Windows
Analysis Report
Informe bancario.pdf.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Informe bancario.pdf.exe (PID: 6496 cmdline:
"C:\Users\ user\Deskt op\Informe bancario. pdf.exe" MD5: 603FE9A434DA79407213DB7D4B907789) - Informe bancario.pdf.exe (PID: 6800 cmdline:
C:\Users\u ser\Deskto p\Informe bancario.p df.exe MD5: 603FE9A434DA79407213DB7D4B907789) - Informe bancario.pdf.exe (PID: 6824 cmdline:
C:\Users\u ser\Deskto p\Informe bancario.p df.exe MD5: 603FE9A434DA79407213DB7D4B907789)
- cleanup
{"C2 list": ["http://kbfvzoboss.bid/alien/fre.php", "http://alphastand.trade/alien/fre.php", "http://alphastand.win/alien/fre.php", "http://alphastand.top/alien/fre.php", "http://kossa.xyz/esi/pp/play.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | ||
JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | ||
INDICATOR_SUSPICIOUS_GENInfoStealer | Detects executables containing common artifcats observed in infostealers | ditekSHen |
| |
Loki_1 | Loki Payload | kevoreilly |
| |
Click to see the 43 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
SUSP_XORed_URL_in_EXE | Detects an XORed URL in an executable | Florian Roth |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | ||
JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | ||
INDICATOR_SUSPICIOUS_GENInfoStealer | Detects executables containing common artifcats observed in infostealers | ditekSHen |
| |
Click to see the 126 entries |
Timestamp: | 192.168.2.3172.67.154.7249744802025381 06/23/22-17:54:38.472164 |
SID: | 2025381 |
Source Port: | 49744 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249767802024313 06/23/22-17:54:57.914899 |
SID: | 2024313 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349836802021641 06/23/22-17:55:40.617404 |
SID: | 2021641 |
Source Port: | 49836 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349843802025381 06/23/22-17:55:45.763232 |
SID: | 2025381 |
Source Port: | 49843 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249746802021641 06/23/22-17:54:42.346945 |
SID: | 2021641 |
Source Port: | 49746 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249749802024313 06/23/22-17:54:47.375834 |
SID: | 2024313 |
Source Port: | 49749 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249767802024318 06/23/22-17:54:57.914899 |
SID: | 2024318 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249770802024313 06/23/22-17:55:02.423254 |
SID: | 2024313 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349745802025381 06/23/22-17:54:39.886492 |
SID: | 2025381 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249844802021641 06/23/22-17:55:50.553165 |
SID: | 2021641 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249749802024318 06/23/22-17:54:47.375834 |
SID: | 2024318 |
Source Port: | 49749 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249762802025381 06/23/22-17:54:52.263394 |
SID: | 2025381 |
Source Port: | 49762 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249773802021641 06/23/22-17:55:09.049678 |
SID: | 2021641 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249877802021641 06/23/22-17:56:13.789082 |
SID: | 2021641 |
Source Port: | 49877 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349876802024318 06/23/22-17:56:11.073086 |
SID: | 2024318 |
Source Port: | 49876 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349876802024313 06/23/22-17:56:11.073086 |
SID: | 2024313 |
Source Port: | 49876 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349778802025381 06/23/22-17:55:15.087771 |
SID: | 2025381 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249859802021641 06/23/22-17:55:58.152468 |
SID: | 2021641 |
Source Port: | 49859 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249771802024318 06/23/22-17:55:04.009923 |
SID: | 2024318 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249768802024318 06/23/22-17:54:59.413778 |
SID: | 2024318 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349876802025381 06/23/22-17:56:11.073086 |
SID: | 2025381 |
Source Port: | 49876 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349835802021641 06/23/22-17:55:36.607918 |
SID: | 2021641 |
Source Port: | 49835 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349775802021641 06/23/22-17:55:12.061012 |
SID: | 2021641 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349780802024318 06/23/22-17:55:16.534873 |
SID: | 2024318 |
Source Port: | 49780 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249875802024313 06/23/22-17:56:08.656582 |
SID: | 2024313 |
Source Port: | 49875 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249768802024313 06/23/22-17:54:59.413778 |
SID: | 2024313 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249816802021641 06/23/22-17:55:26.329557 |
SID: | 2021641 |
Source Port: | 49816 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249875802024318 06/23/22-17:56:08.656582 |
SID: | 2024318 |
Source Port: | 49875 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249743802025381 06/23/22-17:54:37.108830 |
SID: | 2025381 |
Source Port: | 49743 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249771802025381 06/23/22-17:55:04.009923 |
SID: | 2025381 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249757802024318 06/23/22-17:54:50.135454 |
SID: | 2024318 |
Source Port: | 49757 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249770802024318 06/23/22-17:55:02.423254 |
SID: | 2024318 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349745802024313 06/23/22-17:54:39.886492 |
SID: | 2024313 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349774802021641 06/23/22-17:55:10.726793 |
SID: | 2021641 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249769802021641 06/23/22-17:55:00.833023 |
SID: | 2021641 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249772802025381 06/23/22-17:55:07.425069 |
SID: | 2025381 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249852802021641 06/23/22-17:55:55.592533 |
SID: | 2021641 |
Source Port: | 49852 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349780802024313 06/23/22-17:55:16.534873 |
SID: | 2024313 |
Source Port: | 49780 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349872802025381 06/23/22-17:56:02.086134 |
SID: | 2025381 |
Source Port: | 49872 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349745802024318 06/23/22-17:54:39.886492 |
SID: | 2024318 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249757802024313 06/23/22-17:54:50.135454 |
SID: | 2024313 |
Source Port: | 49757 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349792802021641 06/23/22-17:55:18.935502 |
SID: | 2021641 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349881802021641 06/23/22-17:56:16.928509 |
SID: | 2021641 |
Source Port: | 49881 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249882802024313 06/23/22-17:56:19.809048 |
SID: | 2024313 |
Source Port: | 49882 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349776802024318 06/23/22-17:55:13.438859 |
SID: | 2024318 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349813802024313 06/23/22-17:55:22.328153 |
SID: | 2024313 |
Source Port: | 49813 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249770802025381 06/23/22-17:55:02.423254 |
SID: | 2025381 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349776802024313 06/23/22-17:55:13.438859 |
SID: | 2024313 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249877802025381 06/23/22-17:56:13.789082 |
SID: | 2025381 |
Source Port: | 49877 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349883802021641 06/23/22-17:56:20.757705 |
SID: | 2021641 |
Source Port: | 49883 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349813802024318 06/23/22-17:55:22.328153 |
SID: | 2024318 |
Source Port: | 49813 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249741802024317 06/23/22-17:54:33.910153 |
SID: | 2024317 |
Source Port: | 49741 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249747802021641 06/23/22-17:54:44.305987 |
SID: | 2021641 |
Source Port: | 49747 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249845802024313 06/23/22-17:55:53.427872 |
SID: | 2024313 |
Source Port: | 49845 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249744802021641 06/23/22-17:54:38.472164 |
SID: | 2021641 |
Source Port: | 49744 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249741802024312 06/23/22-17:54:33.910153 |
SID: | 2024312 |
Source Port: | 49741 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349865802024313 06/23/22-17:56:00.557524 |
SID: | 2024313 |
Source Port: | 49865 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249762802024313 06/23/22-17:54:52.263394 |
SID: | 2024313 |
Source Port: | 49762 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349865802024318 06/23/22-17:56:00.557524 |
SID: | 2024318 |
Source Port: | 49865 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249767802025381 06/23/22-17:54:57.914899 |
SID: | 2025381 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249773802025381 06/23/22-17:55:09.049678 |
SID: | 2025381 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249845802024318 06/23/22-17:55:53.427872 |
SID: | 2024318 |
Source Port: | 49845 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349766802021641 06/23/22-17:54:56.372364 |
SID: | 2021641 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249831802021641 06/23/22-17:55:33.546351 |
SID: | 2021641 |
Source Port: | 49831 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249762802024318 06/23/22-17:54:52.263394 |
SID: | 2024318 |
Source Port: | 49762 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249771802024313 06/23/22-17:55:04.009923 |
SID: | 2024313 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349803802021641 06/23/22-17:55:20.890777 |
SID: | 2021641 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349778802024313 06/23/22-17:55:15.087771 |
SID: | 2024313 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249769802025381 06/23/22-17:55:00.833023 |
SID: | 2025381 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349778802024318 06/23/22-17:55:15.087771 |
SID: | 2024318 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249742802021641 06/23/22-17:54:35.573404 |
SID: | 2021641 |
Source Port: | 49742 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249773802024318 06/23/22-17:55:09.049678 |
SID: | 2024318 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349837802024318 06/23/22-17:55:42.276335 |
SID: | 2024318 |
Source Port: | 49837 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349792802025381 06/23/22-17:55:18.935502 |
SID: | 2025381 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349765802024318 06/23/22-17:54:54.716737 |
SID: | 2024318 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349843802024313 06/23/22-17:55:45.763232 |
SID: | 2024313 |
Source Port: | 49843 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349872802021641 06/23/22-17:56:02.086134 |
SID: | 2021641 |
Source Port: | 49872 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349837802024313 06/23/22-17:55:42.276335 |
SID: | 2024313 |
Source Port: | 49837 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349881802025381 06/23/22-17:56:16.928509 |
SID: | 2025381 |
Source Port: | 49881 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349765802024313 06/23/22-17:54:54.716737 |
SID: | 2024313 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249743802024313 06/23/22-17:54:37.108830 |
SID: | 2024313 |
Source Port: | 49743 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249772802021641 06/23/22-17:55:07.425069 |
SID: | 2021641 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249873802024313 06/23/22-17:56:04.198158 |
SID: | 2024313 |
Source Port: | 49873 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249875802025381 06/23/22-17:56:08.656582 |
SID: | 2025381 |
Source Port: | 49875 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249743802024318 06/23/22-17:54:37.108830 |
SID: | 2024318 |
Source Port: | 49743 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349843802024318 06/23/22-17:55:45.763232 |
SID: | 2024318 |
Source Port: | 49843 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249873802024318 06/23/22-17:56:04.198158 |
SID: | 2024318 |
Source Port: | 49873 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349837802025381 06/23/22-17:55:42.276335 |
SID: | 2025381 |
Source Port: | 49837 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249859802024313 06/23/22-17:55:58.152468 |
SID: | 2024313 |
Source Port: | 49859 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249743802021641 06/23/22-17:54:37.108830 |
SID: | 2021641 |
Source Port: | 49743 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249746802024318 06/23/22-17:54:42.346945 |
SID: | 2024318 |
Source Port: | 49746 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249844802024318 06/23/22-17:55:50.553165 |
SID: | 2024318 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249859802024318 06/23/22-17:55:58.152468 |
SID: | 2024318 |
Source Port: | 49859 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249746802024313 06/23/22-17:54:42.346945 |
SID: | 2024313 |
Source Port: | 49746 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349883802025381 06/23/22-17:56:20.757705 |
SID: | 2025381 |
Source Port: | 49883 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249844802024313 06/23/22-17:55:50.553165 |
SID: | 2024313 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249749802021641 06/23/22-17:54:47.375834 |
SID: | 2021641 |
Source Port: | 49749 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349836802024318 06/23/22-17:55:40.617404 |
SID: | 2024318 |
Source Port: | 49836 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249747802025381 06/23/22-17:54:44.305987 |
SID: | 2025381 |
Source Port: | 49747 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249845802025381 06/23/22-17:55:53.427872 |
SID: | 2025381 |
Source Port: | 49845 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249770802021641 06/23/22-17:55:02.423254 |
SID: | 2021641 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349836802024313 06/23/22-17:55:40.617404 |
SID: | 2024313 |
Source Port: | 49836 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249882802025381 06/23/22-17:56:19.809048 |
SID: | 2025381 |
Source Port: | 49882 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249816802024313 06/23/22-17:55:26.329557 |
SID: | 2024313 |
Source Port: | 49816 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249877802024313 06/23/22-17:56:13.789082 |
SID: | 2024313 |
Source Port: | 49877 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249773802024313 06/23/22-17:55:09.049678 |
SID: | 2024313 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349766802025381 06/23/22-17:54:56.372364 |
SID: | 2025381 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249816802024318 06/23/22-17:55:26.329557 |
SID: | 2024318 |
Source Port: | 49816 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249767802021641 06/23/22-17:54:57.914899 |
SID: | 2021641 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349778802021641 06/23/22-17:55:15.087771 |
SID: | 2021641 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349876802021641 06/23/22-17:56:11.073086 |
SID: | 2021641 |
Source Port: | 49876 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349775802025381 06/23/22-17:55:12.061012 |
