Windows Analysis Report LFEs2N6DU4.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: NanoCore |
---|
{"Version": "1.2.2.0", "Mutex": "9845a945-f2ff-4e93-b909-aece664d", "Group": "J", "Domain1": "cloudhost.myfirewall.org", "Domain2": "cloudhost.myfirewall.org", "Port": 5654, "KeyboardLogging": "Enable", "RunOnStartup": "Enable", "RequestElevation": "Disable", "BypassUAC": "Enable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "cloudhost.myfirewall.org", "BypassUserAccountControlData": "<?xml version=\"1.0\" encoding=\"UTF-16\"?>\r\n<Task version=\"1.2\" xmlns=\"http://schemas.microsoft.com/windows/2004/02/mit/task\">\r\n <RegistrationInfo />\r\n <Triggers />\r\n <Principals>\r\n <Principal id=\"Author\">\r\n <LogonType>InteractiveToken</LogonType>\r\n <RunLevel>HighestAvailable</RunLevel>\r\n </Principal>\r\n </Principals>\r\n <Settings>\r\n <MultipleInstancesPolicy>Parallel</MultipleInstancesPolicy>\r\n <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>\r\n <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>\r\n <AllowHardTerminate>true</AllowHardTerminate>\r\n <StartWhenAvailable>false</StartWhenAvailable>\r\n <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>\r\n <IdleSettings>\r\n <StopOnIdleEnd>false</StopOnIdleEnd>\r\n <RestartOnIdle>false</RestartOnIdle>\r\n </IdleSettings>\r\n <AllowStartOnDemand>true</AllowStartOnDemand>\r\n <Enabled>true</Enabled>\r\n <Hidden>false</Hidden>\r\n <RunOnlyIfIdle>false</RunOnlyIfIdle>\r\n <WakeToRun>false</WakeToRun>\r\n <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>\r\n <Priority>4</Priority>\r\n </Settings>\r\n <Actions Context=\"Author\">\r\n <Exec>\r\n <Command>\"#EXECUTABLEPATH\"</Command>\r\n <Arguments>$(Arg0)</Arguments>\r\n </Exec>\r\n </Actions>\r\n</Task"}
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> |
| |
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> |
| |
Click to see the 83 entries |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth |
| |
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth |
| |
Click to see the 198 entries |
Sigma Overview |
---|
AV Detection: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
E-Banking Fraud: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
Stealing of Sensitive Information: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
Remote Access Functionality: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link |
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: |
Networking: |
---|
C2 URLs / IPs found in malware configuration | Show sources |
Source: | URLs: |
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary or memory string: |
E-Banking Fraud: |
---|
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary: |
---|
Malicious sample detected (through community Yara rule) | Show sources |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 1_2_022719E2 | |
Source: | Code function: | 1_2_02273B0C | |
Source: | Code function: | 1_2_02272B5B | |
Source: | Code function: | 1_2_02274B88 | |
Source: | Code function: | 1_2_02272178 | |
Source: | Code function: | 1_2_02272188 | |
Source: | Code function: | 1_2_02274621 | |
Source: | Code function: | 1_2_0227267E | |
Source: | Code function: | 1_2_0227267E | |
Source: | Code function: | 1_2_022726BA | |
Source: | Code function: | 1_2_022726E9 | |
Source: | Code function: | 1_2_022726D6 | |
Source: | Code function: | 1_2_02272722 | |
Source: | Code function: | 1_2_0227273A | |
Source: | Code function: | 1_2_02272703 | |
Source: | Code function: | 1_2_02272767 | |
Source: | Code function: | 1_2_0227277F | |
Source: | Code function: | 1_2_02273D8B | |
Source: | Code function: | 13_2_02D8E480 | |
Source: | Code function: | 13_2_02D8E471 | |
Source: | Code function: | 13_2_02D8BBD4 | |
Source: | Code function: | 13_2_069E0040 | |
Source: | Code function: | 21_2_026A19E2 | |
Source: | Code function: | 21_2_026A2188 | |
Source: | Code function: | 21_2_026A2180 | |
Source: | Code function: | 22_2_029419E2 | |
Source: | Code function: | 22_2_02944B88 | |
Source: | Code function: | 22_2_02942188 | |
Source: | Code function: | 22_2_02942178 | |
Source: | Code function: | 22_2_029447AD | |
Source: | Code function: | 24_2_055FE471 | |
Source: | Code function: | 24_2_055FE480 | |
Source: | Code function: | 24_2_055FBBD4 | |
Source: | Code function: | 25_2_0122E471 | |
Source: | Code function: | 25_2_0122E480 | |
Source: | Code function: | 25_2_0122BBD4 | |
Source: | Code function: | 26_2_0228E471 | |
Source: | Code function: | 26_2_0228E480 | |
Source: | Code function: | 26_2_0228BBD4 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Data Obfuscation: |
---|
.NET source code contains potential unpacker | Show sources |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4B40 | |
Source: | Code function: | 21_2_026A4B4C | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4B40 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4698 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 21_2_026A4638 | |
Source: | Code function: | 22_2_0294E014 | |
Source: | Code function: | 22_2_0294AFA4 | |
Source: | Code function: | 22_2_0294DFF4 | |
Source: | Code function: | 22_2_0294E4D4 |
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival: |
---|
Uses schtasks.exe or at.exe to add and modify task schedules | Show sources |
Source: | Process created: |
Hooking and other Techniques for Hiding and Protection: |
---|
Hides that the sample has been downloaded from the Internet (zone.identifier) | Show sources |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion: |
---|
Writes to foreign memory regions | Show sources |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Allocates memory in foreign processes | Show sources |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Injects a PE file into a foreign processes | Show sources |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information: |
---|
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality: |
---|
Detected Nanocore Rat | Show sources |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Scheduled Task/Job1 | Scheduled Task/Job1 | Process Injection312 | Masquerading2 | Input Capture11 | Security Software Discovery1 | Remote Services | Input Capture11 | Exfiltration Over Other Network Medium | Encrypted Channel11 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Scheduled Task/Job1 | Disable or Modify Tools1 | LSASS Memory | Process Discovery2 | Remote Desktop Protocol | Archive Collected Data11 | Exfiltration Over Bluetooth | Non-Standard Port1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Virtualization/Sandbox Evasion21 | Security Account Manager | Virtualization/Sandbox Evasion21 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Remote Access Software1 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Process Injection312 | NTDS | Application Window Discovery1 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Ingress Tool Transfer1 | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Deobfuscate/Decode Files or Information1 | LSA Secrets | Remote System Discovery1 | SSH | Keylogging | Data Transfer Size Limits | Non-Application Layer Protocol2 | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | Hidden Files and Directories1 | Cached Domain Credentials | System Information Discovery12 | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Application Layer Protocol13 | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Obfuscated Files or Information1 | DCSync | Network Sniffing | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | Software Packing11 | Proc Filesystem | Network Service Scanning | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue | |
Exploit Public-Facing Application | PowerShell | At (Linux) | At (Linux) | Timestomp1 | /etc/passwd and /etc/shadow | System Network Connections Discovery | Software Deployment Tools | Data Staged | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Web Protocols | Rogue Cellular Base Station | Data Destruction |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Virustotal | Browse |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | HEUR/AGEN.1131827 | Download File | ||
100% | Avira | TR/NanoCore.fadte | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File |
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cloudhost.myfirewall.org | 91.121.250.249 | true | true | unknown | |
store2.gofile.io | 31.14.69.10 | true | false | high |
Contacted URLs |
---|
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
Contacted IPs |
---|
General Information |
---|
Joe Sandbox Version: | 33.0.0 White Diamond |
Analysis ID: | 502379 |
Start date: | 13.10.2021 |
Start time: | 21:01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 13m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | LFEs2N6DU4.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 35 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@18/12@26/3 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
21:02:27 | API Interceptor | |
21:02:32 | Task Scheduler | |
21:02:33 | Autostart | |
21:02:35 | Task Scheduler | |
21:03:03 | API Interceptor |
Joe Sandbox View / Context |
---|
IPs |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
91.121.250.249 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Domains |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
cloudhost.myfirewall.org | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
OVHFR | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
LINKER-ASFR | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
Process: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 5.713207310454996 |
Encrypted: | false |
SSDEEP: | 192:RylWethV1SLBdCYpy/zFkKt7QqMT0U2/JT0JN7Kae6b4vT:RYWetP1SLuhk6snT0UUKN7Kj |
MD5: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
SHA1: | 112314D871226E07180BF2D0A2852120CBC1399F |
SHA-256: | 799A0831A87F80DDCED683CF26C082C58C936A1BB868DD0E97552A9F035BA4EE |
SHA-512: | 319AA0970867EC79FB9C6B5F90D8D276EAB4E59A7DFD6DEAB30C15F90651B80EA409C57F0FDC8E0E23EEAC0621AF0312CB0A4206F80E2F5E22D63B48AB7DDC57 |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\LFEs2N6DU4.exe |
File Type: | |
Category: | modified |
Size (bytes): | 847 |
Entropy (8bit): | 5.35816127824051 |
Encrypted: | false |
SSDEEP: | 24:ML9E4Ks2wKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7a:MxHKXwYHKhQnoPtHoxHhAHKzva |
MD5: | 31E089E21A2AEB18A2A23D3E61EB2167 |
SHA1: | E873A8FC023D1C6D767A0C752582E3C9FD67A8B0 |
SHA-256: | 2DCCE5D76F242AF36DB3D670C006468BEEA4C58A6814B2684FE44D45E7A3F836 |
SHA-512: | A0DB65C3E133856C0A73990AEC30B1B037EA486B44E4A30657DD5775880FB9248D9E1CB533420299D0538882E9A883BA64F30F7263EB0DD62D1C673E7DBA881D |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
File Type: | |
Category: | modified |
Size (bytes): | 847 |
Entropy (8bit): | 5.35816127824051 |
Encrypted: | false |
SSDEEP: | 24:ML9E4Ks2wKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7a:MxHKXwYHKhQnoPtHoxHhAHKzva |
MD5: | 31E089E21A2AEB18A2A23D3E61EB2167 |
SHA1: | E873A8FC023D1C6D767A0C752582E3C9FD67A8B0 |
SHA-256: | 2DCCE5D76F242AF36DB3D670C006468BEEA4C58A6814B2684FE44D45E7A3F836 |
SHA-512: | A0DB65C3E133856C0A73990AEC30B1B037EA486B44E4A30657DD5775880FB9248D9E1CB533420299D0538882E9A883BA64F30F7263EB0DD62D1C673E7DBA881D |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\LFEs2N6DU4.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 5.713207310454996 |
Encrypted: | false |
SSDEEP: | 192:RylWethV1SLBdCYpy/zFkKt7QqMT0U2/JT0JN7Kae6b4vT:RYWetP1SLuhk6snT0UUKN7Kj |
MD5: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
SHA1: | 112314D871226E07180BF2D0A2852120CBC1399F |
SHA-256: | 799A0831A87F80DDCED683CF26C082C58C936A1BB868DD0E97552A9F035BA4EE |
SHA-512: | 319AA0970867EC79FB9C6B5F90D8D276EAB4E59A7DFD6DEAB30C15F90651B80EA409C57F0FDC8E0E23EEAC0621AF0312CB0A4206F80E2F5E22D63B48AB7DDC57 |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\LFEs2N6DU4.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 5.713207310454996 |
Encrypted: | false |
SSDEEP: | 192:RylWethV1SLBdCYpy/zFkKt7QqMT0U2/JT0JN7Kae6b4vT:RYWetP1SLuhk6snT0UUKN7Kj |
MD5: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
SHA1: | 112314D871226E07180BF2D0A2852120CBC1399F |
SHA-256: | 799A0831A87F80DDCED683CF26C082C58C936A1BB868DD0E97552A9F035BA4EE |
SHA-512: | 319AA0970867EC79FB9C6B5F90D8D276EAB4E59A7DFD6DEAB30C15F90651B80EA409C57F0FDC8E0E23EEAC0621AF0312CB0A4206F80E2F5E22D63B48AB7DDC57 |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1315 |
Entropy (8bit): | 5.120413096534581 |
Encrypted: | false |
SSDEEP: | 24:2dH4+S/4oL600QlMhEMjn5pwjVLUYODOLG9RJh7h8gK0lR8xtn:cbk4oL600QydbQxIYODOLedq3qR8j |
MD5: | 0C10D650882D4A09257AF2C0D57880DE |
SHA1: | 440A4AFE21E983131E157010784C9F4ABABCDBED |
SHA-256: | 52537FE98CA5F2009CF8F41EB7AAD8E12913EB6C50CE21B5888BB2F0AB1BCD58 |
SHA-512: | EBCACB7799826E7610E897AB9DB119DDD751C5DE30A6C32A3E2814C03479644F3CF86274AD52BD349BC8526B05F26F8185F31BAD4DBB853AE9AB2902D622DA5F |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
File Type: | |
Category: | modified |
Size (bytes): | 1310 |
Entropy (8bit): | 5.109425792877704 |
Encrypted: | false |
SSDEEP: | 24:2dH4+S/4oL600QlMhEMjn5pwjVLUYODOLG9RJh7h8gK0R3xtn:cbk4oL600QydbQxIYODOLedq3S3j |
MD5: | 5C2F41CFC6F988C859DA7D727AC2B62A |
SHA1: | 68999C85FC7E37BAB9216E0099836D40D4545C1C |
SHA-256: | 98B6E66B6C2173B9B91FC97FE51805340EFDE978B695453742EBAB631018398B |
SHA-512: | B5DA5DA378D038AFBF8A7738E47921ED39F9B726E2CAA2993D915D9291A3322F94EFE8CCA6E7AD678A670DB19926B22B20E5028460FCC89CEA7F6635E7557334 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8 |
