F6411ED9A6817FD7553709484 |
SHA-256: | 9903E082EA138385CE8CA2418FD1848F422EA4391352B5B5ED57D12C69500D7B |
SHA-512: | 4FDD957F2C27F2E0C566066310715DD6A4F70921E8140FCDC8893931E2D72DB1E79CB96AB74714250AD0735C9502B4BE767FE3FDD82CE4A14519C56F9C690BC6 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3584 |
Entropy (8bit): | 2.6442225461586313 |
Encrypted: | false |
SSDEEP: | 24:etGSrXWMOWEey8MTz7X8daP0eWQSDdWSWtJ0DtkZf6mBqO7XI+ycuZhNRakSfPNq:6bA7KMTcd6q1WPVJ6mU81ulRa39q |
MD5: | DE4F576253BDA1AE82659E3E111C25E6 |
SHA1: | 8A1237FCD0B3E732089509C1AA08FD31532A7564 |
SHA-256: | 599CF9AE58AA3E33D27F5A6B179DC111FCE16A907A2BA8EFEE485E483A07DD44 |
SHA-512: | 388163ABC93D673A14C861172E2BAE47078E38114660CAC4361433B8A1E7EADE57BAFEC90753C1BE5F60FDFCE7EF7A61966AF51642DF979CF8CA4A447AAA1F8A |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe |
File Type: | |
Category: | modified |
Size (bytes): | 412 |
Entropy (8bit): | 4.871364761010112 |
Encrypted: | false |
SSDEEP: | 12:zKaMK4BFNn5KBZvK2wo8dRSgarZucvW3ZDPOU:zKaM5DqBVKVrdFAMBJTH |
MD5: | 83B3C9D9190CE2C57B83EEE13A9719DF |
SHA1: | ABFAB07DEA88AF5D3AF75970E119FE44F43FE19E |
SHA-256: | B5D219E5143716023566DD71C0195F41F32C3E7F30F24345E1708C391DEEEFDA |
SHA-512: | 0DE42AC5924B8A8E977C1330E9D7151E9DCBB1892A038C1815321927DA3DB804EC13B129196B6BC84C7BFC9367C1571FCD128CCB0645EAC7418E39A91BC2FEDB |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1189 |
Entropy (8bit): | 5.305482263812092 |
Encrypted: | false |
SSDEEP: | 24:BxSAs7vBZQx2DOXUWOLCHGIYBtBCWxHjeTKKjX4CIym1ZJXyOLCHGIYBtB7nxSAO:BZqvjQoORFeVxqDYB1ZQFerZZw |
MD5: | 59590A90D28BC6CF4C8C601B8DD050B5 |
SHA1: | 683AE8715C414BA8B4FBB180D5428437C1A0C239 |
SHA-256: | 98CB74CD1B59345C836ECAFD81BF563BE36E0931F98D07D4643D2F2A01B124EF |
SHA-512: | DAC46930F0F98749EF7719761FD4D9A5E6E3EDF6AD16810CF6CD90164A9F08E66E8155F4583AE80D75DAC6F2C89B30C4E3142099A28B97B8C970403D5483DF9F |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1189 |
Entropy (8bit): | 5.308334237745025 |
Encrypted: | false |
SSDEEP: | 24:BxSAs7vBZQx2DOXUWOLCHGIYBtBCWWHjeTKKjX4CIym1ZJXyOLCHGIYBtBamnxS8:BZqvjQoORFeVWqDYB1ZQFeaoZZ6C |
MD5: | F38AD184905D39ED5F604BD58DF787FB |
SHA1: | DA25886901C51B476DD82D233102E94B5E61B6E2 |
SHA-256: | CF176D0FC864490B8181A27D38241E0140ADBB22A58ACB2F4791909922E08C31 |
SHA-512: | AB3EEB69125BAA4D4E14C89361B05C6D551F46B370919601E5C8E64D211E9FB66966664E379B90E61CA0640E738B625B03FE8B3457824ACDBC55F87A2D2F5524 |
Malicious: | false |
Preview: |
|
Process: | C:\Windows\System32\nslookup.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28 |
Entropy (8bit): | 4.039148671903071 |
Encrypted: | false |
SSDEEP: | 3:U+6QlBxAN:U+7BW |
MD5: | D796BA3AE0C072AA0E189083C7E8C308 |
SHA1: | ABB1B68758B9C2BF43018A4AEAE2F2E72B626482 |
SHA-256: | EF17537B7CAAB3B16493F11A099F3192D5DCD911C1E8DF0F68FE4AB6531FB43E |
SHA-512: | BF497C5ACF74DE2446834E93900E92EC021FC03A7F1D3BF7453024266349CCE39C5193E64ACBBD41E3A037473A9DB6B2499540304EAD51E002EF3B747748BF36 |
Malicious: | false |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.647077324309591 |
TrID: |
|
File name: | data.dll |
File size: | 453131 |
MD5: | b0165e4e73dad2ac1cb519ea1eab8bd6 |
SHA1: | 4ebb5db088d233d4c85b19b299613a240ce25c95 |
SHA256: | 7ff6558fd39f6d8db53aa0baa3f3a9b1edb02ea2631102b6d85eafaf4bbd702b |
SHA512: | 0f19a2902265b9e56e8f46ffe283a2796142ab59ef42d97a957bb6327494f838d8a262b957152ad768322bca4b2c05188c386c54a5c65c77c60c3205c742ea30 |
SSDEEP: | 12288:kHlAiJHCwjXvMHk37t4Mv//IfN/YoyL8ozF0nxatQ7:kHltJHCkvH/IJvUWxata |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............g...g...g....l..g..K.8..g...9...g...9...g....0..g...9...g....4..g...g...f...9...g...9..(g...9...g...9...g...9...g..Rich.g. |
File Icon |
---|
Icon Hash: | 74f0e4ecccdce0e4 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x10007197 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x10000000 |
Subsystem: | windows gui |
Image File Characteristics: | 32BIT_MACHINE, EXECUTABLE_IMAGE, DLL |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x57EEB746 [Fri Sep 30 19:04:38 2016 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 3a94ffcdb86144f7d0b6d92dd3393d93 |
Entrypoint Preview |
---|
Instruction |
---|
push ebp |
mov ebp, esp |
cmp dword ptr [ebp+0Ch], 01h |
jne 00007F83D8F13BC7h |
call 00007F83D8F1435Bh |
push dword ptr [ebp+10h] |
push dword ptr [ebp+0Ch] |
push dword ptr [ebp+08h] |
call 00007F83D8F13A7Ah |
add esp, 0Ch |
pop ebp |
retn 000Ch |
push ebp |
mov ebp, esp |
push 00000000h |
call dword ptr [1004F06Ch] |
push dword ptr [ebp+08h] |
call dword ptr [1004F068h] |
push C0000409h |
call dword ptr [1004F060h] |
push eax |
call dword ptr [1004F070h] |
pop ebp |
ret |
push ebp |
mov ebp, esp |
sub esp, 00000324h |
push 00000017h |
call 00007F83D8F47B7Fh |
test eax, eax |
je 00007F83D8F13BC7h |
push 00000002h |
pop ecx |
int 29h |
mov dword ptr [1006CD98h], eax |
mov dword ptr [1006CD94h], ecx |
mov dword ptr [1006CD90h], edx |
mov dword ptr [1006CD8Ch], ebx |
mov dword ptr [1006CD88h], esi |
mov dword ptr [1006CD84h], edi |
mov word ptr [1006CDB0h], ss |
mov word ptr [1006CDA4h], cs |
mov word ptr [1006CD80h], ds |
mov word ptr [1006CD7Ch], es |
mov word ptr [1006CD78h], fs |
mov word ptr [1006CD74h], gs |
pushfd |
pop dword ptr [1006CDA8h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [1006CD9Ch], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [1006CDA0h], eax |
Rich Headers |
---|
Programming Language: |
|
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x6ae90 | 0xb0 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x6af40 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x109000 | 0x440 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x10a000 | 0x2cbc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x69140 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x69198 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x4f000 | 0x19c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4d48c | 0x4d600 | False | 0.541116594305 | data | 6.75100933622 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rdata | 0x4f000 | 0x1c8ec | 0x1ca00 | False | 0.58397584607 | data | 5.72385266985 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x6c000 | 0x9b7e8 | 0xe00 | False | 0.204520089286 | data | 2.89792338491 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.gfids | 0x108000 | 0x228 | 0x400 | False | 0.2529296875 | data | 1.74193986935 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x109000 | 0x440 | 0x600 | False | 0.292317708333 | data | 2.5339353314 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x10a000 | 0x2cbc | 0x2e00 | False | 0.777513586957 | data | 6.63564333671 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_VERSION | 0x109060 | 0x3dc | data | English | United States |
Imports |
---|
DLL | Import |
---|---|
KERNEL32.dll | TlsAlloc, LoadLibraryW, VirtualProtectEx, GetModuleHandleW, CreateSemaphoreW, GetTempPathW, WriteConsoleW, CloseHandle, CreateFileW, OutputDebugStringW, ReadConsoleW, GetEnvironmentVariableW, InitializeCriticalSection, GetModuleFileNameW, RemoveDirectoryW, DeviceIoControl, GetCurrentProcess, EnterCriticalSection, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, EncodePointer, RaiseException, InterlockedPushEntrySList, InterlockedFlushSList, GetLastError, SetLastError, RtlUnwind, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, GetProcAddress, LoadLibraryExW, ExitProcess, GetModuleHandleExW, HeapFree, HeapAlloc, GetCurrentThread, GetDateFormatW, GetTimeFormatW, CompareStringW, LCMapStringW, GetLocaleInfoW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, GetTimeZoneInformation, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, GetProcessHeap, GetStdHandle, GetFileType, SetConsoleCtrlHandler, GetStringTypeW, HeapSize, HeapReAlloc, SetStdHandle, FlushFileBuffers, WriteFile, GetConsoleCP, GetConsoleMode, GetFileSizeEx, SetFilePointerEx, ReadFile, DecodePointer |
ole32.dll | CoUninitialize, CoTaskMemAlloc, CoInitialize, CoTaskMemFree |
CRYPTUI.dll | CryptUIDlgViewContext, CryptUIDlgViewCertificateW, CryptUIWizDigitalSign, CryptUIWizFreeDigitalSignContext, CryptUIWizImport, CryptUIWizExport, CryptUIDlgSelectCertificateFromStore |
Exports |
---|
Name | Ordinal | Address |
---|---|---|
Bonebegin | 1 | 0x1003f370 |
Father | 2 | 0x1003f4d0 |
Ratherdesign | 3 | 0x1003f680 |
Scorematch | 4 | 0x1003f6f0 |
Silverwere | 5 | 0x1003f6d0 |
StoneNumeral | 6 | 0x1003f7e0 |
Version Infos |
---|
Description | Data |
---|---|
LegalCopyright | Fig Governhear suggest Corporation. All rights reserved |
InternalName | Ropemother Smellclean |
FileVersion | 5.6.0.165 |
CompanyName | Fig Governhear suggest Corporation Alsoheld |
ProductName | Fig Governhear suggest Shoecould Quietfrom |
ProductVersion | 5.6.0.165 |
FileDescription | Fig Governhear suggest Shoecould Quietfrom |
OriginalFilename | Soon.dll |
Translation | 0x0409 0x04b0 |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
Snort IDS Alerts |
---|
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
10/07/21-01:32:18.233038 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:19.242466 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:19.340180 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:19.340180 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:20.827048 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49779 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:20.827048 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49779 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:20.886424 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:20.886424 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:23.671129 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:32:23.671129 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:34:00.834180 | TCP | 2033204 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M2 (_2F) | 49862 | 80 | 192.168.2.4 | 194.147.86.221 |
10/07/21-01:34:00.834180 | TCP | 2033203 | ET TROJAN Ursnif Variant CnC Beacon - URI Struct M1 (_2B) | 49862 | 80 | 192.168.2.4 | 194.147.86.221 |
