Windows Analysis Report INV.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: NanoCore |
---|
{"Version": "1.2.2.0", "Mutex": "f4157c11-54e5-4893-8a60-6856b847", "Group": "Default", "Domain1": "dera31.ddns.net", "Domain2": "195.133.18.211", "Port": 1187, "KeyboardLogging": "Enable", "RunOnStartup": "Enable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> |
| |
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> |
| |
Click to see the 48 entries |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
Nanocore_RAT_Feb18_1 | Detects Nanocore RAT | Florian Roth |
| |
JoeSecurity_Nanocore | Yara detected Nanocore RAT | Joe Security | ||
NanoCore | unknown | Kevin Breen <kevin@techanarchy.net> |
| |
Nanocore_RAT_Gen_2 | Detetcs the Nanocore RAT | Florian Roth |
| |
Click to see the 84 entries |
Sigma Overview |
---|
AV Detection: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
E-Banking Fraud: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
Stealing of Sensitive Information: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
Remote Access Functionality: |
---|
Sigma detected: NanoCore | Show sources |
Source: | Author: Joe Security: |
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | ReversingLabs: |
Antivirus / Scanner detection for submitted sample | Show sources |
Source: | Avira: |
Multi AV Scanner detection for domain / URL | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Antivirus detection for dropped file | Show sources |
Source: | Avira: |
Multi AV Scanner detection for dropped file | Show sources |
Source: | ReversingLabs: |
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_07EC0DDF | |
Source: | Code function: | 8_2_06C80DDF |
Networking: |
---|
C2 URLs / IPs found in malware configuration | Show sources |
Source: | URLs: | ||
Source: | URLs: |
Uses dynamic DNS services | Show sources |
Source: | DNS query: |
Source: | ASN Name: |
Source: | TCP traffic: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | Binary or memory string: |
Source: | Binary or memory string: |
E-Banking Fraud: |
---|
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary: |
---|
Malicious sample detected (through community Yara rule) | Show sources |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_01676E70 | |
Source: | Code function: | 0_2_0167CAD4 | |
Source: | Code function: | 0_2_0167EF0B | |
Source: | Code function: | 0_2_0167EF18 | |
Source: | Code function: | 0_2_01676E5F | |
Source: | Code function: | 0_2_07EC12F8 | |
Source: | Code function: | 8_2_00B86E70 | |
Source: | Code function: | 8_2_00B8CAD4 | |
Source: | Code function: | 8_2_00B86E5F | |
Source: | Code function: | 8_2_00B8EF18 | |
Source: | Code function: | 8_2_00B8EF0A | |
Source: | Code function: | 8_2_06C812F8 | |
Source: | Code function: | 11_2_02FCE480 | |
Source: | Code function: | 11_2_02FCE471 | |
Source: | Code function: | 11_2_02FCBBD4 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation: |
---|
.NET source code contains potential unpacker | Show sources |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00FD4FD1 | |
Source: | Code function: | 0_2_0167D23D | |
Source: | Code function: | 0_2_058E7457 | |
Source: | Code function: | 0_2_058E745B | |
Source: | Code function: | 0_2_07EC430F | |
Source: | Code function: | 8_2_00474FD1 | |
Source: | Code function: | 8_2_00B8D23D | |
Source: | Code function: | 8_2_00B81C7A | |
Source: | Code function: | 8_2_00B81C7A | |
Source: | Code function: | 8_2_02A37457 | |
Source: | Code function: | 8_2_02A3745B | |
Source: | Code function: | 8_2_06C80FEC | |
Source: | Code function: | 8_2_06C8430F | |
Source: | Code function: | 11_2_00BE4FD1 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection: |
---|
Hides that the sample has been downloaded from the Internet (zone.identifier) | Show sources |
Source: | File opened: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion: |
---|
Yara detected AntiVM3 | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) | Show sources |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information: |
---|
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality: |
---|
Detected Nanocore Rat | Show sources |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Yara detected Nanocore RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation1 | Path Interception | Process Injection11 | Masquerading2 | Input Capture21 | Query Registry1 | Remote Services | Input Capture21 | Exfiltration Over Other Network Medium | Encrypted Channel1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Disable or Modify Tools1 | LSASS Memory | Security Software Discovery211 | Remote Desktop Protocol | Archive Collected Data11 | Exfiltration Over Bluetooth | Non-Standard Port1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Virtualization/Sandbox Evasion21 | Security Account Manager | Process Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Remote Access Software1 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Process Injection11 | NTDS | Virtualization/Sandbox Evasion21 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Non-Application Layer Protocol1 | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Deobfuscate/Decode Files or Information1 | LSA Secrets | Application Window Discovery1 | SSH | Keylogging | Data Transfer Size Limits | Application Layer Protocol21 | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | Hidden Files and Directories1 | Cached Domain Credentials | System Information Discovery12 | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Obfuscated Files or Information3 | DCSync | Network Sniffing | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | Software Packing13 | Proc Filesystem | Network Service Scanning | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
20% | ReversingLabs | ByteCode-MSIL.Trojan.Taskun | ||
100% | Avira | HEUR/AGEN.1141888 |
Dropped Files |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1141888 | ||
20% | ReversingLabs | ByteCode-MSIL.Trojan.Taskun |
Unpacked PE Files |
---|
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File | ||
100% | Avira | TR/Dropper.MSIL.Gen7 | Download File |
Domains |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
6% | Virustotal | Browse |
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
6% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
5% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
dera31.ddns.net | 194.85.248.250 | true | true |
| unknown |
Contacted URLs |
---|
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
Contacted IPs |
---|
General Information |
---|
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 527765 |
Start date: | 24.11.2021 |
Start time: | 11:39:21 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 10m 52s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | INV.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 23 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@6/8@18/2 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
11:40:33 | API Interceptor | |
11:40:45 | Autostart | |
11:40:59 | API Interceptor |
Joe Sandbox View / Context |
---|
IPs |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
194.85.248.250 | Get hash | malicious | Browse |
Domains |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
dera31.ddns.net | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
DATACENTERRO | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
Process: | C:\Users\user\Desktop\INV.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 553472 |
Entropy (8bit): | 7.892995395638637 |
Encrypted: | false |
SSDEEP: | 12288:tOL/Mq/d/xj06PDRQtc0DEt1G2AjKVUhCX+U3/4sQ+5C5xw:tOLUm/mWDk+RA+qgXF/4sQ+U5 |
MD5: | 9D64FA92CE93C242C09947E6A0A892A6 |
SHA1: | 463C942E70FEE74AEF894C0DA58277C884D8C6BD |
SHA-256: | E6A01CE5B7532B69A312FEE870B244D1DF1A6CAC00551981C850CE38EDC79AF5 |
SHA-512: | 92AAA8E0BABD8B19264D9F4BAB511FEF60B64BC4E54E6D6F65010D4545F9D8670933A22121C0BA2EE54D61C66F63769BA971FD4C1F38CE6497CA8BB6DCCAE61A |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
|
Process: | C:\Users\user\Desktop\INV.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
|
Process: | C:\Users\user\Desktop\INV.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.355304211458859 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84j:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzr |
MD5: | FED34146BF2F2FA59DCF8702FCC8232E |
SHA1: | B03BFEA175989D989850CF06FE5E7BBF56EAA00A |
SHA-256: | 123BE4E3590609A008E85501243AF5BC53FA0C26C82A92881B8879524F8C0D5C |
SHA-512: | 1CC89F2ED1DBD70628FA1DC41A32BA0BFA3E81EAE1A1CF3C5F6A48F2DA0BF1F21A5001B8A18B04043C5B8FE4FBE663068D86AA8C4BD8E17933F75687C3178FF6 |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
|
Process: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.355304211458859 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84j:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzr |
MD5: | FED34146BF2F2FA59DCF8702FCC8232E |
SHA1: | B03BFEA175989D989850CF06FE5E7BBF56EAA00A |
SHA-256: | 123BE4E3590609A008E85501243AF5BC53FA0C26C82A92881B8879524F8C0D5C |
SHA-512: | 1CC89F2ED1DBD70628FA1DC41A32BA0BFA3E81EAE1A1CF3C5F6A48F2DA0BF1F21A5001B8A18B04043C5B8FE4FBE663068D86AA8C4BD8E17933F75687C3178FF6 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
|
Process: | C:\Users\user\Desktop\INV.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 232 |
Entropy (8bit): | 7.117516745217376 |
Encrypted: | false |
SSDEEP: | 6:X4LDAnybgCFcpJSQwP4d7V9Nhyleajl0fuONKcpMe5i:X4LEnybgCFCtvd7V9NYRj+GONKaMv |
MD5: | CF55DF705B79F961ED069D8E84D2AF1C |
SHA1: | 574CDF36753CF356A25872BCCAA3CC6FFCD5D23F |