Entropy (8bit): | 3.0 |
Encrypted: | false |
SSDEEP: | 3:4ot:Z |
MD5: | 899164DAF8349F673139B6C19C768F8C |
SHA1: | BF14995E98D1EDCA60FADB7464DBE3B96F236A03 |
SHA-256: | 562708312FBE0DC6E4D85E89DB03152C0C6F18EA4E37F89476986632F58E0C58 |
SHA-512: | 600831A14C5647E15FFD62E09323CD23243A7389F46372C1F5DF991CCE4379B086F335D165E969240BFC1FCFEE30B24FD913F0E92B4D75596DC6E43A382C9921 |
Malicious: | true |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 52 |
Entropy (8bit): | 4.611416824235501 |
Encrypted: | false |
SSDEEP: | 3:oN0nacwRE2J5xAIYt4A:oNcNwi23fpA |
MD5: | 2C569CD29074C38A4C89BFE53A83613A |
SHA1: | 032F40E0C7AEC8234604CCEF6FCF695E45D315F0 |
SHA-256: | B211D73206C466856EB91A61CE6DEFD0DEBF44C58F2066F3B6270F3315D61057 |
SHA-512: | F9DF17047992E5D6A9459D6E002D98F8C10278102DF0FE32E4456E2660546BCA1370A230643C9732E7CB9AF2CCAC2DE95584D8F0BD123B669D13388E84BD98BB |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 5.713207310454996 |
TrID: |
|
File name: | LFEs2N6DU4.exe |
File size: | 12288 |
MD5: | 5b3262b61a5eaa3ebe7e8bdc4958fc3f |
SHA1: | 112314d871226e07180bf2d0a2852120cbc1399f |
SHA256: | 799a0831a87f80ddced683cf26c082c58c936a1bb868dd0e97552a9f035ba4ee |
SHA512: | 319aa0970867ec79fb9c6b5f90d8d276eab4e59a7dfd6deab30c15f90651b80ea409c57f0fdc8e0e23eeac0621af0312cb0a4206f80e2f5e22d63b48ab7ddc57 |
SSDEEP: | 192:RylWethV1SLBdCYpy/zFkKt7QqMT0U2/JT0JN7Kae6b4vT:RYWetP1SLuhk6snT0UUKN7Kj |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...(.................0..............5... ...@....@.. ....................................@................................ |
File Icon |
---|
Icon Hash: | 8e65656565a5a580 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x40351a |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | 32BIT_MACHINE, EXECUTABLE_IMAGE |
DLL Characteristics: | NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0xE6EFFE28 [Fri Oct 10 14:37:28 2092 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | v4.0.30319 |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Entrypoint Preview |
---|
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x34c8 | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4000 | 0x1464 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x34ac | 0x1c | .text |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x1520 | 0x1600 | False | 0.545276988636 | data | 5.38661650822 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rsrc | 0x4000 | 0x1464 | 0x1600 | False | 0.485440340909 | data | 5.87422786796 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x6000 | 0xc | 0x200 | False | 0.044921875 | data | 0.0815394123432 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x4100 | 0xd90 | data | ||
RT_GROUP_ICON | 0x4ea0 | 0x14 | data | ||
RT_VERSION | 0x4ec4 | 0x39e | data | ||
RT_MANIFEST | 0x5274 | 0x1ea | XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
Imports |
---|
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Version Infos |
---|
Description | Data |
---|---|
Translation | 0x0000 0x04b0 |
LegalCopyright | Copyright (c) 2021, Spotify Ltd |
Assembly Version | 1.1.68.632 |
InternalName | ConsoleApp5NW.exe |
FileVersion | 1.1.68.632 |
CompanyName | Spotify Ltd |
LegalTrademarks | |
Comments | SpotifyInstaller |
ProductName | Spotify |
ProductVersion | 1.1.68.632 |
FileDescription | SpotifyInstaller |
OriginalFilename | ConsoleApp5NW.exe |
Network Behavior |
---|
Snort IDS Alerts |
---|
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
10/13/21-21:02:34.210507 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 56590 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:02:40.001530 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 60501 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:02:45.903541 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 53775 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:02:51.066340 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 63668 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:03:01.665621 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 58717 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:03:34.130301 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 56680 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:03:44.820855 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 60983 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:04:01.242821 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 56064 | 8.8.8.8 | 192.168.2.7 |
10/13/21-21:04:21.984507 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 59571 | 8.8.8.8 | 192.168.2.7 |
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 13, 2021 21:02:24.657881021 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:24.657932997 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:24.658039093 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:24.689141989 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:24.689177036 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:24.826816082 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:24.826991081 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:24.832894087 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:24.832907915 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:24.833211899 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:24.876107931 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.270358086 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.311141968 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.329694986 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.329758883 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.329854012 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.329864025 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.329888105 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.329906940 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.329929113 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.355918884 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.355988026 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.356017113 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.356040001 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.356138945 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.356142998 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.356162071 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.356173038 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.356275082 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.356288910 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.380943060 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.380958080 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381016016 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381119013 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.381119967 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381131887 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381160975 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381191015 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381238937 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.381253958 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381302118 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.381359100 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.381583929 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381593943 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381637096 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381673098 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.381681919 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.381726027 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.381962061 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.382011890 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.382024050 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.382049084 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.382061005 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.382111073 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.409518003 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.409564972 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.409666061 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.409691095 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.409714937 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.409738064 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.409785986 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.409790993 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.409955978 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.409977913 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410020113 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410034895 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410034895 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.410064936 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410111904 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.410418034 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410464048 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410481930 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410523891 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.410537958 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410552025 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410685062 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410726070 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410732031 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.410751104 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410775900 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.410784006 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.410851002 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.411103010 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.411181927 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.411200047 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.411214113 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.411282063 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.436821938 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.436862946 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.436955929 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437098026 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437118053 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437218904 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437248945 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437254906 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437262058 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437309027 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437375069 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437437057 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437462091 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437585115 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437592983 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437640905 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437680006 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437707901 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437755108 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437761068 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437794924 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437825918 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437871933 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437906981 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.437907934 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437958956 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.437966108 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438019037 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438097954 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438124895 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438203096 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438211918 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438304901 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438316107 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438322067 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438345909 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438374043 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438380003 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438416004 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438446045 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438460112 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438488960 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438524008 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438529015 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438623905 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438666105 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438692093 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438786030 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.438791990 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.438853979 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.439312935 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.492650032 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.492685080 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.492765903 