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 7, 2021 01:32:18.183357000 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.232420921 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.232556105 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.233037949 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.322987080 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.712804079 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.712869883 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.712912083 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.712929010 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.712949038 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.712989092 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.713000059 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.713027000 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.713063002 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.713072062 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.713100910 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.713139057 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.713155031 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.713187933 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.713233948 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.762798071 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.762856007 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.762897968 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.762942076 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.762967110 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.762984991 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763025999 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.763166904 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763215065 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763231993 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.763262033 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763302088 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763339043 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763367891 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763390064 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.763406038 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763416052 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.763453007 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763494968 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.763516903 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.763617039 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.803900957 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.803955078 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.803992987 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.804039001 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.804083109 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.804105997 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.804121017 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.804163933 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.804178953 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.814856052 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.814912081 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.814981937 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815020084 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815058947 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815095901 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815103054 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815177917 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815203905 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815213919 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815237045 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815288067 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815329075 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815350056 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815393925 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815401077 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815431118 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815469980 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815483093 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815506935 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815543890 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815584898 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815602064 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815624952 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815639019 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815673113 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815713882 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815751076 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815790892 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815819979 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815829992 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815835953 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815865993 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815881014 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.815906048 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815943956 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815992117 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.815996885 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.816034079 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.816041946 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.816071987 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.816119909 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.855792999 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855822086 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855834961 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855851889 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855871916 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855892897 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855914116 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855935097 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855957985 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.855964899 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.855981112 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.856003046 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.856023073 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.856045008 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.856071949 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.865647078 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865691900 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865716934 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865776062 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865813971 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.865833044 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.865844011 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865869999 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865892887 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865926981 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.865928888 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865947008 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.865969896 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866008997 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866029024 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866065025 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866074085 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866094112 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866100073 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866125107 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866151094 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866163015 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866184950 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866206884 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866221905 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866266012 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866280079 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866290092 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866316080 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866329908 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866338968 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866360903 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866381884 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866383076 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866400003 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866420984 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866430044 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866442919 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866463900 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866485119 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866487026 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866508961 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866528034 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866528988 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866547108 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866588116 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866588116 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866611004 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866633892 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866643906 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866655111 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866668940 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.866678953 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.866731882 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.905524015 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905652046 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.905683041 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905710936 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905734062 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905756950 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905771971 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.905788898 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905801058 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.905812025 