SHA-256: | DF982E10764D21FCB1469EB6EA1175AC69544C68900B0DD8C79A0FE8A8F300F5 |
SHA-512: | 518A037DF1D6FBC8A296DA5B96B67E073FB1F674090AFE3243E52A65B169DE35FC041C2C05F7EEF9EC74A0100A422E53B3D7D920E5ADF6CE42B82FE94244F5DE |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
|
Process: | C:\Users\user\Desktop\INV.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8 |
Entropy (8bit): | 3.0 |
Encrypted: | false |
SSDEEP: | 3:bnt:p |
MD5: | B67F236CCBDD808687AB1ED303277371 |
SHA1: | A7F2A003B809BE7AEC847182F7A8E32E1A69927D |
SHA-256: | 54D51090990EA722925865E229CEC4ACA47400D75F98803D004B2E2F52E86247 |
SHA-512: | 4F53EBEC74CF58ED08C623FE2ABD36000297C162EDDCD27D284A31E57E1AB3A0ECEE1DDA76B936C069CF869D40B6E84C4BFF03B122665DF912CA097CF091ABD2 |
Malicious: | true |
Reputation: | low |
Preview: |
|
Process: | C:\Users\user\Desktop\INV.exe |
File Type: | |
Category: | modified |
Size (bytes): | 40 |
Entropy (8bit): | 5.153055907333276 |
Encrypted: | false |
SSDEEP: | 3:9bzY6oRDT6P2bfVn1:RzWDT621 |
MD5: | 4E5E92E2369688041CC82EF9650EDED2 |
SHA1: | 15E44F2F3194EE232B44E9684163B6F66472C862 |
SHA-256: | F8098A6290118F2944B9E7C842BD014377D45844379F863B00D54515A8A64B48 |
SHA-512: | 1B368018907A3BC30421FDA2C935B39DC9073B9B1248881E70AD48EDB6CAA256070C1A90B97B0F64BBE61E316DBB8D5B2EC8DBABCD0B0B2999AB50B933671ECB |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
|
Process: | C:\Users\user\Desktop\INV.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 315080 |
Entropy (8bit): | 7.999403263872478 |
Encrypted: | true |
SSDEEP: | 6144:m8aeVE5MlgWfxwY/8uvJYRDMVpXUhXQrEBPgzC2D4Toqhs22DJM+iaPnW:mfwiMdxwYEYyWzw0TqC2kM+lnW |
MD5: | 981C80683A41E2D9DD9C297DAA691C54 |
SHA1: | 7A1F5DDFFB3E630FE19E19F6AA923427DE72217B |
SHA-256: | 6C67B680BB9CF41F30C37D791D9EE52582977C1D9D5696FEAE1613FC0C5E2DBE |
SHA-512: | 72E4198AE2A65B7E1698925DF537CBA63A2877677C7C8FEA475E52B99E631272CFBEDCD5A4E1949EB7F8073C01229E89CCCD1ABBFD8832533346A6568750ADAE |
Malicious: | false |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 7.892995395638637 |
TrID: |
|
File name: | INV.exe |
File size: | 553472 |
MD5: | 9d64fa92ce93c242c09947e6a0a892a6 |
SHA1: | 463c942e70fee74aef894c0da58277c884d8c6bd |
SHA256: | e6a01ce5b7532b69a312fee870b244d1df1a6cac00551981c850ce38edc79af5 |
SHA512: | 92aaa8e0babd8b19264d9f4bab511fef60b64bc4e54e6d6f65010d4545f9d8670933a22121c0ba2ee54d61c66f63769ba971fd4c1f38ce6497ca8bb6dccae61a |
SSDEEP: | 12288:tOL/Mq/d/xj06PDRQtc0DEt1G2AjKVUhCX+U3/4sQ+5C5xw:tOLUm/mWDk+RA+qgXF/4sQ+U5 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...f..a..............0..h..........>.... ........@.. ....................................@................................ |
File Icon |
---|
Icon Hash: | 00828e8e8686b000 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x48863e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | 32BIT_MACHINE, EXECUTABLE_IMAGE |
DLL Characteristics: | NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x619DE066 [Wed Nov 24 06:49:10 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | v4.0.30319 |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Entrypoint Preview |
---|
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x885e4 | 0x57 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x8a000 | 0x600 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x8c000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x86644 | 0x86800 | False | 0.923913438081 | data | 7.90207517274 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rsrc | 0x8a000 | 0x600 | 0x600 | False | 0.455078125 | data | 4.26873788537 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x8c000 | 0xc | 0x200 | False | 0.044921875 | data | 0.101910425663 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_VERSION | 0x8a0a0 | 0x370 | data | ||
RT_MANIFEST | 0x8a410 | 0x1ea | XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators |
Imports |
---|
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Version Infos |
---|
Description | Data |
---|---|
Translation | 0x0000 0x04b0 |
LegalCopyright | Real Estate LTD |
Assembly Version | 2.9.0.0 |
InternalName | FORMATFLA.exe |
FileVersion | 2.8.2.0 |
CompanyName | Buena Vista Realty Service |
LegalTrademarks | |
Comments | |
ProductName | ObjectHolderList |
ProductVersion | 2.8.2.0 |
FileDescription | ObjectHolderList |
OriginalFilename | FORMATFLA.exe |
Network Behavior |
---|
Snort IDS Alerts |
---|
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
11/24/21-11:40:43.693178 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 62044 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:40:55.238234 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 49448 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:41:00.517317 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 60342 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:41:11.773479 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 58384 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:41:24.716787 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 53781 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:41:36.939954 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 50010 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:41:55.338434 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 62208 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:42:07.300908 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 56628 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:42:14.530221 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 60778 | 8.8.8.8 | 192.168.2.6 |
11/24/21-11:42:26.568735 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 54683 | 8.8.8.8 | 192.168.2.6 |
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 24, 2021 11:40:43.712908983 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:43.741384983 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:43.741554976 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:43.831315994 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:43.873809099 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:43.920450926 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:43.987067938 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.015316963 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.017401934 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.126719952 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.268603086 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.399573088 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.399620056 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.399648905 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.399677038 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.399734974 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.399771929 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.427073002 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427139997 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427177906 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427208900 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427243948 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427272081 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.427277088 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427295923 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.427333117 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.427390099 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427428007 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.427596092 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.455275059 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455315113 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455343008 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455364943 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455387115 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455406904 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455427885 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455450058 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455476046 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455506086 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455533981 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455559015 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455586910 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455612898 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455638885 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455666065 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.455898046 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484093904 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484133005 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484160900 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484185934 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484214067 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484241009 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484261990 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484270096 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484285116 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484297991 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484324932 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484349012 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484358072 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484369040 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484375954 