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.492882013 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.492898941 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.493210077 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.493223906 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.493238926 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.496617079 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.496638060 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.496674061 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.496685028 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.496826887 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.496834993 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.496848106 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.496889114 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.497081995 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.497091055 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.497104883 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.497109890 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.497251034 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.497260094 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.497279882 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.497344017 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.497930050 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.497947931 CEST | 443 | 49743 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:25.498078108 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.498236895 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.499207973 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:25.527590990 CEST | 49743 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:34.220346928 CEST | 49746 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:34.244812965 CEST | 5654 | 49746 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:34.752038002 CEST | 49746 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:34.776576042 CEST | 5654 | 49746 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:35.277117968 CEST | 49746 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:35.301716089 CEST | 5654 | 49746 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:40.048461914 CEST | 49747 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:40.096297026 CEST | 5654 | 49747 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:40.596216917 CEST | 49747 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:40.621658087 CEST | 5654 | 49747 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:41.127537966 CEST | 49747 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:41.152491093 CEST | 5654 | 49747 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:45.906117916 CEST | 49748 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:45.931962013 CEST | 5654 | 49748 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:46.440453053 CEST | 49748 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:46.466202021 CEST | 5654 | 49748 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:46.971816063 CEST | 49748 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:46.997580051 CEST | 5654 | 49748 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:51.078059912 CEST | 49751 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:51.102807045 CEST | 5654 | 49751 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:51.613003969 CEST | 49751 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:51.638070107 CEST | 5654 | 49751 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:52.144125938 CEST | 49751 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:52.203167915 CEST | 5654 | 49751 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:53.277070999 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:53.277126074 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:53.278618097 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:53.371022940 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:53.371052027 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:53.481673956 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:53.481792927 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:53.489447117 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:53.489468098 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:53.489778042 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:53.534780025 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.091325998 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.139137983 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.165416956 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.165471077 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.165532112 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.165633917 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.165855885 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.165872097 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.165942907 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.165950060 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190500975 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190527916 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190591097 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190598965 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190603971 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.190639973 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190660954 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190669060 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190671921 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.190696955 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.190701962 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190720081 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190737963 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.190738916 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190751076 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190774918 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.190785885 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.190800905 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.190834999 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.215847015 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.215867996 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.215929031 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.215974092 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.215991020 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.216020107 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.216032028 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.216043949 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.216053009 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.216084003 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.216093063 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.216140985 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.216296911 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.216334105 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.216355085 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.216367006 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.216397047 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.241724014 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.241765976 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.241813898 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.241861105 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.241871119 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.241954088 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.241962910 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242213011 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242214918 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242234945 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242280006 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242292881 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242305040 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242368937 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242368937 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242387056 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242429972 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242472887 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242496014 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242547989 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242561102 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242572069 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242602110 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242743015 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242764950 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242815971 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242831945 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242857933 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242886066 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.242969036 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.242993116 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.243035078 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.243046999 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.243129969 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.243257999 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.243263006 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.268558979 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.268609047 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.268734932 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.268750906 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.268796921 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.268810034 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.268827915 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.268848896 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.268867970 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.268882990 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.268893003 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.268922091 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269169092 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269201994 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269238949 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269254923 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269272089 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269301891 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269386053 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269413948 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269447088 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269459009 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269489050 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269510031 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269757986 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269790888 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269851923 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269866943 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.269893885 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.269915104 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270011902 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270040989 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270092964 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270103931 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270155907 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270279884 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270308018 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270359993 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270370007 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270427942 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270591974 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270621061 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270628929 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270663023 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270673037 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270714045 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270735979 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270823002 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270833969 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270867109 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270896912 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270905972 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.270939112 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.270965099 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.271343946 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.318907022 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.318947077 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.319008112 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.319026947 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.319061041 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.319084883 