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905838966 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905863047 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905879974 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.905885935 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905917883 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.905925035 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905947924 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.905977964 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916292906 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916331053 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916353941 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916379929 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916399002 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916404963 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916424990 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916434050 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916457891 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916471004 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916484118 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916508913 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916522026 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916533947 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916557074 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916558981 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916583061 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916604996 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916608095 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916635036 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916656017 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916661024 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916682959 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916706085 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916726112 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916727066 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916749954 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916755915 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916764021 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916778088 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916796923 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916807890 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916812897 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916835070 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916837931 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916853905 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916857004 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916871071 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916888952 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916888952 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.916904926 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:18.916944027 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:18.917934895 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.192461967 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.220047951 CEST | 49776 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.241900921 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.242019892 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.242465973 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.268841982 CEST | 80 | 49776 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.290623903 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.335150957 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.339643002 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.339732885 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.340179920 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.433278084 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.686741114 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.686785936 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.686824083 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.686866045 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.687088013 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.687247038 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.687779903 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.687796116 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.687798977 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.687869072 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.688245058 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.688307047 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.688653946 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.689049959 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.689062119 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.743098974 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743216038 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743242025 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743273973 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743350983 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743380070 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743391991 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.743405104 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743432045 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743514061 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.743583918 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743693113 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743717909 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743750095 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743778944 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743791103 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.743804932 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743830919 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743868113 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743869066 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.743894100 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743913889 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.743917942 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.743921041 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.743947029 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.744018078 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.792788982 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.792815924 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.792831898 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.792948961 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793009996 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793201923 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793204069 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793225050 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793241978 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793256998 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793272972 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793272972 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793287992 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793318033 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793323040 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793343067 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793517113 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793574095 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793607950 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793627024 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793663025 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793673038 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793689013 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793706894 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793710947 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793735027 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793756962 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793777943 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793797970 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793800116 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793803930 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793824911 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793828011 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793843985 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793874025 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793895960 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793916941 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793920040 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793945074 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793968916 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.793972015 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.793991089 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794013023 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794032097 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.794097900 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.794114113 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794138908 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794161081 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794182062 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.794183016 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794203997 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.794204950 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794255018 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794285059 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794301987 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794325113 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.794327974 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.794395924 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.794410944 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.811055899 