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484400034 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484421968 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484445095 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484452009 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484467030 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484472036 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484483004 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484497070 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484522104 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484545946 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484568119 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484572887 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484591007 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.484612942 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.484639883 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.511961937 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.511986971 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512003899 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512021065 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512037992 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512056112 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512075901 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512094975 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512110949 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512115002 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512129068 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512144089 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512150049 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512151957 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512160063 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512168884 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512171030 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512187004 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512206078 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512223005 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512240887 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512258053 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512274981 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512279034 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512290955 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512293100 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512300014 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512311935 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512326956 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512329102 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512346029 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512357950 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512365103 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512387037 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512407064 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512423992 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512440920 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512443066 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512454987 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512459040 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512474060 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512476921 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512495041 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512511969 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512523890 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512531996 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512550116 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512558937 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512567043 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512583017 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512584925 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512603998 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512619019 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512620926 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512636900 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512655020 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512660980 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512670994 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.512718916 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.512738943 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540272951 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540302038 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540318012 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540335894 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540353060 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540371895 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540410995 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540427923 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540472984 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540472984 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540491104 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540501118 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540508986 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540514946 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540529013 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540537119 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540544987 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540563107 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540563107 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540584087 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540601015 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540611029 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540618896 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540636063 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540652037 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540668964 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540677071 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540684938 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540688992 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540704012 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540720940 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540729046 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540738106 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540738106 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540755033 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540772915 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540786028 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540788889 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540807009 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540823936 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540826082 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540842056 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540879965 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540894032 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540896893 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540906906 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.540914059 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540931940 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540946960 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540963888 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540998936 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.540997982 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541008949 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541016102 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541019917 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541033983 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541050911 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541068077 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541084051 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541084051 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541100979 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541117907 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541121006 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541131973 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541136026 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541153908 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541169882 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541169882 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541188002 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.541234970 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.541244984 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.568973064 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569027901 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569065094 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569101095 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569139004 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569154978 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569173098 