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.320648909 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.320702076 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.320873022 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.320894957 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.320959091 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.322654963 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.322690964 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.322882891 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.322897911 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.322988987 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323349953 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323384047 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323463917 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323489904 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323533058 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323548079 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323564053 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323570967 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323600054 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323610067 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323616982 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323641062 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323649883 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323710918 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323724985 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323739052 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323800087 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323808908 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323854923 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323864937 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323885918 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.323906898 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.323924065 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324039936 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324055910 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324069977 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324075937 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324116945 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324153900 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324168921 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324212074 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324224949 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324254036 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324265003 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324275017 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324311972 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324359894 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324389935 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324399948 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324440002 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324445963 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324465990 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324477911 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324518919 CEST | 443 | 49752 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:54.324522972 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.324563980 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.327204943 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.327438116 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:54.330910921 CEST | 49752 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:55.529289007 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:55.529331923 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:55.531011105 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:55.579828024 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:55.579857111 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:55.685437918 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:55.685940027 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:55.692708015 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:55.692733049 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:55.693147898 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:55.738137960 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.306122065 CEST | 49754 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:56.312243938 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.331244946 CEST | 5654 | 49754 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:56.355151892 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.429431915 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.429495096 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.429559946 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.429572105 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.429589033 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.429608107 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.429775953 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.454406977 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454423904 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454499006 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454509974 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454514027 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.454562902 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.454561949 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454591990 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454603910 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454647064 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454662085 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.454673052 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.454725027 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.479573011 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.479592085 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.479677916 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.479713917 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.479722023 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.479732990 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.479799032 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.479804039 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.479860067 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.479866028 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.479919910 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.479924917 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.480009079 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.480014086 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.480078936 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.480117083 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.480190039 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.480190992 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.480214119 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.480283976 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.505281925 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505316019 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505352020 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505471945 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.505486012 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505821943 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505847931 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505907059 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.505917072 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505939007 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.505959988 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.505984068 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506036997 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506046057 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506066084 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506205082 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506230116 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506268024 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506274939 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506302118 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506390095 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506408930 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506448984 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506455898 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506481886 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506570101 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506591082 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506638050 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506647110 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.506684065 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.506809950 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.507028103 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.530339956 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.530376911 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.530584097 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.530600071 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.531696081 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.531725883 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.531776905 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.531789064 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.531814098 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.531816006 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.531843901 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.531951904 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.531971931 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.531984091 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532015085 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532160997 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532203913 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532211065 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532238007 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532269001 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532613039 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532641888 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532706022 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532713890 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532731056 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532742977 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532761097 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532772064 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532778025 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532831907 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532861948 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532871962 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532881021 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532883883 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532917976 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532924891 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532958031 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532960892 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.532974958 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.532995939 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533027887 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533162117 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533169985 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.533204079 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.533240080 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533246040 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.533273935 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533292055 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533324957 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.533353090 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.533392906 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533400059 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.533428907 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533557892 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.533576965 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.534195900 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.580899954 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.580929041 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.580997944 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581048012 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581069946 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581104040 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581114054 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581125021 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581144094 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581151962 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581161022 