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811140060 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811191082 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811217070 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811242104 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811264992 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811290026 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811311960 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811336994 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.811336994 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.811384916 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.824913025 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.825069904 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.845808983 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.845870972 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.845904112 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.845932961 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.845937967 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.845963001 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.845988989 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.845992088 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.845993996 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.845997095 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.846029997 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.846050978 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.846061945 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.846077919 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.846091032 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.846110106 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.846142054 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.860569000 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860635042 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860693932 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860694885 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.860742092 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860785007 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.860795975 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860836029 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860872984 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860904932 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.860910892 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860949039 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.860953093 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.860996008 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861037016 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861063957 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.861076117 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861115932 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861134052 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.861155987 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861191034 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861227989 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861238956 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.861265898 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861272097 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.861314058 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.861356020 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.874541044 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.874596119 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.875806093 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.895229101 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895261049 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895276070 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895299911 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895328045 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895355940 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895382881 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895384073 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.895411968 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895446062 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895477057 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895500898 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.895504951 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895533085 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895554066 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895574093 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895595074 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895622969 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.895658970 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895670891 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.895689964 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.895718098 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.895762920 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911097050 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911155939 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911181927 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911398888 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911425114 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911447048 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911467075 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911472082 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911494970 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911525011 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911529064 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911550045 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911566973 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911572933 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911597013 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911619902 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911628008 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911642075 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911664963 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911670923 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911691904 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911720037 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911720037 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911746025 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911768913 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911777973 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911792994 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911815882 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911839008 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911854029 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911864996 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911910057 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911946058 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.911948919 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911983967 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.911988974 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.912015915 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912046909 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912074089 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.912077904 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912107944 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912138939 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912139893 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.912169933 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912199020 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.912209034 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912242889 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912273884 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912280083 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.912306070 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.912342072 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.912417889 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.934746981 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.934819937 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.934885979 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.934885979 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.934937000 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.934983969 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.945647001 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.945672035 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.945780039 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.945811987 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962347984 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962388039 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962412119 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962431908 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962452888 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962459087 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962472916 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962492943 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962507963 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962523937 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962529898 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962544918 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962560892 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962563992 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962580919 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962593079 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962601900 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962621927 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962641954 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962646961 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962661982 