SID: | 2025381 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349803802025381 06/23/22-17:55:20.890777 |
SID: | 2025381 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249877802024318 06/23/22-17:56:13.789082 |
SID: | 2024318 |
Source Port: | 49877 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249741802025381 06/23/22-17:54:33.910153 |
SID: | 2025381 |
Source Port: | 49741 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349835802024313 06/23/22-17:55:36.607918 |
SID: | 2024313 |
Source Port: | 49835 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249762802021641 06/23/22-17:54:52.263394 |
SID: | 2021641 |
Source Port: | 49762 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349792802024318 06/23/22-17:55:18.935502 |
SID: | 2024318 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349881802024318 06/23/22-17:56:16.928509 |
SID: | 2024318 |
Source Port: | 49881 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349775802024318 06/23/22-17:55:12.061012 |
SID: | 2024318 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349835802024318 06/23/22-17:55:36.607918 |
SID: | 2024318 |
Source Port: | 49835 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249875802021641 06/23/22-17:56:08.656582 |
SID: | 2021641 |
Source Port: | 49875 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349775802024313 06/23/22-17:55:12.061012 |
SID: | 2024313 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349865802025381 06/23/22-17:56:00.557524 |
SID: | 2025381 |
Source Port: | 49865 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249768802021641 06/23/22-17:54:59.413778 |
SID: | 2021641 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249852802024318 06/23/22-17:55:55.592533 |
SID: | 2024318 |
Source Port: | 49852 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249873802025381 06/23/22-17:56:04.198158 |
SID: | 2025381 |
Source Port: | 49873 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349745802021641 06/23/22-17:54:39.886492 |
SID: | 2021641 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349774802024313 06/23/22-17:55:10.726793 |
SID: | 2024313 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349776802025381 06/23/22-17:55:13.438859 |
SID: | 2025381 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349774802024318 06/23/22-17:55:10.726793 |
SID: | 2024318 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249831802025381 06/23/22-17:55:33.546351 |
SID: | 2025381 |
Source Port: | 49831 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349836802025381 06/23/22-17:55:40.617404 |
SID: | 2025381 |
Source Port: | 49836 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249742802025381 06/23/22-17:54:35.573404 |
SID: | 2025381 |
Source Port: | 49742 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249769802024313 06/23/22-17:55:00.833023 |
SID: | 2024313 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349780802021641 06/23/22-17:55:16.534873 |
SID: | 2021641 |
Source Port: | 49780 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249852802024313 06/23/22-17:55:55.592533 |
SID: | 2024313 |
Source Port: | 49852 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349881802024313 06/23/22-17:56:16.928509 |
SID: | 2024313 |
Source Port: | 49881 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249769802024318 06/23/22-17:55:00.833023 |
SID: | 2024318 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249757802021641 06/23/22-17:54:50.135454 |
SID: | 2021641 |
Source Port: | 49757 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349792802024313 06/23/22-17:55:18.935502 |
SID: | 2024313 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349765802025381 06/23/22-17:54:54.716737 |
SID: | 2025381 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249882802024318 06/23/22-17:56:19.809048 |
SID: | 2024318 |
Source Port: | 49882 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349813802025381 06/23/22-17:55:22.328153 |
SID: | 2025381 |
Source Port: | 49813 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349813802021641 06/23/22-17:55:22.328153 |
SID: | 2021641 |
Source Port: | 49813 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249772802024318 06/23/22-17:55:07.425069 |
SID: | 2024318 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349774802025381 06/23/22-17:55:10.726793 |
SID: | 2025381 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349776802021641 06/23/22-17:55:13.438859 |
SID: | 2021641 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249873802021641 06/23/22-17:56:04.198158 |
SID: | 2021641 |
Source Port: | 49873 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249816802025381 06/23/22-17:55:26.329557 |
SID: | 2025381 |
Source Port: | 49816 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249882802021641 06/23/22-17:56:19.809048 |
SID: | 2021641 |
Source Port: | 49882 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349865802021641 06/23/22-17:56:00.557524 |
SID: | 2021641 |
Source Port: | 49865 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349883802024318 06/23/22-17:56:20.757705 |
SID: | 2024318 |
Source Port: | 49883 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349883802024313 06/23/22-17:56:20.757705 |
SID: | 2024313 |
Source Port: | 49883 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249844802025381 06/23/22-17:55:50.553165 |
SID: | 2025381 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249747802024313 06/23/22-17:54:44.305987 |
SID: | 2024313 |
Source Port: | 49747 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249749802025381 06/23/22-17:54:47.375834 |
SID: | 2025381 |
Source Port: | 49749 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249845802021641 06/23/22-17:55:53.427872 |
SID: | 2021641 |
Source Port: | 49845 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249746802025381 06/23/22-17:54:42.346945 |
SID: | 2025381 |
Source Port: | 49746 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249741802021641 06/23/22-17:54:33.910153 |
SID: | 2021641 |
Source Port: | 49741 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249744802024318 06/23/22-17:54:38.472164 |
SID: | 2024318 |
Source Port: | 49744 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249859802025381 06/23/22-17:55:58.152468 |
SID: | 2025381 |
Source Port: | 49859 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349835802025381 06/23/22-17:55:36.607918 |
SID: | 2025381 |
Source Port: | 49835 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249744802024313 06/23/22-17:54:38.472164 |
SID: | 2024313 |
Source Port: | 49744 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249747802024318 06/23/22-17:54:44.305987 |
SID: | 2024318 |
Source Port: | 49747 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349803802024313 06/23/22-17:55:20.890777 |
SID: | 2024313 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249852802025381 06/23/22-17:55:55.592533 |
SID: | 2025381 |
Source Port: | 49852 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349766802024318 06/23/22-17:54:56.372364 |
SID: | 2024318 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249831802024313 06/23/22-17:55:33.546351 |
SID: | 2024313 |
Source Port: | 49831 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249771802021641 06/23/22-17:55:04.009923 |
SID: | 2021641 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349803802024318 06/23/22-17:55:20.890777 |
SID: | 2024318 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249831802024318 06/23/22-17:55:33.546351 |
SID: | 2024318 |
Source Port: | 49831 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249757802025381 06/23/22-17:54:50.135454 |
SID: | 2025381 |
Source Port: | 49757 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249742802024317 06/23/22-17:54:35.573404 |
SID: | 2024317 |
Source Port: | 49742 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249742802024312 06/23/22-17:54:35.573404 |
SID: | 2024312 |
Source Port: | 49742 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349766802024313 06/23/22-17:54:56.372364 |
SID: | 2024313 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249768802025381 06/23/22-17:54:59.413778 |
SID: | 2025381 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349872802024313 06/23/22-17:56:02.086134 |
SID: | 2024313 |
Source Port: | 49872 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349843802021641 06/23/22-17:55:45.763232 |
SID: | 2021641 |
Source Port: | 49843 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349765802021641 06/23/22-17:54:54.716737 |
SID: | 2021641 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349837802021641 06/23/22-17:55:42.276335 |
SID: | 2021641 |
Source Port: | 49837 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349872802024318 06/23/22-17:56:02.086134 |
SID: | 2024318 |
Source Port: | 49872 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3172.67.154.7249772802024313 06/23/22-17:55:07.425069 |
SID: | 2024313 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3104.21.40.15349780802025381 06/23/22-17:55:16.534873 |
SID: | 2025381 |
Source Port: | 49780 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Source: | Malware Configuration Extractor: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 5_2_00403D74 |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | File source: |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Code function: | 5_2_00404ED4 |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_004BA841 | |
Source: | Code function: | 0_2_004BA641 | |
Source: | Code function: | 0_2_004BA276 | |
Source: | Code function: | 0_2_004BA141 | |
Source: | Code function: | 0_2_004BA541 | |
Source: | Code function: | 0_2_004BA741 | |
Source: | Code function: | 0_2_004BA96F | |
Source: | Code function: | 0_2_004BA36E | |
Source: | Code function: | 0_2_00E3E2E0 | |
Source: | Code function: | 0_2_00E3E2F0 | |
Source: | Code function: | 0_2_00E3C37C | |
Source: | Code function: | 0_2_0523B6FF | |
Source: | Code function: | 0_2_05239F6E | |
Source: | Code function: | 0_2_05239F74 | |
Source: | Code function: | 4_2_002BA276 | |
Source: | Code function: | 4_2_002BA841 | |
Source: | Code function: | 4_2_002BA641 | |
Source: | Code function: | 4_2_002BA96F | |
Source: | Code function: | 4_2_002BA36E | |
Source: | Code function: | 4_2_002BA141 | |
Source: | Code function: | 4_2_002BA541 | |
Source: | Code function: | 4_2_002BA741 | |
Source: | Code function: | 5_2_0040549C | |
Source: | Code function: | 5_2_004029D4 | |
Source: | Code function: | 5_2_006EA841 | |
Source: | Code function: | 5_2_006EA96F | |
Source: | Code function: | 5_2_006EA141 | |
Source: | Code function: | 5_2_006EA541 | |
Source: | Code function: | 5_2_006EA276 | |
Source: | Code function: | 5_2_006EA641 | |
Source: | Code function: | 5_2_006EA36E | |
Source: | Code function: | 5_2_006EA741 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Virustotal: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 5_2_0040650A |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Code function: | 5_2_0040434D |
Source: | Static file information: | |||
Source: | Section loaded: | Jump to behavior |
Source: | Mutant created: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00E3F571 | |
Source: | Code function: | 0_2_00E36946 | |
Source: | Code function: | 0_2_00E3691E | |
Source: | Code function: | 0_2_00E3EC29 | |
Source: | Code function: | 0_2_05239FE1 | |
Source: | Code function: | 5_2_00402AD4 | |
Source: | Code function: | 5_2_00402AFC |
Source: | Static PE information: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Static PE information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 5_2_00403D74 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 5_2_00402B7C |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 5_2_0040317B |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 5_2_00406069 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 5_2_0040D069 | |
Source: | Code function: | 5_2_0040D069 |
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Access Token Manipulation | 1 Disable or Modify Tools | 2 OS Credential Dumping | 1 Account Discovery | Remote Services | 11 Archive Collected Data | Exfiltration Over Other Network Medium | 3 Ingress Tool Transfer | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 11 Process Injection | 11 Deobfuscate/Decode Files or Information | 1 Input Capture | 1 File and Directory Discovery | Remote Desktop Protocol | 2 Data from Local System | Exfiltration Over Bluetooth | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | 13 Obfuscated Files or Information | 2 Credentials in Registry | 13 System Information Discovery | SMB/Windows Admin Shares | 1 Email Collection | Automated Exfiltration | 3 Non-Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | 12 Software Packing | NTDS | 111 Security Software Discovery | Distributed Component Object Model | 1 Input Capture | Scheduled Transfer | 113 Application Layer Protocol | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 11 Masquerading | LSA Secrets | 1 Process Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 21 Virtualization/Sandbox Evasion | Cached Domain Credentials | 21 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | 1 Access Token Manipulation | DCSync | 1 System Owner/User Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | 11 Process Injection | Proc Filesystem | 1 Remote System Discovery | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
30% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
10% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kossa.xyz | 172.67.154.72 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.40.153 | unknown | United States | 13335 | CLOUDFLARENETUS | true | |
172.67.154.72 | kossa.xyz | United States | 13335 | CLOUDFLARENETUS | true |
Joe Sandbox Version: | 35.0.0 Citrine |
Analysis ID: | 651256 |
Start date and time: 23/06/202217:53:08 | 2022-06-23 17:53:08 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 8m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | Informe bancario.pdf.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 24 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@5/3@46/2 |
EGA Information: |
|
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe
- Excluded domains from analysis (whitelisted): www.bing.com, ris.api.iris.microsoft.com, fs.microsoft.com, store-images.s-microsoft.com, login.live.com, sls.update.microsoft.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
- Execution Graph export aborted for target Informe bancario.pdf.exe, PID 6800 because there are no executed function
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
17:54:22 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
104.21.40.153 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
172.67.154.72 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
kossa.xyz | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Informe bancario.pdf.exe.log
Download File
Process: | C:\Users\user\Desktop\Informe bancario.pdf.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.355304211458859 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84j:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzr |
MD5: | FED34146BF2F2FA59DCF8702FCC8232E |
SHA1: | B03BFEA175989D989850CF06FE5E7BBF56EAA00A |
SHA-256: | 123BE4E3590609A008E85501243AF5BC53FA0C26C82A92881B8879524F8C0D5C |