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581197977 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581207991 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581238031 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581244946 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581264019 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581276894 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581293106 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581336975 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581346989 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581367016 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581371069 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581389904 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581435919 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581454039 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581463099 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581466913 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581478119 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581486940 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581521034 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581532001 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581548929 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581556082 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581568003 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581625938 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581636906 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581656933 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581676960 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581682920 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581707001 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581717014 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581744909 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581747055 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581773043 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581796885 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581809044 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581818104 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581842899 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581871033 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581875086 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581885099 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.581898928 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581929922 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.581942081 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.582040071 CEST | 443 | 49753 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:02:56.582104921 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.582259893 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.582715988 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.619626999 CEST | 49753 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:02:56.831954956 CEST | 49754 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:56.855954885 CEST | 5654 | 49754 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:02:57.364207029 CEST | 49754 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:02:57.388421059 CEST | 5654 | 49754 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:01.667103052 CEST | 49755 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:01.691617966 CEST | 5654 | 49755 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:02.223058939 CEST | 49755 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:02.247492075 CEST | 5654 | 49755 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:02.655133963 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:02.655174971 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:02.655782938 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:02.709825039 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:02.709851980 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:02.821751118 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:02.821996927 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:02.825814962 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:02.825830936 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:02.826100111 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:02.910600901 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:02.926256895 CEST | 49755 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:02.950906992 CEST | 5654 | 49755 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:03.655570984 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.705199957 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.708009958 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.708061934 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.708133936 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.708142996 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.710848093 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.710865974 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733411074 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733629942 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.733649015 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733666897 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733674049 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733738899 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733751059 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733772993 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733798027 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733807087 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733819008 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.733825922 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733840942 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.733851910 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.733869076 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.734188080 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.759804010 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.759829044 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.759854078 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.759900093 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.759912014 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.759932995 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.759947062 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.759959936 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760019064 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.760030985 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760035038 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.760037899 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.760056019 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760066986 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760080099 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760097980 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760130882 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.760284901 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760330915 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760360956 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760411024 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.760436058 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.760448933 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.760464907 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.761018038 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.785634041 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.785712957 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.785758972 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.785907984 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.785973072 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.786005020 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.786005974 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.786171913 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.786252022 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.786262035 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.786284924 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.786520004 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.786546946 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.786681890 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.786906004 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.786974907 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.786994934 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.787000895 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.787239075 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.787272930 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.787435055 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.787461996 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.787466049 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.812833071 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.812961102 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813003063 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813014030 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813069105 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813097954 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813138962 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813163042 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813167095 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813184977 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813251019 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813270092 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813308001 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813318968 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813380003 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813405991 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813432932 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813446999 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813461065 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813530922 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813536882 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813570976 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813599110 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813654900 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813664913 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813687086 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813832998 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813865900 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.813957930 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.813991070 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814120054 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814239979 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814250946 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814275026 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814285994 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814289093 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814305067 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814444065 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814554930 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814599037 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814603090 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814605951 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814620018 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814676046 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814693928 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814724922 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814733982 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.814908981 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814922094 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.814935923 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.815830946 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.866449118 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.866487026 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.866575003 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.872616053 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.872636080 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.872653008 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.872661114 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.873034000 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.873061895 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.873085022 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.873758078 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.873785973 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.873806953 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874022961 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874030113 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.874154091 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874219894 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.874237061 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.874238968 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874324083 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874356031 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.874402046 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874468088 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874469995 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.874516964 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874572992 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874589920 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.874675989 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874767065 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.874783039 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.874794006 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.875080109 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.890739918 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.891047955 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.891402960 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.891412973 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.891870975 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.892239094 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.892363071 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.892375946 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.892405033 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.892478943 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.892488003 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.892518997 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.892580986 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.892587900 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.892627001 CEST | 443 | 49756 | 31.14.69.10 | 192.168.2.7 |