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962668896 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962687016 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962708950 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962712049 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962732077 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962750912 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962769985 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962771893 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962789059 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962795973 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962809086 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962829113 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962830067 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962853909 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962876081 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962882996 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962894917 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962928057 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962935925 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962953091 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.962965965 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.962976933 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963001013 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963010073 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.963025093 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963054895 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963082075 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963094950 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.963112116 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963129044 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.963171959 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963203907 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963241100 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963242054 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.963274002 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963311911 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963316917 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.963346958 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963359118 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.963371992 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963396072 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963411093 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.963419914 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.963489056 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.984118938 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.984167099 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.984200954 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.984240055 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.984256029 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.984294891 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.994852066 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.994915962 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.994998932 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995208979 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995268106 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995306969 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995346069 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995372057 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995393038 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995398045 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995443106 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995467901 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995491982 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995501995 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995544910 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995580912 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995593071 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995628119 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995647907 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:19.995649099 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:19.995704889 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.000814915 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.000905991 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.000965118 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.001013994 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.001020908 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.001055956 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.002638102 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.012643099 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012754917 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012774944 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012794018 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012809992 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012826920 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012842894 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012860060 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012876034 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012891054 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012911081 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012928963 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.012986898 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013016939 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013034105 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013061047 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013109922 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013129950 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013148069 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013164997 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013181925 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013228893 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013243914 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013263941 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013288975 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013300896 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013305902 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013319969 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013401031 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013420105 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013437033 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013452053 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013483047 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013523102 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013592005 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013607979 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013622999 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013638973 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013695002 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013695002 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013710976 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013745070 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013771057 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013794899 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013808966 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013818026 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013840914 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013858080 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013874054 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013896942 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013902903 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013921976 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013945103 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013955116 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.013967037 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013991117 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.013994932 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.014014006 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.014045000 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.014087915 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.033302069 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.033324957 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.033337116 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.033349991 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.033365965 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.033458948 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.044347048 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044392109 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044409037 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044425011 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044446945 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044461966 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044482946 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044581890 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.044630051 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.044641018 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044699907 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044747114 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044789076 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.044838905 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.044871092 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.044878960 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.044995070 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.049719095 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.049761057 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.049860001 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.051165104 