SHA-512: | 1CC89F2ED1DBD70628FA1DC41A32BA0BFA3E81EAE1A1CF3C5F6A48F2DA0BF1F21A5001B8A18B04043C5B8FE4FBE663068D86AA8C4BD8E17933F75687C3178FF6 |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\Informe bancario.pdf.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\414045e2d09286d5db2581e0d955d358_d06ed635-68f6-4e9a-955c-4899f5f57b9a
Download File
Process: | C:\Users\user\Desktop\Informe bancario.pdf.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 46 |
Entropy (8bit): | 1.0424600748477153 |
Encrypted: | false |
SSDEEP: | 3:/lbON:u |
MD5: | 89CA7E02D8B79ED50986F098D5686EC9 |
SHA1: | A602E0D4398F00C827BFCF711066E67718CA1377 |
SHA-256: | 30AC626CBD4A97DB480A0379F6D2540195F594C967B7087A26566E352F24C794 |
SHA-512: | C5F453E32C0297E51BE43F84A7E63302E7D1E471FADF8BB789C22A4D6E03712D26E2B039D6FBDBD9EBD35C4E93EC27F03684A7BBB67C4FADCCE9F6279417B5DE |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.605576053949014 |
TrID: |
|
File name: | Informe bancario.pdf.exe |
File size: | 497664 |
MD5: | 603fe9a434da79407213db7d4b907789 |
SHA1: | 812797eae86b27f54e5caadb021a4c00c31e4a7e |
SHA256: | 07776cc1a0981b4143d63533a5e30f2deb4f545f4d27544cda60f5d07b602593 |
SHA512: | 1e18fd13addd394ed2fddc401e48d111f5da9c2119cf96a57377623e77fd7ca26a51cf49cfc543b0e012303a31d9dd666e397b6ffca858fffebe50417e332d18 |
SSDEEP: | 12288:TpkPRxliW1CCQo4gg4kX5B2tA6fIVeZJPhLn8Nc5UDceiGk:lkPRrhLvLkX50MeZJpLna2UDuR |
TLSH: | CAB4E1E4E3A45EABD843D3BC587C811427A7FB4AC4ACD6057CF6748AA5B23E55093E03 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......b..............0.................. ........@.. ....................................@................................ |
Icon Hash: | 00828e8e8686b000 |
Entrypoint: | 0x47adbe |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x62B4812E [Thu Jun 23 15:05:18 2022 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x7ad6c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x7c000 | 0x444 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x7e000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x78dc4 | 0x78e00 | False | 0.809062338417787 | data | 7.621462978207712 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x7c000 | 0x444 | 0x600 | False | 0.2805989583333333 | data | 2.4690099230174813 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x7e000 | 0xc | 0x200 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_VERSION | 0x7c058 | 0x3e8 | data |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.3172.67.154.7249744802025381 06/23/22-17:54:38.472164 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249767802024313 06/23/22-17:54:57.914899 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349836802021641 06/23/22-17:55:40.617404 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349843802025381 06/23/22-17:55:45.763232 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249746802021641 06/23/22-17:54:42.346945 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249749802024313 06/23/22-17:54:47.375834 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249767802024318 06/23/22-17:54:57.914899 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249770802024313 06/23/22-17:55:02.423254 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349745802025381 06/23/22-17:54:39.886492 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249844802021641 06/23/22-17:55:50.553165 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249749802024318 06/23/22-17:54:47.375834 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249762802025381 06/23/22-17:54:52.263394 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249773802021641 06/23/22-17:55:09.049678 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249877802021641 06/23/22-17:56:13.789082 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349876802024318 06/23/22-17:56:11.073086 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349876802024313 06/23/22-17:56:11.073086 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349778802025381 06/23/22-17:55:15.087771 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249859802021641 06/23/22-17:55:58.152468 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249771802024318 06/23/22-17:55:04.009923 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249768802024318 06/23/22-17:54:59.413778 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349876802025381 06/23/22-17:56:11.073086 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349835802021641 06/23/22-17:55:36.607918 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349775802021641 06/23/22-17:55:12.061012 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349780802024318 06/23/22-17:55:16.534873 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249875802024313 06/23/22-17:56:08.656582 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249768802024313 06/23/22-17:54:59.413778 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249816802021641 06/23/22-17:55:26.329557 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249875802024318 06/23/22-17:56:08.656582 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249743802025381 06/23/22-17:54:37.108830 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249771802025381 06/23/22-17:55:04.009923 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249757802024318 06/23/22-17:54:50.135454 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249770802024318 06/23/22-17:55:02.423254 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349745802024313 06/23/22-17:54:39.886492 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349774802021641 06/23/22-17:55:10.726793 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249769802021641 06/23/22-17:55:00.833023 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249772802025381 06/23/22-17:55:07.425069 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249852802021641 06/23/22-17:55:55.592533 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349780802024313 06/23/22-17:55:16.534873 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349872802025381 06/23/22-17:56:02.086134 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349745802024318 06/23/22-17:54:39.886492 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249757802024313 06/23/22-17:54:50.135454 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349792802021641 06/23/22-17:55:18.935502 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349881802021641 06/23/22-17:56:16.928509 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249882802024313 06/23/22-17:56:19.809048 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349776802024318 06/23/22-17:55:13.438859 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349813802024313 06/23/22-17:55:22.328153 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249770802025381 06/23/22-17:55:02.423254 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349776802024313 06/23/22-17:55:13.438859 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249877802025381 06/23/22-17:56:13.789082 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349883802021641 06/23/22-17:56:20.757705 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349813802024318 06/23/22-17:55:22.328153 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249741802024317 06/23/22-17:54:33.910153 | TCP | 2024317 | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249747802021641 06/23/22-17:54:44.305987 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249845802024313 06/23/22-17:55:53.427872 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249744802021641 06/23/22-17:54:38.472164 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249741802024312 06/23/22-17:54:33.910153 | TCP | 2024312 | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349865802024313 06/23/22-17:56:00.557524 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249762802024313 06/23/22-17:54:52.263394 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349865802024318 06/23/22-17:56:00.557524 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249767802025381 06/23/22-17:54:57.914899 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249773802025381 06/23/22-17:55:09.049678 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249845802024318 06/23/22-17:55:53.427872 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349766802021641 06/23/22-17:54:56.372364 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249831802021641 06/23/22-17:55:33.546351 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249762802024318 06/23/22-17:54:52.263394 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249771802024313 06/23/22-17:55:04.009923 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349803802021641 06/23/22-17:55:20.890777 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349778802024313 06/23/22-17:55:15.087771 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249769802025381 06/23/22-17:55:00.833023 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349778802024318 06/23/22-17:55:15.087771 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249742802021641 06/23/22-17:54:35.573404 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249773802024318 06/23/22-17:55:09.049678 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349837802024318 06/23/22-17:55:42.276335 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349792802025381 06/23/22-17:55:18.935502 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349765802024318 06/23/22-17:54:54.716737 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349843802024313 06/23/22-17:55:45.763232 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349872802021641 06/23/22-17:56:02.086134 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349837802024313 06/23/22-17:55:42.276335 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349881802025381 06/23/22-17:56:16.928509 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349765802024313 06/23/22-17:54:54.716737 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249743802024313 06/23/22-17:54:37.108830 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249772802021641 06/23/22-17:55:07.425069 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249873802024313 06/23/22-17:56:04.198158 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249875802025381 06/23/22-17:56:08.656582 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249743802024318 06/23/22-17:54:37.108830 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349843802024318 06/23/22-17:55:45.763232 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249873802024318 06/23/22-17:56:04.198158 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349837802025381 06/23/22-17:55:42.276335 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249859802024313 06/23/22-17:55:58.152468 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249743802021641 06/23/22-17:54:37.108830 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249746802024318 06/23/22-17:54:42.346945 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249844802024318 06/23/22-17:55:50.553165 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249859802024318 06/23/22-17:55:58.152468 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249746802024313 06/23/22-17:54:42.346945 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349883802025381 06/23/22-17:56:20.757705 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249844802024313 06/23/22-17:55:50.553165 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249749802021641 06/23/22-17:54:47.375834 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349836802024318 06/23/22-17:55:40.617404 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249747802025381 06/23/22-17:54:44.305987 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249845802025381 06/23/22-17:55:53.427872 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249770802021641 06/23/22-17:55:02.423254 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349836802024313 06/23/22-17:55:40.617404 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249882802025381 06/23/22-17:56:19.809048 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249816802024313 06/23/22-17:55:26.329557 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249877802024313 06/23/22-17:56:13.789082 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249773802024313 06/23/22-17:55:09.049678 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349766802025381 06/23/22-17:54:56.372364 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249816802024318 06/23/22-17:55:26.329557 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249767802021641 06/23/22-17:54:57.914899 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349778802021641 06/23/22-17:55:15.087771 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349876802021641 06/23/22-17:56:11.073086 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349775802025381 06/23/22-17:55:12.061012 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349803802025381 06/23/22-17:55:20.890777 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249877802024318 06/23/22-17:56:13.789082 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249741802025381 06/23/22-17:54:33.910153 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349835802024313 06/23/22-17:55:36.607918 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249762802021641 06/23/22-17:54:52.263394 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349792802024318 06/23/22-17:55:18.935502 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349881802024318 06/23/22-17:56:16.928509 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349775802024318 06/23/22-17:55:12.061012 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349835802024318 06/23/22-17:55:36.607918 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249875802021641 06/23/22-17:56:08.656582 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349775802024313 06/23/22-17:55:12.061012 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349865802025381 06/23/22-17:56:00.557524 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249768802021641 06/23/22-17:54:59.413778 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249852802024318 06/23/22-17:55:55.592533 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249873802025381 06/23/22-17:56:04.198158 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349745802021641 06/23/22-17:54:39.886492 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349774802024313 06/23/22-17:55:10.726793 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349776802025381 06/23/22-17:55:13.438859 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349774802024318 06/23/22-17:55:10.726793 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249831802025381 06/23/22-17:55:33.546351 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349836802025381 06/23/22-17:55:40.617404 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249742802025381 06/23/22-17:54:35.573404 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249769802024313 06/23/22-17:55:00.833023 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349780802021641 06/23/22-17:55:16.534873 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249852802024313 06/23/22-17:55:55.592533 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349881802024313 06/23/22-17:56:16.928509 