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569178104 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569216967 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569256067 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569262028 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569293976 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569329977 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569360018 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569365978 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569397926 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569402933 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569439888 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569475889 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569510937 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569520950 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569535017 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569549084 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569585085 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569610119 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569621086 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569658041 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569694996 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569705009 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569732904 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569741964 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569772005 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569808006 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569844007 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569880009 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569896936 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569909096 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569916010 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569952011 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.569973946 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.569989920 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570028067 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570064068 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570099115 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570111990 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570123911 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570135117 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570173025 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570209026 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570225954 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570250034 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570286989 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570323944 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570339918 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570352077 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570363045 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570396900 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570431948 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570460081 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570470095 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570497990 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570534945 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570569992 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570573092 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570585966 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570605993 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570633888 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570642948 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570677996 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570714951 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.570746899 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.570760012 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598293066 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598352909 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598392963 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598432064 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598474026 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598485947 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598511934 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598516941 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598560095 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598599911 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598613977 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598640919 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598656893 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598681927 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598721981 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598763943 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598807096 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598810911 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598856926 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598874092 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598897934 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598939896 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.598956108 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.598978996 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599020004 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599035978 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599061012 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599100113 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599119902 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599139929 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599179983 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599195957 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599220991 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599266052 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599306107 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599344969 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599353075 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599365950 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599386930 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599432945 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599478006 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599518061 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599558115 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599595070 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599595070 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599607944 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599636078 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599674940 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599715948 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599726915 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599757910 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599767923 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599811077 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599867105 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599908113 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599946022 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.599947929 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599961042 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.599987030 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600025892 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600064039 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600075006 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600104094 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600112915 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600142956 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600182056 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600223064 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600240946 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600264072 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600270987 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600303888 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600342989 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600380898 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600393057 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600421906 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600434065 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600462914 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600502968 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600513935 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600545883 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600584984 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600594997 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600625038 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600663900 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600703001 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600713015 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600743055 