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062318087 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062371016 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062407017 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062453032 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062496901 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062517881 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062534094 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062556028 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062561989 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062572956 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062611103 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062645912 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062661886 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062684059 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062696934 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062721014 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062767029 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062808990 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062817097 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062845945 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062869072 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062886000 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062922955 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062958956 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.062968969 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.062995911 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.063005924 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.063030005 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.065000057 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.065067053 CEST | 49778 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.093746901 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.093813896 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.093868971 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.093869925 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.093921900 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.093928099 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.093949080 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.093978882 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.093980074 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.094036102 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.094041109 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.094100952 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.094125986 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.094151020 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.094152927 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.094206095 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.099222898 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.099283934 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.099394083 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.114713907 CEST | 80 | 49778 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143610954 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143637896 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143657923 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143677950 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143701077 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.143706083 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143733025 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143733978 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.143757105 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.143759012 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.143800974 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.148165941 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.148466110 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.192871094 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.192926884 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.192967892 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.192994118 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.193003893 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.193072081 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.193200111 CEST | 49777 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.241934061 CEST | 80 | 49777 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.775321007 CEST | 49779 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.826149940 CEST | 80 | 49779 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.826302052 CEST | 49779 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.827048063 CEST | 49779 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.833169937 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.885941029 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.886065006 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.886424065 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:20.918912888 CEST | 80 | 49779 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:20.980824947 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.292851925 CEST | 80 | 49779 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.292890072 CEST | 80 | 49779 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.293133020 CEST | 49779 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.544200897 CEST | 49779 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.568727970 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.568784952 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.568821907 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.568861008 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.568875074 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.568897009 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.568914890 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.568938971 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.568977118 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.568990946 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.569017887 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.569056988 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.569072008 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.569092989 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.569140911 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.592881918 CEST | 80 | 49779 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618634939 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618660927 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618678093 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618695021 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618711948 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618736982 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618752003 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.618794918 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.618798971 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.618824959 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618851900 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618870974 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618891001 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.618891954 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.618951082 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.667849064 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668404102 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668441057 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668489933 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668533087 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668565035 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.668570042 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668607950 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668637991 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.668648005 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668648958 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.668684006 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668720007 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.668724060 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668761015 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.668791056 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.718566895 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718624115 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718667030 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718688011 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.718703032 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718714952 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.718743086 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718780994 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718786001 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.718828917 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718871117 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718880892 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.718909025 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718949080 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.718951941 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.767036915 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.769186020 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769222021 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769243956 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769265890 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769284010 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769290924 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.769304991 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769328117 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769349098 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769357920 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.769365072 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.769373894 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769412994 