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249769802024318 06/23/22-17:55:00.833023 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249757802021641 06/23/22-17:54:50.135454 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349792802024313 06/23/22-17:55:18.935502 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349765802025381 06/23/22-17:54:54.716737 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249882802024318 06/23/22-17:56:19.809048 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349813802025381 06/23/22-17:55:22.328153 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349813802021641 06/23/22-17:55:22.328153 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249772802024318 06/23/22-17:55:07.425069 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349774802025381 06/23/22-17:55:10.726793 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349776802021641 06/23/22-17:55:13.438859 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249873802021641 06/23/22-17:56:04.198158 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249816802025381 06/23/22-17:55:26.329557 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249882802021641 06/23/22-17:56:19.809048 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349865802021641 06/23/22-17:56:00.557524 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349883802024318 06/23/22-17:56:20.757705 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349883802024313 06/23/22-17:56:20.757705 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249844802025381 06/23/22-17:55:50.553165 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249747802024313 06/23/22-17:54:44.305987 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249749802025381 06/23/22-17:54:47.375834 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249845802021641 06/23/22-17:55:53.427872 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249746802025381 06/23/22-17:54:42.346945 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249741802021641 06/23/22-17:54:33.910153 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249744802024318 06/23/22-17:54:38.472164 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249859802025381 06/23/22-17:55:58.152468 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349835802025381 06/23/22-17:55:36.607918 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249744802024313 06/23/22-17:54:38.472164 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249747802024318 06/23/22-17:54:44.305987 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349803802024313 06/23/22-17:55:20.890777 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249852802025381 06/23/22-17:55:55.592533 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349766802024318 06/23/22-17:54:56.372364 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249831802024313 06/23/22-17:55:33.546351 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249771802021641 06/23/22-17:55:04.009923 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349803802024318 06/23/22-17:55:20.890777 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249831802024318 06/23/22-17:55:33.546351 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249757802025381 06/23/22-17:54:50.135454 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249742802024317 06/23/22-17:54:35.573404 | TCP | 2024317 | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2 | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3172.67.154.7249742802024312 06/23/22-17:54:35.573404 | TCP | 2024312 | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349766802024313 06/23/22-17:54:56.372364 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249768802025381 06/23/22-17:54:59.413778 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349872802024313 06/23/22-17:56:02.086134 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349843802021641 06/23/22-17:55:45.763232 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349765802021641 06/23/22-17:54:54.716737 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349837802021641 06/23/22-17:55:42.276335 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3104.21.40.15349872802024318 06/23/22-17:56:02.086134 | TCP | 2024318 | ET TROJAN LokiBot Request for C2 Commands Detected M2 | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
192.168.2.3172.67.154.7249772802024313 06/23/22-17:55:07.425069 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
192.168.2.3104.21.40.15349780802025381 06/23/22-17:55:16.534873 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 23, 2022 17:54:33.873667955 CEST | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:33.906069040 CEST | 80 | 49741 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:33.907007933 CEST | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:33.910152912 CEST | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:33.942464113 CEST | 80 | 49741 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:33.943350077 CEST | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:33.975655079 CEST | 80 | 49741 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:34.295411110 CEST | 80 | 49741 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:34.295753002 CEST | 80 | 49741 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:34.296437025 CEST | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:34.296827078 CEST | 49741 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:34.329353094 CEST | 80 | 49741 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:35.537940025 CEST | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:35.570380926 CEST | 80 | 49742 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:35.570612907 CEST | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:35.573404074 CEST | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:35.605788946 CEST | 80 | 49742 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:35.605947018 CEST | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:35.638160944 CEST | 80 | 49742 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:35.979684114 CEST | 80 | 49742 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:35.979902029 CEST | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:36.012144089 CEST | 80 | 49742 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:36.218437910 CEST | 80 | 49742 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:36.218904018 CEST | 49742 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:37.072376966 CEST | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:37.104892015 CEST | 80 | 49743 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:37.105021000 CEST | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:37.108829975 CEST | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:37.141222000 CEST | 80 | 49743 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:37.141366959 CEST | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:37.173758030 CEST | 80 | 49743 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:37.484196901 CEST | 80 | 49743 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:37.484416008 CEST | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:37.517374039 CEST | 80 | 49743 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:37.722713947 CEST | 80 | 49743 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:37.723525047 CEST | 49743 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:38.436321020 CEST | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:38.468525887 CEST | 80 | 49744 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:38.468648911 CEST | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:38.472163916 CEST | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:38.504229069 CEST | 80 | 49744 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:38.504328012 CEST | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:38.536420107 CEST | 80 | 49744 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:38.845036030 CEST | 80 | 49744 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:38.845256090 CEST | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:38.845357895 CEST | 80 | 49744 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:38.845438957 CEST | 49744 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:38.877574921 CEST | 80 | 49744 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:39.866887093 CEST | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:39.883833885 CEST | 80 | 49745 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:39.883953094 CEST | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:39.886492014 CEST | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:39.903594017 CEST | 80 | 49745 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:39.903673887 CEST | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:39.920392036 CEST | 80 | 49745 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:40.249713898 CEST | 80 | 49745 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:40.249761105 CEST | 80 | 49745 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:40.249830961 CEST | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:40.249897957 CEST | 49745 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:40.266798973 CEST | 80 | 49745 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:42.309146881 CEST | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:42.341340065 CEST | 80 | 49746 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:42.343955994 CEST | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:42.346945047 CEST | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:42.380894899 CEST | 80 | 49746 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:42.383651018 CEST | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:42.417906046 CEST | 80 | 49746 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:42.724734068 CEST | 80 | 49746 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:42.724874020 CEST | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:42.757117033 CEST | 80 | 49746 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:42.961307049 CEST | 80 | 49746 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:42.961420059 CEST | 49746 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:44.269737005 CEST | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:44.302773952 CEST | 80 | 49747 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:44.303009033 CEST | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:44.305986881 CEST | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:44.338363886 CEST | 80 | 49747 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:44.338661909 CEST | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:44.371105909 CEST | 80 | 49747 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:44.695508003 CEST | 80 | 49747 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:44.695698977 CEST | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:44.695736885 CEST | 80 | 49747 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:44.695832968 CEST | 49747 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:44.728557110 CEST | 80 | 49747 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:47.267076969 CEST | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:47.299616098 CEST | 80 | 49749 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:47.299771070 CEST | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:47.375833988 CEST | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:47.408014059 CEST | 80 | 49749 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:47.408128023 CEST | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:47.440428972 CEST | 80 | 49749 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:47.760540009 CEST | 80 | 49749 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:47.760590076 CEST | 80 | 49749 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:47.760878086 CEST | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:48.548027992 CEST | 49749 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:48.580526114 CEST | 80 | 49749 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:50.091150045 CEST | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:50.123351097 CEST | 80 | 49757 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:50.123565912 CEST | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:50.135453939 CEST | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:50.167676926 CEST | 80 | 49757 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:50.167802095 CEST | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:50.200040102 CEST | 80 | 49757 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:50.515275002 CEST | 80 | 49757 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:50.515558958 CEST | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:50.547643900 CEST | 80 | 49757 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:50.753053904 CEST | 80 | 49757 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:50.754034042 CEST | 49757 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:52.228221893 CEST | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:52.260663986 CEST | 80 | 49762 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:52.260859966 CEST | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:52.263394117 CEST | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:52.295691013 CEST | 80 | 49762 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:52.295813084 CEST | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:52.328241110 CEST | 80 | 49762 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:52.635915995 CEST | 80 | 49762 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:52.635962009 CEST | 80 | 49762 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:52.636127949 CEST | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:52.636178017 CEST | 49762 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:52.668570042 CEST | 80 | 49762 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:54.696646929 CEST | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:54.713877916 CEST | 80 | 49765 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:54.714032888 CEST | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:54.716737032 CEST | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:54.733916044 CEST | 80 | 49765 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:54.734097958 CEST | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:54.751332998 CEST | 80 | 49765 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:55.074867964 CEST | 80 | 49765 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:55.075005054 CEST | 80 | 49765 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:55.075149059 CEST | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:55.075551987 CEST | 49765 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:55.092658043 CEST | 80 | 49765 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:56.349472046 CEST | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:56.366348982 CEST | 80 | 49766 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:56.366476059 CEST | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:56.372364044 CEST | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:56.389240980 CEST | 80 | 49766 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:56.389347076 CEST | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:56.406162977 CEST | 80 | 49766 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:56.739352942 CEST | 80 | 49766 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:56.739480972 CEST | 80 | 49766 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:56.739686012 CEST | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:56.739734888 CEST | 49766 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:54:56.756691933 CEST | 80 | 49766 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:54:57.879748106 CEST | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:57.911891937 CEST | 80 | 49767 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:57.912018061 CEST | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:57.914899111 CEST | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:57.946989059 CEST | 80 | 49767 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:57.947086096 CEST | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:57.979180098 CEST | 80 | 49767 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:58.307390928 CEST | 80 | 49767 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:58.307514906 CEST | 80 | 49767 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:58.307595015 CEST | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:58.308254004 CEST | 49767 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:58.339797020 CEST | 80 | 49767 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:59.378288984 CEST | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:59.410649061 CEST | 80 | 49768 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:59.410748959 CEST | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:59.413778067 CEST | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:59.446037054 CEST | 80 | 49768 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:59.446124077 CEST | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:59.478368044 CEST | 80 | 49768 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:59.812854052 CEST | 80 | 49768 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:54:59.813637972 CEST | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:54:59.845971107 CEST | 80 | 49768 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:00.053103924 CEST | 80 | 49768 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:00.053186893 CEST | 49768 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:00.797518969 CEST | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:00.830113888 CEST | 80 | 49769 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:00.830297947 CEST | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:00.833023071 CEST | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:00.866092920 CEST | 80 | 49769 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:00.866178989 CEST | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:00.898600101 CEST | 80 | 49769 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:01.207211018 CEST | 80 | 49769 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:01.207259893 CEST | 80 | 49769 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:01.207357883 CEST | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:01.207787991 CEST | 49769 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:01.241281986 CEST | 80 | 49769 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:02.387921095 CEST | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:02.420561075 CEST | 80 | 49770 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:02.420698881 CEST | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:02.423254013 CEST | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:02.458586931 CEST | 80 | 49770 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:02.458756924 CEST | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:02.491401911 CEST | 80 | 49770 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:02.800951004 CEST | 80 | 49770 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:02.801076889 CEST | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:02.801292896 CEST | 80 | 49770 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:02.801484108 CEST | 49770 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:02.833559990 CEST | 80 | 49770 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:03.970961094 CEST | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:04.003825903 CEST | 80 | 49771 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:04.003966093 CEST | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:04.009922981 CEST | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:04.042598009 CEST | 80 | 49771 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:04.043416977 CEST | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:04.076169968 CEST | 80 | 49771 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:04.389384031 CEST | 80 | 49771 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:04.389446020 CEST | 80 | 49771 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:04.389539003 CEST | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:04.389596939 CEST | 49771 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:04.422316074 CEST | 80 | 49771 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:07.386195898 CEST | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:07.418771029 CEST | 80 | 49772 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:07.418950081 CEST | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:07.425069094 CEST | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:07.457503080 CEST | 80 | 49772 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:07.457617044 CEST | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:07.490065098 CEST | 80 | 49772 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:07.799252033 CEST | 80 | 49772 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:07.799305916 CEST | 80 | 49772 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:07.799386024 CEST | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:07.799433947 CEST | 49772 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:07.831866026 CEST | 80 | 49772 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:09.010090113 CEST | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:09.042787075 CEST | 80 | 49773 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:09.043050051 CEST | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:09.049678087 CEST | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:09.081998110 CEST | 80 | 49773 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:09.082096100 CEST | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:09.114403009 CEST | 80 | 49773 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:09.424262047 CEST | 80 | 49773 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:09.424314022 CEST | 80 | 49773 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:09.424427032 CEST | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:09.424555063 CEST | 49773 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:09.457093000 CEST | 80 | 49773 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:10.704790115 CEST | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:10.722934961 CEST | 80 | 49774 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:10.723962069 CEST | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:10.726793051 CEST | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:10.743774891 CEST | 80 | 49774 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:10.744281054 CEST | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:10.761107922 CEST | 80 | 49774 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:11.087935925 CEST | 80 | 49774 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:11.088032961 CEST | 80 | 49774 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:11.088200092 CEST | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:11.088656902 CEST | 49774 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:11.105549097 CEST | 80 | 49774 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:12.041100979 CEST | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:12.058124065 CEST | 80 | 49775 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:12.058326006 CEST | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:12.061012030 CEST | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:12.077924013 CEST | 80 | 49775 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:12.078103065 CEST | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:12.095444918 CEST | 80 | 49775 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:12.409252882 CEST | 80 | 49775 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:12.409285069 CEST | 80 | 49775 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:12.409548044 CEST | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:12.409605980 CEST | 49775 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:12.426570892 CEST | 80 | 49775 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:13.412720919 CEST | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:13.429891109 CEST | 80 | 49776 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:13.429989100 CEST | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:13.438858986 CEST | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:13.455876112 CEST | 80 | 49776 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:13.455945015 CEST | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:13.472982883 CEST | 80 | 49776 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:13.814687014 CEST | 80 | 49776 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:13.814778090 CEST | 80 | 49776 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:13.814810038 CEST | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:13.814856052 CEST | 49776 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:13.831964970 CEST | 80 | 49776 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:15.067784071 CEST | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:15.084860086 CEST | 80 | 49778 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:15.084968090 CEST | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:15.087770939 CEST | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:15.104696035 CEST | 80 | 49778 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:15.104842901 CEST | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:15.121912003 CEST | 80 | 49778 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:15.450156927 CEST | 80 | 49778 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:15.450323105 CEST | 80 | 49778 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:15.450355053 CEST | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:15.450411081 CEST | 49778 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:15.467324972 CEST | 80 | 49778 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:16.509201050 CEST | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:16.527266026 CEST | 80 | 49780 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:16.531153917 CEST | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:16.534873009 CEST | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:16.553278923 CEST | 80 | 49780 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:16.555150032 CEST | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:16.572027922 CEST | 80 | 49780 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:16.906121969 CEST | 80 | 49780 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:16.906280994 CEST | 80 | 49780 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:16.906361103 CEST | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:16.906408072 CEST | 49780 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:16.923202038 CEST | 80 | 49780 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:18.911736965 CEST | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:18.928652048 CEST | 80 | 49792 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:18.928884983 CEST | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:18.935502052 CEST | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:18.952414036 CEST | 80 | 49792 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:18.953016043 CEST | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:18.969857931 CEST | 80 | 49792 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:19.293885946 CEST | 80 | 49792 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:19.294802904 CEST | 80 | 49792 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:19.294959068 CEST | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:19.295030117 CEST | 49792 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:19.311779976 CEST | 80 | 49792 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:20.870438099 CEST | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:20.887736082 CEST | 80 | 49803 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:20.887871027 CEST | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:20.890777111 CEST | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:20.907794952 CEST | 80 | 49803 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:20.907857895 CEST | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:20.924964905 CEST | 80 | 49803 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:21.252073050 CEST | 80 | 49803 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:21.252096891 CEST | 80 | 49803 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:21.252162933 CEST | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:21.252182007 CEST | 49803 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:21.269140959 CEST | 80 | 49803 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:22.293987036 CEST | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:22.311539888 CEST | 80 | 49813 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:22.311667919 CEST | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:22.328152895 CEST | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:22.346501112 CEST | 80 | 49813 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:22.346621990 CEST | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:22.364960909 CEST | 80 | 49813 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:22.691435099 CEST | 80 | 49813 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:22.691462994 CEST | 80 | 49813 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:22.691627026 CEST | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:22.746881962 CEST | 49813 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:22.763799906 CEST | 80 | 49813 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:26.294692993 CEST | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:26.326750040 CEST | 80 | 49816 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:26.326874018 CEST | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:26.329556942 CEST | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:26.361731052 CEST | 80 | 49816 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:26.361991882 CEST | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:26.394181967 CEST | 80 | 49816 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:26.709573984 CEST | 80 | 49816 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:26.709625959 CEST | 80 | 49816 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:26.709717035 CEST | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:26.709744930 CEST | 49816 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:26.741976023 CEST | 80 | 49816 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:33.510468006 CEST | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:33.542799950 CEST | 80 | 49831 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:33.542982101 CEST | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:33.546350956 CEST | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:33.578455925 CEST | 80 | 49831 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:33.578521013 CEST | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:33.610555887 CEST | 80 | 49831 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:33.938213110 CEST | 80 | 49831 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:33.938337088 CEST | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:33.970422029 CEST | 80 | 49831 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:34.177958965 CEST | 80 | 49831 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:34.178178072 CEST | 49831 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:36.580209970 CEST | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:36.597132921 CEST | 80 | 49835 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:36.597289085 CEST | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:36.607918024 CEST | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:36.624784946 CEST | 80 | 49835 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:36.624871969 CEST | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:36.641727924 CEST | 80 | 49835 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:36.962721109 CEST | 80 | 49835 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:36.962759972 CEST | 80 | 49835 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:36.963495970 CEST | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:36.963521004 CEST | 49835 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:36.980442047 CEST | 80 | 49835 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:40.593314886 CEST | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:40.610479116 CEST | 80 | 49836 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:40.610671043 CEST | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:40.617403984 CEST | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:40.634263039 CEST | 80 | 49836 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:40.634340048 CEST | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:40.651411057 CEST | 80 | 49836 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:40.986800909 CEST | 80 | 49836 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:40.989020109 CEST | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:41.005964994 CEST | 80 | 49836 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:41.211616993 CEST | 80 | 49836 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:41.211695910 CEST | 49836 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:42.256494045 CEST | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:42.273444891 CEST | 80 | 49837 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:42.273540974 CEST | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:42.276335001 CEST | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:42.293207884 CEST | 80 | 49837 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:42.295589924 CEST | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:42.312597036 CEST | 80 | 49837 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:42.633047104 CEST | 80 | 49837 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:42.633095026 CEST | 80 | 49837 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:42.633194923 CEST | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:42.633239031 CEST | 49837 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:42.650068998 CEST | 80 | 49837 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:45.740482092 CEST | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:45.757973909 CEST | 80 | 49843 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:45.758163929 CEST | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:45.763231993 CEST | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:45.780457973 CEST | 80 | 49843 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:45.780632973 CEST | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:45.797717094 CEST | 80 | 49843 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:46.128196955 CEST | 80 | 49843 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:46.128386021 CEST | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:46.145586967 CEST | 80 | 49843 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:46.352329016 CEST | 80 | 49843 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:55:46.353497982 CEST | 49843 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:55:50.516387939 CEST | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:50.548914909 CEST | 80 | 49844 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:50.549067020 CEST | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:50.553164959 CEST | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:50.585647106 CEST | 80 | 49844 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:50.585745096 CEST | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:50.619381905 CEST | 80 | 49844 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:50.924413919 CEST | 80 | 49844 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:50.924550056 CEST | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:50.956804037 CEST | 80 | 49844 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:51.158474922 CEST | 80 | 49844 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:51.158596039 CEST | 49844 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:53.392102957 CEST | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:53.424693108 CEST | 80 | 49845 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:53.424833059 CEST | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:53.427871943 CEST | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:53.460294008 CEST | 80 | 49845 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:53.460439920 CEST | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:53.492924929 CEST | 80 | 49845 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:53.809928894 CEST | 80 | 49845 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:53.810041904 CEST | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:53.810168028 CEST | 80 | 49845 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:53.810233116 CEST | 49845 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:53.842550993 CEST | 80 | 49845 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:55.554249048 CEST | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:55.586833954 CEST | 80 | 49852 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:55.588546038 CEST | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:55.592533112 CEST | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:55.624906063 CEST | 80 | 49852 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:55.625174046 CEST | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:55.657535076 CEST | 80 | 49852 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:55.968697071 CEST | 80 | 49852 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:55.968853951 CEST | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:56.001346111 CEST | 80 | 49852 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:56.207880020 CEST | 80 | 49852 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:56.208005905 CEST | 49852 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:58.115633965 CEST | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:58.148004055 CEST | 80 | 49859 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:58.148471117 CEST | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:58.152467966 CEST | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:58.184746027 CEST | 80 | 49859 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:58.185668945 CEST | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:58.218033075 CEST | 80 | 49859 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:58.564342022 CEST | 80 | 49859 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:58.565049887 CEST | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:55:58.597362995 CEST | 80 | 49859 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:58.802684069 CEST | 80 | 49859 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:55:58.802822113 CEST | 49859 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:00.537055016 CEST | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:00.554126978 CEST | 80 | 49865 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:00.554302931 CEST | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:00.557523966 CEST | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:00.574472904 CEST | 80 | 49865 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:00.574569941 CEST | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:00.591449022 CEST | 80 | 49865 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:00.910413980 CEST | 80 | 49865 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:00.910458088 CEST | 80 | 49865 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:00.910520077 CEST | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:00.910573006 CEST | 49865 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:00.927710056 CEST | 80 | 49865 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:02.065193892 CEST | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:02.082235098 CEST | 80 | 49872 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:02.082391024 CEST | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:02.086133957 CEST | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:02.103436947 CEST | 80 | 49872 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:02.103677034 CEST | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:02.123186111 CEST | 80 | 49872 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:02.444869041 CEST | 80 | 49872 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:02.444930077 CEST | 80 | 49872 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:02.445018053 CEST | 49872 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:02.461910963 CEST | 80 | 49872 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:04.161947012 CEST | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:04.194277048 CEST | 80 | 49873 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:04.194350958 CEST | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:04.198158026 CEST | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:04.230424881 CEST | 80 | 49873 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:04.230531931 CEST | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:04.262775898 CEST | 80 | 49873 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:04.571379900 CEST | 80 | 49873 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:04.571463108 CEST | 80 | 49873 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:04.571659088 CEST | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:04.572055101 CEST | 49873 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:04.604469061 CEST | 80 | 49873 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:08.620399952 CEST | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:08.652993917 CEST | 80 | 49875 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:08.653135061 CEST | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:08.656582117 CEST | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:08.688949108 CEST | 80 | 49875 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:08.689090967 CEST | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:08.721857071 CEST | 80 | 49875 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:09.034661055 CEST | 80 | 49875 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:09.034745932 CEST | 80 | 49875 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:09.034789085 CEST | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:09.034835100 CEST | 49875 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:09.067070007 CEST | 80 | 49875 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:11.051812887 CEST | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:11.068639040 CEST | 80 | 49876 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:11.068911076 CEST | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:11.073086023 CEST | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:11.089853048 CEST | 80 | 49876 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:11.089920998 CEST | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:11.106777906 CEST | 80 | 49876 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:11.421587944 CEST | 80 | 49876 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:11.421665907 CEST | 80 | 49876 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:11.421782017 CEST | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:11.426265955 CEST | 49876 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:11.443190098 CEST | 80 | 49876 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:13.753844976 CEST | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:13.786319017 CEST | 80 | 49877 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:13.786420107 CEST | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:13.789082050 CEST | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:13.821399927 CEST | 80 | 49877 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:13.821517944 CEST | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:13.854238987 CEST | 80 | 49877 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:14.167265892 CEST | 80 | 49877 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:14.167392015 CEST | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:14.167510033 CEST | 80 | 49877 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:14.167574883 CEST | 49877 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:14.199888945 CEST | 80 | 49877 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:16.870012999 CEST | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:16.886775970 CEST | 80 | 49881 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:16.886871099 CEST | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:16.928508997 CEST | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:16.945116997 CEST | 80 | 49881 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:16.945166111 CEST | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:16.961759090 CEST | 80 | 49881 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:17.284101009 CEST | 80 | 49881 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:17.284121037 CEST | 80 | 49881 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:17.284183979 CEST | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:17.284246922 CEST | 49881 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:17.301050901 CEST | 80 | 49881 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:19.774075031 CEST | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:19.806118011 CEST | 80 | 49882 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:19.806247950 CEST | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:19.809047937 CEST | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:19.841156960 CEST | 80 | 49882 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:19.841264963 CEST | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:19.873234034 CEST | 80 | 49882 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:20.189312935 CEST | 80 | 49882 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:20.189451933 CEST | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:20.222158909 CEST | 80 | 49882 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:20.426688910 CEST | 80 | 49882 | 172.67.154.72 | 192.168.2.3 |