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600754023 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600781918 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600821018 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600897074 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.600913048 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.600990057 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601027966 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601067066 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601072073 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.601083994 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.601109028 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601145983 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601183891 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601217031 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.601223946 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601231098 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.601264000 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601303101 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601341009 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601356030 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.601381063 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601393938 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.601423979 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601459980 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601495981 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:44.601542950 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:44.601555109 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:45.193011045 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:45.326129913 CET | 1187 | 49753 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:46.023402929 CET | 49753 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:50.451780081 CET | 49754 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:50.480556965 CET | 1187 | 49754 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:50.480823040 CET | 49754 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:50.486825943 CET | 49754 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:50.575819016 CET | 1187 | 49754 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:50.624735117 CET | 49754 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:50.654215097 CET | 1187 | 49754 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:50.655199051 CET | 49754 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:50.683837891 CET | 1187 | 49754 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:50.733448982 CET | 49754 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:51.047384977 CET | 49754 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:55.295407057 CET | 49757 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:55.325592041 CET | 1187 | 49757 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:55.325721025 CET | 49757 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:55.349519014 CET | 49757 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:55.398087978 CET | 1187 | 49757 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:55.452579021 CET | 49757 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:55.480192900 CET | 1187 | 49757 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:55.480587006 CET | 49757 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:55.509193897 CET | 1187 | 49757 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:40:55.561969042 CET | 49757 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:40:56.265347004 CET | 49757 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:00.520036936 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:00.547324896 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:00.547461033 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:00.548000097 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:00.600771904 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:00.601236105 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:00.629344940 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:00.688250065 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:00.849030018 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:00.849369049 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:00.948066950 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:01.096210003 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:01.234654903 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:01.255641937 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:01.262079954 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:01.348032951 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:01.348268986 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:01.396651983 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:01.398772001 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:01.425996065 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:01.430542946 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:01.553947926 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:01.977757931 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:02.075021029 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:02.234446049 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:02.551909924 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:02.648013115 CET | 1187 | 49758 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:02.704416037 CET | 49758 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:06.783859968 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:06.815354109 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:06.815502882 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:06.817764997 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:06.858939886 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:06.906725883 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:06.934500933 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:06.934853077 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:06.963567972 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:07.016139984 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:07.156583071 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:07.238740921 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:07.405574083 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:07.421910048 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:07.452733994 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:07.454222918 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:07.486915112 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:07.487226009 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:07.522933960 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:07.528835058 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:07.605429888 CET | 1187 | 49759 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:07.689150095 CET | 49759 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:11.775161982 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:11.802690983 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:11.803477049 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:11.818964005 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:11.866879940 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:11.867252111 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:11.897802114 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:11.938381910 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:12.705281019 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:12.792346001 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:12.923115969 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:12.994168997 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:13.120508909 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:13.121505976 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:13.149003983 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:13.150319099 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:13.239212036 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:13.239367962 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:13.251238108 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:13.297936916 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:13.319233894 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:13.325345993 CET | 1187 | 49762 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:13.376079082 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:13.705785990 CET | 49762 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:17.767410994 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:17.794773102 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:17.794898033 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:17.795324087 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:17.846820116 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:17.847178936 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:17.875632048 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:17.985759974 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:18.432672024 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:18.513153076 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:18.519691944 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:18.604103088 