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.769423008 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.769488096 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.769532919 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.813895941 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.826608896 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826642036 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826664925 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826689005 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826734066 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.826750040 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826776028 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826800108 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826809883 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.826817989 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826841116 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826862097 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.826863050 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826898098 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.826910019 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.826927900 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.863271952 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.863369942 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.875900984 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.875931978 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.875997066 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876019955 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876041889 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876041889 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.876064062 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876082897 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.876086950 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876111031 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876122952 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.876132965 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876157045 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876183033 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.876200914 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.876209974 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.912503004 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.912545919 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.912643909 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.925545931 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925582886 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925605059 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925622940 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925640106 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925666094 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925684929 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.925688028 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925714970 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925721884 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.925728083 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.925733089 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.925740004 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925764084 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.925796986 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.961692095 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.961734056 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.961764097 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.975244045 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975285053 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975303888 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975327015 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975349903 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975368023 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.975373030 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975393057 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975414991 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975430012 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.975440025 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975446939 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.975505114 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975513935 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:21.975620031 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:21.975680113 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.011742115 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.011779070 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.011842966 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.026062012 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026103020 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026124001 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026140928 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026160002 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026180983 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026201010 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026221991 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026245117 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026262045 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.026267052 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026287079 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026298046 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.026307106 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.026309013 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026312113 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.026331902 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.026362896 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.061079025 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.061152935 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.065243959 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.076000929 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076056957 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076097012 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076134920 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076172113 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076191902 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.076214075 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.076219082 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076227903 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.076263905 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076302052 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076334953 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.076339006 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076375961 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076386929 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.076412916 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.076457024 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.114375114 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.114432096 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.114604950 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.127623081 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.127691984 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.127741098 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.127789974 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.127811909 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.127839088 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.127845049 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.127895117 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.127947092 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.127949953 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.127995014 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.128043890 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.128082991 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.128094912 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.128143072 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.128156900 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.128191948 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.128240108 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.128248930 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.128297091 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.128354073 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.163994074 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.164031982 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.164170980 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.178225994 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178261042 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178278923 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178303003 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178327084 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178349018 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178380013 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.178400040 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.178453922 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178463936 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.178479910 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178499937 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178519011 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178595066 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.178658009 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.178682089 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178704977 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178724051 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178746939 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178774118 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.178824902 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.178849936 