Jun 23, 2022 17:56:20.426822901 CEST | 49882 | 80 | 192.168.2.3 | 172.67.154.72 |
Jun 23, 2022 17:56:20.735656977 CEST | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:20.752676964 CEST | 80 | 49883 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:20.752820969 CEST | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:20.757704973 CEST | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:20.774638891 CEST | 80 | 49883 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:20.774715900 CEST | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:20.791732073 CEST | 80 | 49883 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:21.122421980 CEST | 80 | 49883 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:21.122534037 CEST | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
Jun 23, 2022 17:56:21.139591932 CEST | 80 | 49883 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:21.346590042 CEST | 80 | 49883 | 104.21.40.153 | 192.168.2.3 |
Jun 23, 2022 17:56:21.346663952 CEST | 49883 | 80 | 192.168.2.3 | 104.21.40.153 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 23, 2022 17:54:33.833693981 CEST | 49316 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:33.859457970 CEST | 53 | 49316 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:35.517091990 CEST | 56417 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:35.536612988 CEST | 53 | 56417 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:37.046273947 CEST | 55923 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:37.070851088 CEST | 53 | 55923 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:38.413971901 CEST | 57723 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:38.431252003 CEST | 53 | 57723 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:39.833098888 CEST | 58116 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:39.858500004 CEST | 53 | 58116 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:42.271841049 CEST | 57421 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:42.305263996 CEST | 53 | 57421 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:44.249469042 CEST | 65358 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:44.268577099 CEST | 53 | 65358 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:47.204190016 CEST | 53802 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:47.230014086 CEST | 53 | 53802 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:50.070828915 CEST | 63332 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:50.089931011 CEST | 53 | 63332 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:52.207909107 CEST | 49327 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:52.227092981 CEST | 53 | 49327 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:54.671829939 CEST | 58981 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:54.695344925 CEST | 53 | 58981 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:56.328485966 CEST | 64452 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:56.346199989 CEST | 53 | 64452 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:57.859044075 CEST | 61380 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:57.878499985 CEST | 53 | 61380 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:54:59.359349012 CEST | 63146 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:54:59.376538992 CEST | 53 | 63146 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:00.776829958 CEST | 52985 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:00.796344042 CEST | 53 | 52985 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:02.366936922 CEST | 58625 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:02.386096954 CEST | 53 | 58625 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:03.948007107 CEST | 52810 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:03.969122887 CEST | 53 | 52810 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:07.364010096 CEST | 50778 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:07.383429050 CEST | 53 | 50778 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:08.991691113 CEST | 55151 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:09.008948088 CEST | 53 | 55151 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:10.683821917 CEST | 59795 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:10.703425884 CEST | 53 | 59795 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:12.016415119 CEST | 59390 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:12.039047003 CEST | 53 | 59390 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:13.382803917 CEST | 64816 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:13.407774925 CEST | 53 | 64816 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:15.005296946 CEST | 53816 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:15.025069952 CEST | 53 | 53816 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:16.487935066 CEST | 60640 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:16.508002996 CEST | 53 | 60640 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:18.880110025 CEST | 52581 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:18.899779081 CEST | 53 | 52581 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:20.849235058 CEST | 50450 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:20.869082928 CEST | 53 | 50450 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:22.244772911 CEST | 64941 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:22.262568951 CEST | 53 | 64941 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:26.274383068 CEST | 61877 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:26.293586969 CEST | 53 | 61877 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:33.486325979 CEST | 62547 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:33.503941059 CEST | 53 | 62547 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:36.560930014 CEST | 60110 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:36.578289032 CEST | 53 | 60110 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:40.570740938 CEST | 49230 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:40.590874910 CEST | 53 | 49230 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:42.235366106 CEST | 57442 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:42.254795074 CEST | 53 | 57442 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:45.719465971 CEST | 65334 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:45.739217043 CEST | 53 | 65334 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:50.492064953 CEST | 52487 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:50.511487961 CEST | 53 | 52487 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:53.366695881 CEST | 51994 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:53.386226892 CEST | 53 | 51994 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:55.533931971 CEST | 51658 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:55.552799940 CEST | 53 | 51658 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:55:58.096735954 CEST | 58950 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:55:58.114485025 CEST | 53 | 58950 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:00.509530067 CEST | 53883 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:00.529114008 CEST | 53 | 53883 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:02.044512987 CEST | 59065 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:02.063860893 CEST | 53 | 59065 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:04.141248941 CEST | 55686 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:04.160404921 CEST | 53 | 55686 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:08.598506927 CEST | 64589 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:08.618109941 CEST | 53 | 64589 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:11.030992985 CEST | 64934 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:11.050276995 CEST | 53 | 64934 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:13.735444069 CEST | 55795 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:13.752243996 CEST | 53 | 55795 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:16.851468086 CEST | 64635 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:16.868690968 CEST | 53 | 64635 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:19.753016949 CEST | 55269 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:19.772675037 CEST | 53 | 55269 | 8.8.8.8 | 192.168.2.3 |
Jun 23, 2022 17:56:20.715711117 CEST | 63083 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 23, 2022 17:56:20.735198021 CEST | 53 | 63083 | 8.8.8.8 | 192.168.2.3 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Jun 23, 2022 17:54:33.833693981 CEST | 192.168.2.3 | 8.8.8.8 | 0xc3fd | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:35.517091990 CEST | 192.168.2.3 | 8.8.8.8 | 0xcba5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:37.046273947 CEST | 192.168.2.3 | 8.8.8.8 | 0x12b1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:38.413971901 CEST | 192.168.2.3 | 8.8.8.8 | 0xe208 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:39.833098888 CEST | 192.168.2.3 | 8.8.8.8 | 0xa3d5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:42.271841049 CEST | 192.168.2.3 | 8.8.8.8 | 0xa2cd | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:44.249469042 CEST | 192.168.2.3 | 8.8.8.8 | 0x75a1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:47.204190016 CEST | 192.168.2.3 | 8.8.8.8 | 0x388c | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:50.070828915 CEST | 192.168.2.3 | 8.8.8.8 | 0x1705 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:52.207909107 CEST | 192.168.2.3 | 8.8.8.8 | 0x1d5c | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:54.671829939 CEST | 192.168.2.3 | 8.8.8.8 | 0xe586 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:56.328485966 CEST | 192.168.2.3 | 8.8.8.8 | 0xf6b9 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:57.859044075 CEST | 192.168.2.3 | 8.8.8.8 | 0x857 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:54:59.359349012 CEST | 192.168.2.3 | 8.8.8.8 | 0x5357 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:00.776829958 CEST | 192.168.2.3 | 8.8.8.8 | 0xc00f | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:02.366936922 CEST | 192.168.2.3 | 8.8.8.8 | 0x7338 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:03.948007107 CEST | 192.168.2.3 | 8.8.8.8 | 0x858 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:07.364010096 CEST | 192.168.2.3 | 8.8.8.8 | 0xfd0e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:08.991691113 CEST | 192.168.2.3 | 8.8.8.8 | 0x7440 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:10.683821917 CEST | 192.168.2.3 | 8.8.8.8 | 0xa8a4 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:12.016415119 CEST | 192.168.2.3 | 8.8.8.8 | 0x592 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:13.382803917 CEST | 192.168.2.3 | 8.8.8.8 | 0x657b | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:15.005296946 CEST | 192.168.2.3 | 8.8.8.8 | 0x2505 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:16.487935066 CEST | 192.168.2.3 | 8.8.8.8 | 0x2e94 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:18.880110025 CEST | 192.168.2.3 | 8.8.8.8 | 0x255e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:20.849235058 CEST | 192.168.2.3 | 8.8.8.8 | 0xde93 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:22.244772911 CEST | 192.168.2.3 | 8.8.8.8 | 0x9f80 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:26.274383068 CEST | 192.168.2.3 | 8.8.8.8 | 0xa552 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:33.486325979 CEST | 192.168.2.3 | 8.8.8.8 | 0xf39 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:36.560930014 CEST | 192.168.2.3 | 8.8.8.8 | 0xfb89 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:40.570740938 CEST | 192.168.2.3 | 8.8.8.8 | 0x7f71 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:42.235366106 CEST | 192.168.2.3 | 8.8.8.8 | 0x2bfc | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:45.719465971 CEST | 192.168.2.3 | 8.8.8.8 | 0xc204 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:50.492064953 CEST | 192.168.2.3 | 8.8.8.8 | 0x473a | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:53.366695881 CEST | 192.168.2.3 | 8.8.8.8 | 0xfec | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:55.533931971 CEST | 192.168.2.3 | 8.8.8.8 | 0x9e3f | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:55:58.096735954 CEST | 192.168.2.3 | 8.8.8.8 | 0x11e3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:00.509530067 CEST | 192.168.2.3 | 8.8.8.8 | 0x29be | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:02.044512987 CEST | 192.168.2.3 | 8.8.8.8 | 0xfd3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:04.141248941 CEST | 192.168.2.3 | 8.8.8.8 | 0x29c8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:08.598506927 CEST | 192.168.2.3 | 8.8.8.8 | 0xd3b9 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:11.030992985 CEST | 192.168.2.3 | 8.8.8.8 | 0x3c9e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:13.735444069 CEST | 192.168.2.3 | 8.8.8.8 | 0x2c4c | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:16.851468086 CEST | 192.168.2.3 | 8.8.8.8 | 0xcebe | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:19.753016949 CEST | 192.168.2.3 | 8.8.8.8 | 0xf3b6 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 23, 2022 17:56:20.715711117 CEST | 192.168.2.3 | 8.8.8.8 | 0x7fc1 | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Jun 23, 2022 17:54:33.859457970 CEST | 8.8.8.8 | 192.168.2.3 | 0xc3fd | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:33.859457970 CEST | 8.8.8.8 | 192.168.2.3 | 0xc3fd | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:35.536612988 CEST | 8.8.8.8 | 192.168.2.3 | 0xcba5 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:35.536612988 CEST | 8.8.8.8 | 192.168.2.3 | 0xcba5 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:37.070851088 CEST | 8.8.8.8 | 192.168.2.3 | 0x12b1 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:37.070851088 CEST | 8.8.8.8 | 192.168.2.3 | 0x12b1 