Oct 13, 2021 21:03:03.893508911 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:03.894634962 CEST | 49756 | 443 | 192.168.2.7 | 31.14.69.10 |
Oct 13, 2021 21:03:07.201564074 CEST | 49759 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:07.225709915 CEST | 5654 | 49759 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:07.911040068 CEST | 49759 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:07.935085058 CEST | 5654 | 49759 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:08.573791981 CEST | 49759 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:08.597723961 CEST | 5654 | 49759 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:12.777347088 CEST | 49760 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:12.805039883 CEST | 5654 | 49760 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:13.411492109 CEST | 49760 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:13.435965061 CEST | 5654 | 49760 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:14.099096060 CEST | 49760 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:14.123533010 CEST | 5654 | 49760 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:18.323560953 CEST | 49764 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:18.348481894 CEST | 5654 | 49764 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:18.943218946 CEST | 49764 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:18.967612982 CEST | 5654 | 49764 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:19.521384954 CEST | 49764 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:19.546010971 CEST | 5654 | 49764 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:23.708355904 CEST | 49779 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:23.732486963 CEST | 5654 | 49779 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:24.240542889 CEST | 49779 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:24.264689922 CEST | 5654 | 49779 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:24.771810055 CEST | 49779 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:24.795767069 CEST | 5654 | 49779 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:28.953540087 CEST | 49810 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:28.978466034 CEST | 5654 | 49810 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:29.490978956 CEST | 49810 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:29.517795086 CEST | 5654 | 49810 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:30.022308111 CEST | 49810 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:30.046689034 CEST | 5654 | 49810 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:34.131402016 CEST | 49814 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:34.156387091 CEST | 5654 | 49814 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:34.663469076 CEST | 49814 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:34.688374996 CEST | 5654 | 49814 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:35.194673061 CEST | 49814 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:35.219074965 CEST | 5654 | 49814 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:39.464104891 CEST | 49815 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:39.488567114 CEST | 5654 | 49815 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:40.054403067 CEST | 49815 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:40.078891039 CEST | 5654 | 49815 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:40.663734913 CEST | 49815 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:40.689657927 CEST | 5654 | 49815 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:44.822844982 CEST | 49817 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:44.847155094 CEST | 5654 | 49817 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:45.351727962 CEST | 49817 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:45.375828981 CEST | 5654 | 49817 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:45.883162022 CEST | 49817 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:45.909224033 CEST | 5654 | 49817 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:49.978811979 CEST | 49829 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:50.002938986 CEST | 5654 | 49829 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:50.508351088 CEST | 49829 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:50.532238007 CEST | 5654 | 49829 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:51.039798021 CEST | 49829 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:51.063831091 CEST | 5654 | 49829 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:55.840145111 CEST | 49853 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:55.864149094 CEST | 5654 | 49853 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:56.368325949 CEST | 49853 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:56.392358065 CEST | 5654 | 49853 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:03:56.899630070 CEST | 49853 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:03:56.923674107 CEST | 5654 | 49853 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:01.244613886 CEST | 49871 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:01.269171953 CEST | 5654 | 49871 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:01.790601015 CEST | 49871 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:01.817099094 CEST | 5654 | 49871 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:02.321880102 CEST | 49871 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:02.350661039 CEST | 5654 | 49871 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:06.450087070 CEST | 49872 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:06.474230051 CEST | 5654 | 49872 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:06.979023933 CEST | 49872 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:07.003264904 CEST | 5654 | 49872 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:07.509948015 CEST | 49872 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:07.534152985 CEST | 5654 | 49872 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:11.564399958 CEST | 49873 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:11.588505983 CEST | 5654 | 49873 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:12.088630915 CEST | 49873 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:12.112847090 CEST | 5654 | 49873 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:12.619637012 CEST | 49873 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:12.643811941 CEST | 5654 | 49873 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:16.864876032 CEST | 49876 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:16.889213085 CEST | 5654 | 49876 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:17.401254892 CEST | 49876 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:17.425281048 CEST | 5654 | 49876 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:17.932642937 CEST | 49876 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:17.956880093 CEST | 5654 | 49876 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:21.985719919 CEST | 49877 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:22.010078907 CEST | 5654 | 49877 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:22.527920961 CEST | 49877 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:22.552237988 CEST | 5654 | 49877 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:23.067786932 CEST | 49877 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:23.092309952 CEST | 5654 | 49877 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:27.124128103 CEST | 49878 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:27.148818016 CEST | 5654 | 49878 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:27.657392979 CEST | 49878 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:27.681896925 CEST | 5654 | 49878 | 91.121.250.249 | 192.168.2.7 |
Oct 13, 2021 21:04:28.205916882 CEST | 49878 | 5654 | 192.168.2.7 | 91.121.250.249 |
Oct 13, 2021 21:04:28.231285095 CEST | 5654 | 49878 | 91.121.250.249 | 192.168.2.7 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 13, 2021 21:02:24.612535954 CEST | 61242 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:24.630748034 CEST | 53 | 61242 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:02:34.187187910 CEST | 56590 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:34.210506916 CEST | 53 | 56590 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:02:39.948121071 CEST | 60501 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:40.001529932 CEST | 53 | 60501 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:02:45.880455017 CEST | 53775 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:45.903541088 CEST | 53 | 53775 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:02:51.042285919 CEST | 63668 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:51.066339970 CEST | 53 | 63668 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:02:53.222882032 CEST | 54640 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:53.241328001 CEST | 53 | 54640 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:02:55.477127075 CEST | 58739 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:55.495481968 CEST | 53 | 58739 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:02:56.288610935 CEST | 60338 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:02:56.305104971 CEST | 53 | 60338 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:01.638463020 CEST | 58717 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:01.665621042 CEST | 53 | 58717 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:02.567184925 CEST | 59762 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:02.597265959 CEST | 53 | 59762 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:07.181483030 CEST | 54329 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:07.199901104 CEST | 53 | 54329 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:12.757250071 CEST | 58052 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:12.775641918 CEST | 53 | 58052 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:18.186084032 CEST | 64569 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:18.204528093 CEST | 53 | 64569 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:23.689912081 CEST | 50452 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:23.706641912 CEST | 53 | 50452 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:28.888942957 CEST | 64296 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:28.907193899 CEST | 53 | 64296 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:34.103861094 CEST | 56680 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:34.130300999 CEST | 53 | 56680 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:39.443249941 CEST | 58820 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:39.462678909 CEST | 53 | 58820 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:44.797622919 CEST | 60983 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:44.820854902 CEST | 53 | 60983 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:49.958292007 CEST | 49247 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:49.976731062 CEST | 53 | 49247 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:03:55.820278883 CEST | 52286 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:03:55.836883068 CEST | 53 | 52286 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:04:01.210704088 CEST | 56064 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:04:01.242820978 CEST | 53 | 56064 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:04:06.401926041 CEST | 63744 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:04:06.420233011 CEST | 53 | 63744 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:04:11.545428991 CEST | 61457 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:04:11.563745022 CEST | 53 | 61457 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:04:16.845597029 CEST | 60599 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:04:16.863938093 CEST | 53 | 60599 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:04:21.960386038 CEST | 59571 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:04:21.984507084 CEST | 53 | 59571 | 8.8.8.8 | 192.168.2.7 |