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:18.714849949 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:18.723123074 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:18.750695944 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:18.752170086 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:18.786695957 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:18.786770105 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:18.831360102 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:18.831546068 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:18.859179020 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:18.985836983 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:19.549344063 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:19.623152971 CET | 1187 | 49765 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:20.581711054 CET | 49765 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:24.725455999 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:24.752921104 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:24.753022909 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:24.753668070 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:24.827334881 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:24.833187103 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:24.833483934 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:24.866858006 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:24.986337900 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:25.678812981 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:25.758158922 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:25.844224930 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:25.921655893 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:26.388391018 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:26.389672041 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:26.417356968 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:26.419384003 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:26.447298050 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:26.447407961 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:26.476901054 CET | 1187 | 49774 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:26.689610004 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:26.775417089 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:26.775621891 CET | 49774 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:30.898787975 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:30.926857948 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:30.927335978 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:30.928014994 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:30.975408077 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:30.975852013 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:31.004390955 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:31.190233946 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:31.753897905 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:31.828337908 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:31.862411022 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:31.945305109 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:31.999561071 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:32.027628899 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:32.063564062 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:32.065118074 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:32.105987072 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:32.106122017 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:32.135384083 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:32.190066099 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:32.243745089 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:32.314054012 CET | 1187 | 49780 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:32.885200977 CET | 49780 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.026859045 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.054939032 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.055186987 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.055747032 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.150295019 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.151823044 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.179646015 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.238132000 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.368045092 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.381100893 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.466510057 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.754357100 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.789638042 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.817790031 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.862442970 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.889961004 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.891396999 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.922471046 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:37.923172951 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:37.951483011 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:38.065541983 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:38.192097902 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:38.266160011 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:38.285319090 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:38.366224051 CET | 1187 | 49798 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:39.254003048 CET | 49798 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:43.360002995 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:43.388962030 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:43.389091969 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:43.389647007 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:43.497482061 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:43.497837067 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:43.636892080 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:43.637017012 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:43.704184055 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:43.753545046 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:44.417825937 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:44.508337021 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:44.508419991 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:44.608619928 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:44.780755997 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:44.831763029 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:44.834481001 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:44.862632990 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:44.909898043 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:44.937441111 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:44.954351902 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:44.986040115 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:45.019435883 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:45.047393084 CET | 1187 | 49817 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:45.097466946 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:45.341444969 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:45.395925999 CET | 49817 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:49.495485067 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:49.523305893 CET | 1187 | 49822 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:49.523426056 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:49.595912933 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:49.685281038 CET | 1187 | 49822 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:49.685578108 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:49.727864981 CET | 1187 | 49822 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:49.769680023 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:49.797291040 CET | 1187 | 49822 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:49.847794056 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:50.105746984 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:50.266309023 CET | 1187 | 49822 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:50.459156036 CET | 49822 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:55.340416908 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:55.368279934 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:55.368419886 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:55.369220972 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:55.487374067 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:55.489643097 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:55.539727926 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:55.582664013 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.190253019 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.311012030 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:56.311501980 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.410121918 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:56.612942934 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:56.675590992 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.678724051 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.703582048 