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.213804007 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.213840008 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.213970900 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229209900 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229269981 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229315042 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229357004 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229382992 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229397058 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229409933 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229439974 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229489088 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229533911 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229537010 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229543924 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229577065 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229619980 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229639053 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229717970 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229758978 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229787111 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229799986 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229845047 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.229846954 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229890108 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.229979992 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.263015032 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.263047934 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.263174057 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.306135893 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.306200981 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.306248903 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.306298971 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.306351900 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.306359053 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.306385040 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:22.306397915 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:22.306446075 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:23.063931942 CEST | 49780 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:23.113169909 CEST | 80 | 49780 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:23.620450020 CEST | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:23.669929981 CEST | 80 | 49781 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:23.670125008 CEST | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:23.671128988 CEST | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:23.764269114 CEST | 80 | 49781 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:24.126127005 CEST | 80 | 49781 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:24.173518896 CEST | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:24.507015944 CEST | 80 | 49781 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:32:24.507299900 CEST | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:24.507493019 CEST | 49781 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:32:24.556721926 CEST | 80 | 49781 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:00.783740044 CEST | 49862 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:00.833882093 CEST | 80 | 49862 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:00.834063053 CEST | 49862 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:00.834180117 CEST | 49862 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:00.927697897 CEST | 80 | 49862 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:01.322679043 CEST | 80 | 49862 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:01.322864056 CEST | 49862 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:01.322945118 CEST | 49862 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:01.371798038 CEST | 80 | 49862 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:10.072343111 CEST | 49863 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:10.121365070 CEST | 80 | 49863 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:10.121700048 CEST | 49863 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:10.121752024 CEST | 49863 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:10.121759892 CEST | 49863 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:10.170469999 CEST | 80 | 49863 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:10.640894890 CEST | 80 | 49863 | 194.147.86.221 | 192.168.2.4 |
Oct 7, 2021 01:34:10.641083002 CEST | 49863 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:10.641149044 CEST | 49863 | 80 | 192.168.2.4 | 194.147.86.221 |
Oct 7, 2021 01:34:10.690242052 CEST | 80 | 49863 | 194.147.86.221 | 192.168.2.4 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 7, 2021 01:32:17.880515099 CEST | 49714 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:32:18.173275948 CEST | 53 | 49714 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:32:18.824342966 CEST | 58028 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:32:18.980140924 CEST | 53097 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:32:19.161839008 CEST | 53 | 58028 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:32:19.289130926 CEST | 53 | 53097 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:32:20.480238914 CEST | 49257 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:32:20.772708893 CEST | 53 | 49257 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:32:20.812315941 CEST | 62389 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:32:20.830039024 CEST | 53 | 62389 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:32:23.312601089 CEST | 49910 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:32:23.618545055 CEST | 53 | 49910 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:33:24.333306074 CEST | 64078 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:33:24.352554083 CEST | 53 | 64078 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:33:24.362245083 CEST | 64079 | 53 | 192.168.2.4 | 208.67.222.222 |
Oct 7, 2021 01:33:24.379193068 CEST | 53 | 64079 | 208.67.222.222 | 192.168.2.4 |
Oct 7, 2021 01:33:24.381411076 CEST | 64080 | 53 | 192.168.2.4 | 208.67.222.222 |
Oct 7, 2021 01:33:24.399873972 CEST | 53 | 64080 | 208.67.222.222 | 192.168.2.4 |
Oct 7, 2021 01:33:24.429609060 CEST | 64081 | 53 | 192.168.2.4 | 208.67.222.222 |
Oct 7, 2021 01:33:24.448523998 CEST | 53 | 64081 | 208.67.222.222 | 192.168.2.4 |
Oct 7, 2021 01:34:00.486257076 CEST | 51255 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:34:00.780658960 CEST | 53 | 51255 | 8.8.8.8 | 192.168.2.4 |
Oct 7, 2021 01:34:09.717750072 CEST | 61522 | 53 | 192.168.2.4 | 8.8.8.8 |
Oct 7, 2021 01:34:10.070925951 CEST | 53 | 61522 | 8.8.8.8 | 192.168.2.4 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Oct 7, 2021 01:32:17.880515099 CEST | 192.168.2.4 | 8.8.8.8 | 0x2a0e | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:32:18.824342966 CEST | 192.168.2.4 | 8.8.8.8 | 0x4731 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:32:18.980140924 CEST | 192.168.2.4 | 8.8.8.8 | 0xa7a5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:32:20.480238914 CEST | 192.168.2.4 | 8.8.8.8 | 0x46cb | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:32:20.812315941 CEST | 192.168.2.4 | 8.8.8.8 | 0x2650 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:32:23.312601089 CEST | 192.168.2.4 | 8.8.8.8 | 0x5791 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:33:24.333306074 CEST | 192.168.2.4 | 8.8.8.8 | 0xb091 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:33:24.362245083 CEST | 192.168.2.4 | 208.67.222.222 | 0x1 | Standard query (0) | PTR (Pointer record) | IN (0x0001) | |
Oct 7, 2021 01:33:24.381411076 CEST | 192.168.2.4 | 208.67.222.222 | 0x2 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:33:24.429609060 CEST | 192.168.2.4 | 208.67.222.222 | 0x3 | Standard query (0) | 28 | IN (0x0001) | |
Oct 7, 2021 01:34:00.486257076 CEST | 192.168.2.4 | 8.8.8.8 | 0x70a8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 7, 2021 01:34:09.717750072 CEST | 192.168.2.4 | 8.8.8.8 | 0x75b | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Oct 7, 2021 01:32:18.173275948 CEST | 8.8.8.8 | 192.168.2.4 | 0x2a0e | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:32:19.161839008 CEST | 8.8.8.8 | 192.168.2.4 | 0x4731 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:32:19.289130926 CEST | 8.8.8.8 | 192.168.2.4 | 0xa7a5 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:32:20.772708893 CEST | 8.8.8.8 | 192.168.2.4 | 0x46cb | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:32:20.830039024 CEST | 8.8.8.8 | 192.168.2.4 | 0x2650 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:32:23.618545055 CEST | 8.8.8.8 | 192.168.2.4 | 0x5791 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:33:24.352554083 CEST | 8.8.8.8 | 192.168.2.4 | 0xb091 | No error (0) | 208.67.222.222 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:33:24.379193068 CEST | 208.67.222.222 | 192.168.2.4 | 0x1 | No error (0) | PTR (Pointer record) | IN (0x0001) | |||
Oct 7, 2021 01:33:24.379193068 CEST | 208.67.222.222 | 192.168.2.4 | 0x1 | No error (0) | PTR (Pointer record) | IN (0x0001) | |||
Oct 7, 2021 01:33:24.379193068 CEST | 208.67.222.222 | 192.168.2.4 | 0x1 | No error (0) | PTR (Pointer record) | IN (0x0001) | |||
Oct 7, 2021 01:33:24.399873972 CEST | 208.67.222.222 | 192.168.2.4 | 0x2 | No error (0) | 102.129.143.57 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:34:00.780658960 CEST | 8.8.8.8 | 192.168.2.4 | 0x70a8 | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) | ||
Oct 7, 2021 01:34:10.070925951 CEST | 8.8.8.8 | 192.168.2.4 | 0x75b | No error (0) | 194.147.86.221 | A (IP address) | IN (0x0001) |
HTTP Request Dependency Graph |
---|
|
HTTP Packets |
---|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.4 | 49776 | 194.147.86.221 | 80 | C:\Windows\System32\loaddll32.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Oct 7, 2021 01:32:18.233037949 CEST | 1596 | OUT | |
Oct 7, 2021 01:32:18.712804079 CEST | 1597 | IN |