Oct 13, 2021 21:04:27.102984905 CEST | 52689 | 53 | 192.168.2.7 | 8.8.8.8 |
Oct 13, 2021 21:04:27.121478081 CEST | 53 | 52689 | 8.8.8.8 | 192.168.2.7 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Oct 13, 2021 21:02:24.612535954 CEST | 192.168.2.7 | 8.8.8.8 | 0x95e9 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:02:34.187187910 CEST | 192.168.2.7 | 8.8.8.8 | 0xdc26 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:02:39.948121071 CEST | 192.168.2.7 | 8.8.8.8 | 0xfe76 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:02:45.880455017 CEST | 192.168.2.7 | 8.8.8.8 | 0x5e68 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:02:51.042285919 CEST | 192.168.2.7 | 8.8.8.8 | 0x884e | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:02:53.222882032 CEST | 192.168.2.7 | 8.8.8.8 | 0x97df | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:02:55.477127075 CEST | 192.168.2.7 | 8.8.8.8 | 0xf722 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:02:56.288610935 CEST | 192.168.2.7 | 8.8.8.8 | 0x2c4a | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:01.638463020 CEST | 192.168.2.7 | 8.8.8.8 | 0x1cfb | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:02.567184925 CEST | 192.168.2.7 | 8.8.8.8 | 0x1d61 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:07.181483030 CEST | 192.168.2.7 | 8.8.8.8 | 0x141e | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:12.757250071 CEST | 192.168.2.7 | 8.8.8.8 | 0xd297 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:18.186084032 CEST | 192.168.2.7 | 8.8.8.8 | 0x9ad1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:23.689912081 CEST | 192.168.2.7 | 8.8.8.8 | 0x6011 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:28.888942957 CEST | 192.168.2.7 | 8.8.8.8 | 0xa14a | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:34.103861094 CEST | 192.168.2.7 | 8.8.8.8 | 0x9a8a | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:39.443249941 CEST | 192.168.2.7 | 8.8.8.8 | 0x5554 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:44.797622919 CEST | 192.168.2.7 | 8.8.8.8 | 0xf5b8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:49.958292007 CEST | 192.168.2.7 | 8.8.8.8 | 0xa30f | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:03:55.820278883 CEST | 192.168.2.7 | 8.8.8.8 | 0x5aa5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:04:01.210704088 CEST | 192.168.2.7 | 8.8.8.8 | 0xbbc3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:04:06.401926041 CEST | 192.168.2.7 | 8.8.8.8 | 0x3227 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:04:11.545428991 CEST | 192.168.2.7 | 8.8.8.8 | 0x260b | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:04:16.845597029 CEST | 192.168.2.7 | 8.8.8.8 | 0x2572 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:04:21.960386038 CEST | 192.168.2.7 | 8.8.8.8 | 0x9d84 | Standard query (0) | A (IP address) | IN (0x0001) | |
Oct 13, 2021 21:04:27.102984905 CEST | 192.168.2.7 | 8.8.8.8 | 0x1b00 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Oct 13, 2021 21:02:24.630748034 CEST | 8.8.8.8 | 192.168.2.7 | 0x95e9 | No error (0) | 31.14.69.10 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:02:34.210506916 CEST | 8.8.8.8 | 192.168.2.7 | 0xdc26 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:02:40.001529932 CEST | 8.8.8.8 | 192.168.2.7 | 0xfe76 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:02:45.903541088 CEST | 8.8.8.8 | 192.168.2.7 | 0x5e68 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:02:51.066339970 CEST | 8.8.8.8 | 192.168.2.7 | 0x884e | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:02:53.241328001 CEST | 8.8.8.8 | 192.168.2.7 | 0x97df | No error (0) | 31.14.69.10 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:02:55.495481968 CEST | 8.8.8.8 | 192.168.2.7 | 0xf722 | No error (0) | 31.14.69.10 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:02:56.305104971 CEST | 8.8.8.8 | 192.168.2.7 | 0x2c4a | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:01.665621042 CEST | 8.8.8.8 | 192.168.2.7 | 0x1cfb | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:02.597265959 CEST | 8.8.8.8 | 192.168.2.7 | 0x1d61 | No error (0) | 31.14.69.10 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:07.199901104 CEST | 8.8.8.8 | 192.168.2.7 | 0x141e | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:12.775641918 CEST | 8.8.8.8 | 192.168.2.7 | 0xd297 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:18.204528093 CEST | 8.8.8.8 | 192.168.2.7 | 0x9ad1 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:23.706641912 CEST | 8.8.8.8 | 192.168.2.7 | 0x6011 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:28.907193899 CEST | 8.8.8.8 | 192.168.2.7 | 0xa14a | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:34.130300999 CEST | 8.8.8.8 | 192.168.2.7 | 0x9a8a | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:39.462678909 CEST | 8.8.8.8 | 192.168.2.7 | 0x5554 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:44.820854902 CEST | 8.8.8.8 | 192.168.2.7 | 0xf5b8 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:49.976731062 CEST | 8.8.8.8 | 192.168.2.7 | 0xa30f | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:03:55.836883068 CEST | 8.8.8.8 | 192.168.2.7 | 0x5aa5 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:04:01.242820978 CEST | 8.8.8.8 | 192.168.2.7 | 0xbbc3 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:04:06.420233011 CEST | 8.8.8.8 | 192.168.2.7 | 0x3227 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:04:11.563745022 CEST | 8.8.8.8 | 192.168.2.7 | 0x260b | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:04:16.863938093 CEST | 8.8.8.8 | 192.168.2.7 | 0x2572 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:04:21.984507084 CEST | 8.8.8.8 | 192.168.2.7 | 0x9d84 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) | ||
Oct 13, 2021 21:04:27.121478081 CEST | 8.8.8.8 | 192.168.2.7 | 0x1b00 | No error (0) | 91.121.250.249 | A (IP address) | IN (0x0001) |
HTTP Request Dependency Graph |
---|
|
HTTPS Proxied Packets |
---|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.7 | 49743 | 31.14.69.10 | 443 | C:\Users\user\Desktop\LFEs2N6DU4.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2021-10-13 19:02:25 UTC | 0 | OUT | |
2021-10-13 19:02:25 UTC | 0 | IN | |
2021-10-13 19:02:25 UTC | 0 | IN | |
2021-10-13 19:02:25 UTC | 1 | IN | |
2021-10-13 19:02:25 UTC | 3 | IN | |
2021-10-13 19:02:25 UTC | 4 | IN | |
2021-10-13 19:02:25 UTC | 8 | IN | |
2021-10-13 19:02:25 UTC | 14 | IN | |
2021-10-13 19:02:25 UTC | 21 | IN | |
2021-10-13 19:02:25 UTC | 29 | IN | |
2021-10-13 19:02:25 UTC | 38 | IN | |
2021-10-13 19:02:25 UTC | 49 | IN | |
2021-10-13 19:02:25 UTC | 53 | IN | |
2021-10-13 19:02:25 UTC | 64 | IN | |
2021-10-13 19:02:25 UTC | 78 | IN | |
2021-10-13 19:02:25 UTC | 93 | IN | |
2021-10-13 19:02:25 UTC | 96 | IN | |
2021-10-13 19:02:25 UTC | 112 | IN | |
2021-10-13 19:02:25 UTC | 128 | IN | |
2021-10-13 19:02:25 UTC | 144 | IN | |
2021-10-13 19:02:25 UTC | 160 | IN | |
2021-10-13 19:02:25 UTC | 176 | IN | |
2021-10-13 19:02:25 UTC | 192 | IN | |
2021-10-13 19:02:25 UTC | 208 | IN | |
2021-10-13 19:02:25 UTC | 224 | IN | |
2021-10-13 19:02:25 UTC | 240 | IN | |
2021-10-13 19:02:25 UTC | 256 | IN | |
2021-10-13 19:02:25 UTC | 272 | IN | |
2021-10-13 19:02:25 UTC | 288 | IN | |
2021-10-13 19:02:25 UTC | 304 | IN | |
2021-10-13 19:02:25 UTC | 320 | IN | |
2021-10-13 19:02:25 UTC | 336 | IN | |
2021-10-13 19:02:25 UTC | 352 | IN | |
2021-10-13 19:02:25 UTC | 368 | IN | |
2021-10-13 19:02:25 UTC | 384 | IN | |
2021-10-13 19:02:25 UTC | 400 | IN | |
2021-10-13 19:02:25 UTC | 416 | IN | |
2021-10-13 19:02:25 UTC | 432 | IN | |
2021-10-13 19:02:25 UTC | 448 | IN | |
2021-10-13 19:02:25 UTC | 464 | IN | |
2021-10-13 19:02:25 UTC | 480 | IN | |
2021-10-13 19:02:25 UTC | 496 | IN | |
2021-10-13 19:02:25 UTC | 512 | IN | |
2021-10-13 19:02:25 UTC | 528 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.7 | 49752 | 31.14.69.10 | 443 | C:\Users\user\Desktop\LFEs2N6DU4.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2021-10-13 19:02:54 UTC | 530 | OUT | |
2021-10-13 19:02:54 UTC | 530 | IN | |
2021-10-13 19:02:54 UTC | 530 | IN | |
2021-10-13 19:02:54 UTC | 531 | IN | |
2021-10-13 19:02:54 UTC | 533 | IN | |
2021-10-13 19:02:54 UTC | 534 | IN | |
2021-10-13 19:02:54 UTC | 538 | IN | |
2021-10-13 19:02:54 UTC | 543 | IN | |
2021-10-13 19:02:54 UTC | 550 | IN | |
2021-10-13 19:02:54 UTC | 559 | IN | |
2021-10-13 19:02:54 UTC | 566 | IN | |
2021-10-13 19:02:54 UTC | 577 | IN | |
2021-10-13 19:02:54 UTC | 588 | IN | |
2021-10-13 19:02:54 UTC | 594 | IN | |
2021-10-13 19:02:54 UTC | 608 | IN | |
2021-10-13 19:02:54 UTC | 623 | IN | |
2021-10-13 19:02:54 UTC | 626 | IN | |
2021-10-13 19:02:54 UTC | 642 | IN | |
2021-10-13 19:02:54 UTC | 658 | IN | |
2021-10-13 19:02:54 UTC | 674 | IN | |
2021-10-13 19:02:54 UTC | 690 | IN | |
2021-10-13 19:02:54 UTC | 706 | IN | |
2021-10-13 19:02:54 UTC | 722 | IN | |
2021-10-13 19:02:54 UTC | 738 | IN | |
2021-10-13 19:02:54 UTC | 754 | IN | |
2021-10-13 19:02:54 UTC | 770 | IN | |
2021-10-13 19:02:54 UTC | 786 | IN | |
2021-10-13 19:02:54 UTC | 802 | IN | |
2021-10-13 19:02:54 UTC | 818 | IN | |
2021-10-13 19:02:54 UTC | 834 | IN | |
2021-10-13 19:02:54 UTC | 850 | IN | |
2021-10-13 19:02:54 UTC | 866 | IN | |
2021-10-13 19:02:54 UTC | 882 | IN | |
2021-10-13 19:02:54 UTC | 898 | IN | |
2021-10-13 19:02:54 UTC | 914 | IN | |
2021-10-13 19:02:54 UTC | 930 | IN | |
2021-10-13 19:02:54 UTC | 946 | IN | |
2021-10-13 19:02:54 UTC | 962 | IN | |
2021-10-13 19:02:54 UTC | 978 | IN | |
2021-10-13 19:02:54 UTC | 994 | IN | |
2021-10-13 19:02:54 UTC | 1010 | IN | |
2021-10-13 19:02:54 UTC | 1026 | IN | |
2021-10-13 19:02:54 UTC | 1042 | IN | |
2021-10-13 19:02:54 UTC | 1058 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.7 | 49753 | 31.14.69.10 | 443 | C:\Users\user\Desktop\LFEs2N6DU4.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2021-10-13 19:02:56 UTC | 1060 | OUT | |
2021-10-13 19:02:56 UTC | 1060 | IN | |
2021-10-13 19:02:56 UTC | 1060 | IN | |
2021-10-13 19:02:56 UTC | 1061 | IN | |
2021-10-13 19:02:56 UTC | 1063 | IN | |
2021-10-13 19:02:56 UTC | 1064 | IN | |
2021-10-13 19:02:56 UTC | 1068 | IN | |
2021-10-13 19:02:56 UTC | 1074 | IN | |
2021-10-13 19:02:56 UTC | 1081 | IN | |
2021-10-13 19:02:56 UTC | 1089 | IN | |
2021-10-13 19:02:56 UTC | 1098 | IN | |
2021-10-13 19:02:56 UTC | 1099 | IN | |
2021-10-13 19:02:56 UTC | 1111 | IN | |
2021-10-13 19:02:56 UTC | 1123 | IN | |
2021-10-13 19:02:56 UTC | 1124 | IN | |
2021-10-13 19:02:56 UTC | 1139 | IN | |
2021-10-13 19:02:56 UTC | 1155 | IN | |
2021-10-13 19:02:56 UTC | 1156 | IN | |
2021-10-13 19:02:56 UTC | 1172 | IN | |
2021-10-13 19:02:56 UTC | 1188 | IN | |
2021-10-13 19:02:56 UTC | 1204 | IN | |
2021-10-13 19:02:56 UTC | 1220 | IN | |
2021-10-13 19:02:56 UTC | 1236 | IN | |
2021-10-13 19:02:56 UTC | 1252 | IN | |
2021-10-13 19:02:56 UTC | 1268 | IN | |
2021-10-13 19:02:56 UTC | 1284 | IN | |
2021-10-13 19:02:56 UTC | 1300 | IN | |
2021-10-13 19:02:56 UTC | 1316 | IN | |
2021-10-13 19:02:56 UTC | 1332 | IN | |
2021-10-13 19:02:56 UTC | 1348 | IN | |
2021-10-13 19:02:56 UTC | 1364 | IN | |
2021-10-13 19:02:56 UTC | 1380 | IN | |
2021-10-13 19:02:56 UTC | 1396 | IN | |
2021-10-13 19:02:56 UTC | 1412 | IN | |
2021-10-13 19:02:56 UTC | 1428 | IN | |
2021-10-13 19:02:56 UTC | 1444 | IN | |
2021-10-13 19:02:56 UTC | 1460 | IN | |
2021-10-13 19:02:56 UTC | 1476 | IN | |
2021-10-13 19:02:56 UTC | 1492 | IN | |
2021-10-13 19:02:56 UTC | 1508 | IN | |
2021-10-13 19:02:56 UTC | 1524 | IN | |
2021-10-13 19:02:56 UTC | 1540 | IN | |
2021-10-13 19:02:56 UTC | 1556 | IN | |
2021-10-13 19:02:56 UTC | 1572 | IN | |
2021-10-13 19:02:56 UTC | 1588 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.7 | 49756 | 31.14.69.10 | 443 | C:\Users\user\Desktop\LFEs2N6DU4.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2021-10-13 19:03:03 UTC | 1590 | OUT | |
2021-10-13 19:03:03 UTC | 1590 | IN | |
2021-10-13 19:03:03 UTC | 1590 | IN | |
2021-10-13 19:03:03 UTC | 1591 | IN | |
2021-10-13 19:03:03 UTC | 1593 | IN | |
2021-10-13 19:03:03 UTC | 1594 | IN | |
2021-10-13 19:03:03 UTC | 1598 | IN | |
2021-10-13 19:03:03 UTC | 1601 | IN | |
2021-10-13 19:03:03 UTC | 1608 | IN | |
2021-10-13 19:03:03 UTC | 1616 | IN | |
2021-10-13 19:03:03 UTC | 1626 | IN | |
2021-10-13 19:03:03 UTC | 1633 | IN | |
2021-10-13 19:03:03 UTC | 1645 | IN | |
2021-10-13 19:03:03 UTC | 1654 | IN | |
2021-10-13 19:03:03 UTC | 1668 | IN | |
2021-10-13 19:03:03 UTC | 1683 | IN | |
2021-10-13 19:03:03 UTC | 1686 | IN | |
2021-10-13 19:03:03 UTC | 1702 | IN | |
2021-10-13 19:03:03 UTC | 1718 | IN | |
2021-10-13 19:03:03 UTC | 1734 | IN | |
2021-10-13 19:03:03 UTC | 1750 | IN | |
2021-10-13 19:03:03 UTC | 1766 | IN | |
2021-10-13 19:03:03 UTC | 1782 | IN | |
2021-10-13 19:03:03 UTC | 1798 | IN | |