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:56.775749922 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.807051897 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:56.813724995 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.907084942 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:56.908417940 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:56.981694937 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:57.079698086 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:57.149310112 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:57.272718906 CET | 1187 | 49823 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:41:57.377291918 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:41:58.175012112 CET | 49823 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:02.236095905 CET | 49826 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:02.263983965 CET | 1187 | 49826 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:02.264344931 CET | 49826 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:02.366913080 CET | 49826 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:02.436016083 CET | 1187 | 49826 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:02.436314106 CET | 49826 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:02.566329956 CET | 1187 | 49826 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:02.620491982 CET | 1187 | 49826 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:02.681233883 CET | 49826 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:03.232311964 CET | 49826 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:07.312253952 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:07.340902090 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:07.341064930 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:07.341722965 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:07.508527040 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:07.652966976 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:07.656426907 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:07.684442997 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:07.729183912 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:07.853807926 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:08.007112026 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:08.319361925 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:08.406176090 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:08.678150892 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:08.685941935 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:08.718283892 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:08.760581970 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:08.794405937 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:08.794739008 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:08.883131981 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:08.883285046 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:09.007114887 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:09.230077028 CET | 1187 | 49839 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:09.276184082 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:09.339459896 CET | 49839 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:14.532421112 CET | 49850 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:14.565838099 CET | 1187 | 49850 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:14.565993071 CET | 49850 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:14.566495895 CET | 49850 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:14.670845985 CET | 1187 | 49850 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:15.496875048 CET | 49850 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:15.666528940 CET | 1187 | 49850 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:16.511997938 CET | 49850 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:20.594291925 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:20.622972965 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:20.623065948 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:20.624151945 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:20.709602118 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:21.496515989 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:21.589036942 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:21.591540098 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:21.650882959 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:21.699054003 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:21.871136904 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:22.008816957 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:22.209002018 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:22.210777998 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:22.307266951 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:22.450306892 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:22.496083021 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:22.512718916 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:22.523525953 CET | 1187 | 49851 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:22.523684978 CET | 49851 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:26.570091963 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:26.597685099 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:26.597878933 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:26.598331928 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:26.765579939 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:27.496989965 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:27.665601969 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:27.834218979 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:27.834450960 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:27.887372017 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:27.934051037 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:28.247528076 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:28.365703106 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:28.497173071 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:28.526139975 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:28.526714087 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:28.557976007 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:28.558559895 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:28.596577883 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:28.596713066 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:28.624682903 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:28.668461084 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:29.113073111 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:29.168456078 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
Nov 24, 2021 11:42:33.349155903 CET | 1187 | 49852 | 194.85.248.250 | 192.168.2.6 |
Nov 24, 2021 11:42:33.411953926 CET | 49852 | 1187 | 192.168.2.6 | 194.85.248.250 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 24, 2021 11:40:43.669563055 CET | 62044 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:40:43.693177938 CET | 53 | 62044 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:40:50.424350977 CET | 63791 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:40:50.444122076 CET | 53 | 63791 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:40:55.217364073 CET | 49448 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:40:55.238234043 CET | 53 | 49448 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:00.488914013 CET | 60342 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:00.517317057 CET | 53 | 60342 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:06.762356997 CET | 61346 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:06.782207966 CET | 53 | 61346 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:11.752306938 CET | 58384 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:11.773478985 CET | 53 | 58384 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:17.746325970 CET | 60261 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:17.766179085 CET | 53 | 60261 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:24.693977118 CET | 53781 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:24.716787100 CET | 53 | 53781 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:30.877182961 CET | 63745 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:30.895451069 CET | 53 | 63745 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:36.918418884 CET | 50010 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:36.939954042 CET | 53 | 50010 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:43.336577892 CET | 62116 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:43.356537104 CET | 53 | 62116 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:49.437659025 CET | 55014 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:49.455307961 CET | 53 | 55014 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:41:55.319106102 CET | 62208 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:41:55.338433981 CET | 53 | 62208 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:42:02.210747957 CET | 51818 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:42:02.228897095 CET | 53 | 51818 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:42:07.276382923 CET | 56628 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:42:07.300908089 CET | 53 | 56628 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:42:14.507567883 CET | 60778 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:42:14.530220985 CET | 53 | 60778 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:42:20.570477009 CET | 53799 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:42:20.592962027 CET | 53 | 53799 | 8.8.8.8 | 192.168.2.6 |