2021-10-13 19:03:03 UTC | 1814 | IN | |
2021-10-13 19:03:03 UTC | 1830 | IN | |
2021-10-13 19:03:03 UTC | 1846 | IN | |
2021-10-13 19:03:03 UTC | 1862 | IN | |
2021-10-13 19:03:03 UTC | 1878 | IN | |
2021-10-13 19:03:03 UTC | 1894 | IN | |
2021-10-13 19:03:03 UTC | 1910 | IN | |
2021-10-13 19:03:03 UTC | 1926 | IN | |
2021-10-13 19:03:03 UTC | 1942 | IN | |
2021-10-13 19:03:03 UTC | 1958 | IN | |
2021-10-13 19:03:03 UTC | 1974 | IN | |
2021-10-13 19:03:03 UTC | 1990 | IN | |
2021-10-13 19:03:03 UTC | 2006 | IN | |
2021-10-13 19:03:03 UTC | 2022 | IN | |
2021-10-13 19:03:03 UTC | 2038 | IN | |
2021-10-13 19:03:03 UTC | 2054 | IN | |
2021-10-13 19:03:03 UTC | 2070 | IN | |
2021-10-13 19:03:03 UTC | 2086 | IN | |
2021-10-13 19:03:03 UTC | 2102 | IN | |
2021-10-13 19:03:03 UTC | 2118 | IN |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
High Level Behavior Distribution |
---|
back
Click to dive into process behavior distribution
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 21:02:04 |
Start date: | 13/10/2021 |
Path: | C:\Users\user\Desktop\LFEs2N6DU4.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x60000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
General |
---|
Start time: | 21:02:27 |
Start date: | 13/10/2021 |
Path: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x960000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
General |
---|
Start time: | 21:02:30 |
Start date: | 13/10/2021 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xba0000 |
File size: | 185856 bytes |
MD5 hash: | 15FF7D8324231381BAD48A052F85DF04 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 21:02:31 |
Start date: | 13/10/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff774ee0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 21:02:31 |
Start date: | 13/10/2021 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xba0000 |
File size: | 185856 bytes |
MD5 hash: | 15FF7D8324231381BAD48A052F85DF04 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 21:02:32 |
Start date: | 13/10/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff774ee0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 21:02:32 |
Start date: | 13/10/2021 |
Path: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd70000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
General |
---|
Start time: | 21:02:35 |
Start date: | 13/10/2021 |
Path: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x460000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
General |
---|
Start time: | 21:02:42 |
Start date: | 13/10/2021 |
Path: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6f0000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
General |
---|
Start time: | 21:02:56 |
Start date: | 13/10/2021 |
Path: | C:\Users\user\AppData\Local\Temp\LFEs2N6DU4.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd00000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
General |
---|
Start time: | 21:03:02 |
Start date: | 13/10/2021 |
Path: | C:\Users\user\AppData\Local\Temp\dhcpmon.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x7b0000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
General |
---|
Start time: | 21:03:07 |
Start date: | 13/10/2021 |
Path: | C:\Users\user\AppData\Local\Temp\dhcpmon.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x10000 |
File size: | 12288 bytes |
MD5 hash: | 5B3262B61A5EAA3EBE7E8BDC4958FC3F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Disassembly |
---|
Code Analysis |
---|
Executed Functions |
---|
Function 022719E2, Relevance: .2, Instructions: 171COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227DD84, Relevance: 1.6, APIs: 1, Instructions: 112COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227DD90, Relevance: 1.6, APIs: 1, Instructions: 112COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02279CA1, Relevance: 1.6, APIs: 1, Instructions: 84fileCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02279469, Relevance: 1.6, APIs: 1, Instructions: 74memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227D944, Relevance: 1.6, APIs: 1, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02279CC8, Relevance: 1.6, APIs: 1, Instructions: 70fileCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227C33C, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227C028, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227C030, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227D960, Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227E158, Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227DCC8, Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227DCC2, Relevance: 1.6, APIs: 1, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227B980, Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 022794A0, Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227B988, Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227B7F9, Relevance: 1.6, APIs: 1, Instructions: 51threadCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227B800, Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0092D4D8, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0092D3EC, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0093D030, Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0093D006, Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0092D4D3, Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0092D3E7, Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 0227267E, Relevance: .8, Instructions: 794COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227273A, Relevance: .8, Instructions: 776COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 022726BA, Relevance: .8, Instructions: 773COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0227277F, Relevance: .8, Instructions: 773COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 022726E9, Relevance: .8, Instructions: 772COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02272722, Relevance: .8, Instructions: 772COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02272767, Relevance: .8, Instructions: 772COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 022726D6, Relevance: .8, Instructions: 771COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02272703, Relevance: .8, Instructions: 771COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02273B0C, Relevance: .8, Instructions: 767COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02272B5B, Relevance: .8, Instructions: 767COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02273D8B, Relevance: .8, Instructions: 767COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02274621, Relevance: .8, Instructions: 756COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02274B88, Relevance: .3, Instructions: 254COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02272178, Relevance: .2, Instructions: 169COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02272188, Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Executed Functions |
---|
Function 069E3738, Relevance: 1.7, APIs: 1, Instructions: 206COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D893E8, Relevance: 1.7, APIs: 1, Instructions: 194COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D8FB98, Relevance: 1.6, APIs: 1, Instructions: 143COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D8FB61, Relevance: 1.6, APIs: 1, Instructions: 133COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D8DA04, Relevance: 1.6, APIs: 1, Instructions: 116COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D8A14C, Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D8BCF9, Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D895C8, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D8DA3C, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02D8FE38, Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Executed Functions |
---|
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026ADD90, Relevance: 1.6, APIs: 1, Instructions: 112COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026A9CC8, Relevance: 1.6, APIs: 1, Instructions: 70fileCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026AC33C, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026AC030, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026AB8B0, Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026AD960, Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026ADCC8, Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026A949B, Relevance: 1.6, APIs: 1, Instructions: 56memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026A94A0, Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026AB988, Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 026AB800, Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 009FD3EC, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C2D030, Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C2D005, Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 009FD3E7, Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Executed Functions |
---|
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294DD90, Relevance: 1.6, APIs: 1, Instructions: 112COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294DD88, Relevance: 1.6, APIs: 1, Instructions: 111COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02949CA1, Relevance: 1.6, APIs: 1, Instructions: 87fileCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02949469, Relevance: 1.6, APIs: 1, Instructions: 76memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294C32F, Relevance: 1.6, APIs: 1, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02949CC8, Relevance: 1.6, APIs: 1, Instructions: 70fileCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294C028, Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294C33C, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294C030, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294D95B, Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294D960, Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294E158, Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294DCC3, Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294DCC8, Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294B980, Relevance: 1.6, APIs: 1, Instructions: 56memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 029494A0, Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294B988, Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294B7FE, Relevance: 1.6, APIs: 1, Instructions: 50threadCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0294B800, Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 028AD4D8, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 028AD3EC, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 028BD030, Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 028AD4D3, Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 028AD3E7, Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 028BD02B, Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Executed Functions |
---|
Function 055F93E8, Relevance: 1.7, APIs: 1, Instructions: 194COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055FFB20, Relevance: 1.7, APIs: 1, Instructions: 180COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055FFB98, Relevance: 1.6, APIs: 1, Instructions: 145COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055FDA04, Relevance: 1.6, APIs: 1, Instructions: 116COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055FA14C, Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055FBCF9, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055F95C8, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055FDA3C, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055FFE38, Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0140D4A0, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0141D01C, Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0141D006, Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0140D49B, Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Executed Functions |
---|
APIs |
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0122FBEC, Relevance: 1.6, APIs: 1, Instructions: 117COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0122FBF8, Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0122BCF9, Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0122BD00, Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 012295C8, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0122FE38, Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0122FE40, Relevance: 1.5, APIs: 1, Instructions: 44COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Executed Functions |
---|
Function 0228B6C0, Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 122threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228B6D0, Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 120threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228FAA0, Relevance: 1.8, APIs: 1, Instructions: 252COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228FBF8, Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228BDC1, Relevance: 1.6, APIs: 1, Instructions: 102COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228BCF9, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228BD00, Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 022895C8, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228FE40, Relevance: 1.5, APIs: 1, Instructions: 44COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0228FE38, Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0073D01C, Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0073D017, Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|