Nov 24, 2021 11:42:26.549261093 CET | 54683 | 53 | 192.168.2.6 | 8.8.8.8 |
Nov 24, 2021 11:42:26.568734884 CET | 53 | 54683 | 8.8.8.8 | 192.168.2.6 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Nov 24, 2021 11:40:43.669563055 CET | 192.168.2.6 | 8.8.8.8 | 0xb92c | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:40:50.424350977 CET | 192.168.2.6 | 8.8.8.8 | 0x60b7 | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:40:55.217364073 CET | 192.168.2.6 | 8.8.8.8 | 0x2f78 | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:00.488914013 CET | 192.168.2.6 | 8.8.8.8 | 0x673e | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:06.762356997 CET | 192.168.2.6 | 8.8.8.8 | 0xe54e | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:11.752306938 CET | 192.168.2.6 | 8.8.8.8 | 0x1451 | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:17.746325970 CET | 192.168.2.6 | 8.8.8.8 | 0x66aa | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:24.693977118 CET | 192.168.2.6 | 8.8.8.8 | 0xe18e | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:30.877182961 CET | 192.168.2.6 | 8.8.8.8 | 0x376c | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:36.918418884 CET | 192.168.2.6 | 8.8.8.8 | 0x23c8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:43.336577892 CET | 192.168.2.6 | 8.8.8.8 | 0x1f37 | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:49.437659025 CET | 192.168.2.6 | 8.8.8.8 | 0x5e3f | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:41:55.319106102 CET | 192.168.2.6 | 8.8.8.8 | 0xbb7d | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:42:02.210747957 CET | 192.168.2.6 | 8.8.8.8 | 0x604e | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:42:07.276382923 CET | 192.168.2.6 | 8.8.8.8 | 0xa6cf | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:42:14.507567883 CET | 192.168.2.6 | 8.8.8.8 | 0x812b | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:42:20.570477009 CET | 192.168.2.6 | 8.8.8.8 | 0xa47a | Standard query (0) | A (IP address) | IN (0x0001) | |
Nov 24, 2021 11:42:26.549261093 CET | 192.168.2.6 | 8.8.8.8 | 0x909b | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Nov 24, 2021 11:40:43.693177938 CET | 8.8.8.8 | 192.168.2.6 | 0xb92c | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:40:50.444122076 CET | 8.8.8.8 | 192.168.2.6 | 0x60b7 | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:40:55.238234043 CET | 8.8.8.8 | 192.168.2.6 | 0x2f78 | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:00.517317057 CET | 8.8.8.8 | 192.168.2.6 | 0x673e | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:06.782207966 CET | 8.8.8.8 | 192.168.2.6 | 0xe54e | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:11.773478985 CET | 8.8.8.8 | 192.168.2.6 | 0x1451 | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:17.766179085 CET | 8.8.8.8 | 192.168.2.6 | 0x66aa | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:24.716787100 CET | 8.8.8.8 | 192.168.2.6 | 0xe18e | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:30.895451069 CET | 8.8.8.8 | 192.168.2.6 | 0x376c | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:36.939954042 CET | 8.8.8.8 | 192.168.2.6 | 0x23c8 | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:43.356537104 CET | 8.8.8.8 | 192.168.2.6 | 0x1f37 | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:49.455307961 CET | 8.8.8.8 | 192.168.2.6 | 0x5e3f | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:41:55.338433981 CET | 8.8.8.8 | 192.168.2.6 | 0xbb7d | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:42:02.228897095 CET | 8.8.8.8 | 192.168.2.6 | 0x604e | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:42:07.300908089 CET | 8.8.8.8 | 192.168.2.6 | 0xa6cf | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:42:14.530220985 CET | 8.8.8.8 | 192.168.2.6 | 0x812b | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:42:20.592962027 CET | 8.8.8.8 | 192.168.2.6 | 0xa47a | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) | ||
Nov 24, 2021 11:42:26.568734884 CET | 8.8.8.8 | 192.168.2.6 | 0x909b | No error (0) | 194.85.248.250 | A (IP address) | IN (0x0001) |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
High Level Behavior Distribution |
---|
back
Click to dive into process behavior distribution
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 11:40:22 |
Start date: | 24/11/2021 |
Path: | C:\Users\user\Desktop\INV.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfd0000 |
File size: | 553472 bytes |
MD5 hash: | 9D64FA92CE93C242C09947E6A0A892A6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
General |
---|
Start time: | 11:40:34 |
Start date: | 24/11/2021 |
Path: | C:\Users\user\Desktop\INV.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x9c0000 |
File size: | 553472 bytes |
MD5 hash: | 9D64FA92CE93C242C09947E6A0A892A6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
General |
---|
Start time: | 11:40:53 |
Start date: | 24/11/2021 |
Path: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x470000 |
File size: | 553472 bytes |
MD5 hash: | 9D64FA92CE93C242C09947E6A0A892A6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
General |
---|
Start time: | 11:41:01 |
Start date: | 24/11/2021 |
Path: | C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbe0000 |
File size: | 553472 bytes |
MD5 hash: | 9D64FA92CE93C242C09947E6A0A892A6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
Disassembly |
---|
Code Analysis |
---|
Executed Functions |
---|
Function 01676E5F, Relevance: 1.3, Strings: 1, Instructions: 89COMMON
Strings |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01676E70, Relevance: 1.3, Strings: 1, Instructions: 87COMMON
Strings |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 07EC12F8, Relevance: .3, Instructions: 317COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01679D30, Relevance: 1.7, APIs: 1, Instructions: 191COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E07C4, Relevance: 1.6, APIs: 1, Instructions: 116COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E07D0, Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01673E44, Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0167539D, Relevance: 1.6, APIs: 1, Instructions: 94COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2D90, Relevance: 1.6, APIs: 1, Instructions: 93COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0167AA6C, Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0167C253, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01679F10, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0A10, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 07EC178A, Relevance: 1.5, APIs: 1, Instructions: 45windowCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0A18, Relevance: 1.5, APIs: 1, Instructions: 44COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 07EC1790, Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Function 07EC0DDF, Relevance: 1.3, Strings: 1, Instructions: 63COMMON
Strings |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0167EF18, Relevance: .3, Instructions: 315COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0167CAD4, Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0167EF0B, Relevance: .2, Instructions: 235COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Executed Functions |
---|
Function 00B89D30, Relevance: 1.7, APIs: 1, Instructions: 194COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B83E44, Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B8539D, Relevance: 1.6, APIs: 1, Instructions: 94COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02A32D90, Relevance: 1.6, APIs: 1, Instructions: 93COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B8AA6C, Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B8C252, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B89F10, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 06C81789, Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 06C81790, Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AAD4C4, Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00ABD01C, Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00ABD1D4, Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AAD4BF, Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00ABD1CF, Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00ABD017, Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AAD651, Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AAD650, Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
Executed Functions |
---|
Function 02FC93E8, Relevance: 1.7, APIs: 1, Instructions: 194COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FCFB20, Relevance: 1.7, APIs: 1, Instructions: 182COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FCFB98, Relevance: 1.6, APIs: 1, Instructions: 145COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FCDA04, Relevance: 1.6, APIs: 1, Instructions: 116COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FCA14C, Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FCBCF9, Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FC95C8, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FCDA3C, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 02FCFE38, Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|