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:38.431252003 CEST | 8.8.8.8 | 192.168.2.3 | 0xe208 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:38.431252003 CEST | 8.8.8.8 | 192.168.2.3 | 0xe208 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:39.858500004 CEST | 8.8.8.8 | 192.168.2.3 | 0xa3d5 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:39.858500004 CEST | 8.8.8.8 | 192.168.2.3 | 0xa3d5 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:42.305263996 CEST | 8.8.8.8 | 192.168.2.3 | 0xa2cd | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:42.305263996 CEST | 8.8.8.8 | 192.168.2.3 | 0xa2cd | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:44.268577099 CEST | 8.8.8.8 | 192.168.2.3 | 0x75a1 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:44.268577099 CEST | 8.8.8.8 | 192.168.2.3 | 0x75a1 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:47.230014086 CEST | 8.8.8.8 | 192.168.2.3 | 0x388c | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:47.230014086 CEST | 8.8.8.8 | 192.168.2.3 | 0x388c | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:50.089931011 CEST | 8.8.8.8 | 192.168.2.3 | 0x1705 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:50.089931011 CEST | 8.8.8.8 | 192.168.2.3 | 0x1705 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:52.227092981 CEST | 8.8.8.8 | 192.168.2.3 | 0x1d5c | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:52.227092981 CEST | 8.8.8.8 | 192.168.2.3 | 0x1d5c | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:54.695344925 CEST | 8.8.8.8 | 192.168.2.3 | 0xe586 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:54.695344925 CEST | 8.8.8.8 | 192.168.2.3 | 0xe586 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:56.346199989 CEST | 8.8.8.8 | 192.168.2.3 | 0xf6b9 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:56.346199989 CEST | 8.8.8.8 | 192.168.2.3 | 0xf6b9 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:57.878499985 CEST | 8.8.8.8 | 192.168.2.3 | 0x857 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:57.878499985 CEST | 8.8.8.8 | 192.168.2.3 | 0x857 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:59.376538992 CEST | 8.8.8.8 | 192.168.2.3 | 0x5357 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:54:59.376538992 CEST | 8.8.8.8 | 192.168.2.3 | 0x5357 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:00.796344042 CEST | 8.8.8.8 | 192.168.2.3 | 0xc00f | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:00.796344042 CEST | 8.8.8.8 | 192.168.2.3 | 0xc00f | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:02.386096954 CEST | 8.8.8.8 | 192.168.2.3 | 0x7338 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:02.386096954 CEST | 8.8.8.8 | 192.168.2.3 | 0x7338 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:03.969122887 CEST | 8.8.8.8 | 192.168.2.3 | 0x858 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:03.969122887 CEST | 8.8.8.8 | 192.168.2.3 | 0x858 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:07.383429050 CEST | 8.8.8.8 | 192.168.2.3 | 0xfd0e | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:07.383429050 CEST | 8.8.8.8 | 192.168.2.3 | 0xfd0e | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:09.008948088 CEST | 8.8.8.8 | 192.168.2.3 | 0x7440 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:09.008948088 CEST | 8.8.8.8 | 192.168.2.3 | 0x7440 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:10.703425884 CEST | 8.8.8.8 | 192.168.2.3 | 0xa8a4 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:10.703425884 CEST | 8.8.8.8 | 192.168.2.3 | 0xa8a4 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:12.039047003 CEST | 8.8.8.8 | 192.168.2.3 | 0x592 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:12.039047003 CEST | 8.8.8.8 | 192.168.2.3 | 0x592 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:13.407774925 CEST | 8.8.8.8 | 192.168.2.3 | 0x657b | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:13.407774925 CEST | 8.8.8.8 | 192.168.2.3 | 0x657b | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:15.025069952 CEST | 8.8.8.8 | 192.168.2.3 | 0x2505 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:15.025069952 CEST | 8.8.8.8 | 192.168.2.3 | 0x2505 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:16.508002996 CEST | 8.8.8.8 | 192.168.2.3 | 0x2e94 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:16.508002996 CEST | 8.8.8.8 | 192.168.2.3 | 0x2e94 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:18.899779081 CEST | 8.8.8.8 | 192.168.2.3 | 0x255e | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:18.899779081 CEST | 8.8.8.8 | 192.168.2.3 | 0x255e | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:20.869082928 CEST | 8.8.8.8 | 192.168.2.3 | 0xde93 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:20.869082928 CEST | 8.8.8.8 | 192.168.2.3 | 0xde93 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:22.262568951 CEST | 8.8.8.8 | 192.168.2.3 | 0x9f80 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:22.262568951 CEST | 8.8.8.8 | 192.168.2.3 | 0x9f80 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:26.293586969 CEST | 8.8.8.8 | 192.168.2.3 | 0xa552 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:26.293586969 CEST | 8.8.8.8 | 192.168.2.3 | 0xa552 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:33.503941059 CEST | 8.8.8.8 | 192.168.2.3 | 0xf39 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:33.503941059 CEST | 8.8.8.8 | 192.168.2.3 | 0xf39 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:36.578289032 CEST | 8.8.8.8 | 192.168.2.3 | 0xfb89 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:36.578289032 CEST | 8.8.8.8 | 192.168.2.3 | 0xfb89 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:40.590874910 CEST | 8.8.8.8 | 192.168.2.3 | 0x7f71 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:40.590874910 CEST | 8.8.8.8 | 192.168.2.3 | 0x7f71 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:42.254795074 CEST | 8.8.8.8 | 192.168.2.3 | 0x2bfc | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:42.254795074 CEST | 8.8.8.8 | 192.168.2.3 | 0x2bfc | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:45.739217043 CEST | 8.8.8.8 | 192.168.2.3 | 0xc204 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:45.739217043 CEST | 8.8.8.8 | 192.168.2.3 | 0xc204 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:50.511487961 CEST | 8.8.8.8 | 192.168.2.3 | 0x473a | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:50.511487961 CEST | 8.8.8.8 | 192.168.2.3 | 0x473a | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:53.386226892 CEST | 8.8.8.8 | 192.168.2.3 | 0xfec | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:53.386226892 CEST | 8.8.8.8 | 192.168.2.3 | 0xfec | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:55.552799940 CEST | 8.8.8.8 | 192.168.2.3 | 0x9e3f | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:55.552799940 CEST | 8.8.8.8 | 192.168.2.3 | 0x9e3f | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:58.114485025 CEST | 8.8.8.8 | 192.168.2.3 | 0x11e3 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:55:58.114485025 CEST | 8.8.8.8 | 192.168.2.3 | 0x11e3 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:00.529114008 CEST | 8.8.8.8 | 192.168.2.3 | 0x29be | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:00.529114008 CEST | 8.8.8.8 | 192.168.2.3 | 0x29be | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:02.063860893 CEST | 8.8.8.8 | 192.168.2.3 | 0xfd3 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:02.063860893 CEST | 8.8.8.8 | 192.168.2.3 | 0xfd3 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:04.160404921 CEST | 8.8.8.8 | 192.168.2.3 | 0x29c8 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:04.160404921 CEST | 8.8.8.8 | 192.168.2.3 | 0x29c8 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:08.618109941 CEST | 8.8.8.8 | 192.168.2.3 | 0xd3b9 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:08.618109941 CEST | 8.8.8.8 | 192.168.2.3 | 0xd3b9 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:11.050276995 CEST | 8.8.8.8 | 192.168.2.3 | 0x3c9e | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:11.050276995 CEST | 8.8.8.8 | 192.168.2.3 | 0x3c9e | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:13.752243996 CEST | 8.8.8.8 | 192.168.2.3 | 0x2c4c | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:13.752243996 CEST | 8.8.8.8 | 192.168.2.3 | 0x2c4c | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:16.868690968 CEST | 8.8.8.8 | 192.168.2.3 | 0xcebe | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:16.868690968 CEST | 8.8.8.8 | 192.168.2.3 | 0xcebe | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:19.772675037 CEST | 8.8.8.8 | 192.168.2.3 | 0xf3b6 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:19.772675037 CEST | 8.8.8.8 | 192.168.2.3 | 0xf3b6 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:20.735198021 CEST | 8.8.8.8 | 192.168.2.3 | 0x7fc1 | No error (0) | 104.21.40.153 | A (IP address) | IN (0x0001) | ||
Jun 23, 2022 17:56:20.735198021 CEST | 8.8.8.8 | 192.168.2.3 | 0x7fc1 | No error (0) | 172.67.154.72 | A (IP address) | IN (0x0001) |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.3 | 49741 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:33.910152912 CEST | 1145 | OUT | |
Jun 23, 2022 17:54:33.943350077 CEST | 1146 | OUT | |
Jun 23, 2022 17:54:34.295411110 CEST | 1146 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.3 | 49742 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:35.573404074 CEST | 1147 | OUT | |
Jun 23, 2022 17:54:35.605947018 CEST | 1147 | OUT | |
Jun 23, 2022 17:54:35.979684114 CEST | 1148 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
10 | 192.168.2.3 | 49765 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:54.716737032 CEST | 1333 | OUT | |
Jun 23, 2022 17:54:54.734097958 CEST | 1334 | OUT | |
Jun 23, 2022 17:54:55.074867964 CEST | 1334 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
11 | 192.168.2.3 | 49766 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:56.372364044 CEST | 1335 | OUT | |
Jun 23, 2022 17:54:56.389347076 CEST | 1335 | OUT | |
Jun 23, 2022 17:54:56.739352942 CEST | 1336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
12 | 192.168.2.3 | 49767 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:57.914899111 CEST | 1338 | OUT | |
Jun 23, 2022 17:54:57.947086096 CEST | 1338 | OUT | |
Jun 23, 2022 17:54:58.307390928 CEST | 1339 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
13 | 192.168.2.3 | 49768 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:59.413778067 CEST | 1340 | OUT | |
Jun 23, 2022 17:54:59.446124077 CEST | 1340 | OUT | |
Jun 23, 2022 17:54:59.812854052 CEST | 1341 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
14 | 192.168.2.3 | 49769 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:00.833023071 CEST | 1341 | OUT | |
Jun 23, 2022 17:55:00.866178989 CEST | 1342 | OUT | |
Jun 23, 2022 17:55:01.207211018 CEST | 1342 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
15 | 192.168.2.3 | 49770 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:02.423254013 CEST | 1343 | OUT | |
Jun 23, 2022 17:55:02.458756924 CEST | 1344 | OUT | |
Jun 23, 2022 17:55:02.800951004 CEST | 1344 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
16 | 192.168.2.3 | 49771 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:04.009922981 CEST | 1345 | OUT | |
Jun 23, 2022 17:55:04.043416977 CEST | 1345 | OUT | |
Jun 23, 2022 17:55:04.389384031 CEST | 1346 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
17 | 192.168.2.3 | 49772 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:07.425069094 CEST | 1347 | OUT | |
Jun 23, 2022 17:55:07.457617044 CEST | 1347 | OUT | |
Jun 23, 2022 17:55:07.799252033 CEST | 1348 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
18 | 192.168.2.3 | 49773 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:09.049678087 CEST | 1349 | OUT | |
Jun 23, 2022 17:55:09.082096100 CEST | 1349 | OUT | |
Jun 23, 2022 17:55:09.424262047 CEST | 1350 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
19 | 192.168.2.3 | 49774 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:10.726793051 CEST | 1351 | OUT | |
Jun 23, 2022 17:55:10.744281054 CEST | 1351 | OUT | |
Jun 23, 2022 17:55:11.087935925 CEST | 1352 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.3 | 49743 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:37.108829975 CEST | 1149 | OUT | |
Jun 23, 2022 17:54:37.141366959 CEST | 1149 | OUT | |
Jun 23, 2022 17:54:37.484196901 CEST | 1150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
20 | 192.168.2.3 | 49775 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:12.061012030 CEST | 1352 | OUT | |
Jun 23, 2022 17:55:12.078103065 CEST | 1353 | OUT | |
Jun 23, 2022 17:55:12.409252882 CEST | 1353 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
21 | 192.168.2.3 | 49776 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:13.438858986 CEST | 1354 | OUT | |
Jun 23, 2022 17:55:13.455945015 CEST | 1354 | OUT | |
Jun 23, 2022 17:55:13.814687014 CEST | 1355 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
22 | 192.168.2.3 | 49778 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:15.087770939 CEST | 1357 | OUT | |
Jun 23, 2022 17:55:15.104842901 CEST | 1361 | OUT | |
Jun 23, 2022 17:55:15.450156927 CEST | 1362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
23 | 192.168.2.3 | 49780 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:16.534873009 CEST | 1406 | OUT | |
Jun 23, 2022 17:55:16.555150032 CEST | 1406 | OUT | |
Jun 23, 2022 17:55:16.906121969 CEST | 1445 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
24 | 192.168.2.3 | 49792 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:18.935502052 CEST | 1559 | OUT | |
Jun 23, 2022 17:55:18.953016043 CEST | 1572 | OUT | |
Jun 23, 2022 17:55:19.293885946 CEST | 1595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
25 | 192.168.2.3 | 49803 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:20.890777111 CEST | 1693 | OUT | |
Jun 23, 2022 17:55:20.907857895 CEST | 1694 | OUT | |
Jun 23, 2022 17:55:21.252073050 CEST | 1829 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
26 | 192.168.2.3 | 49813 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:22.328152895 CEST | 1883 | OUT | |
Jun 23, 2022 17:55:22.346621990 CEST | 1884 | OUT | |
Jun 23, 2022 17:55:22.691435099 CEST | 1890 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
27 | 192.168.2.3 | 49816 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:26.329556942 CEST | 2012 | OUT | |
Jun 23, 2022 17:55:26.361991882 CEST | 2012 | OUT | |
Jun 23, 2022 17:55:26.709573984 CEST | 2013 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
28 | 192.168.2.3 | 49831 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:33.546350956 CEST | 2647 | OUT | |
Jun 23, 2022 17:55:33.578521013 CEST | 2647 | OUT | |
Jun 23, 2022 17:55:33.938213110 CEST | 2691 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
29 | 192.168.2.3 | 49835 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:36.607918024 CEST | 2772 | OUT | |
Jun 23, 2022 17:55:36.624871969 CEST | 2772 | OUT | |
Jun 23, 2022 17:55:36.962721109 CEST | 2773 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.3 | 49744 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:38.472163916 CEST | 1151 | OUT | |
Jun 23, 2022 17:54:38.504328012 CEST | 1151 | OUT | |
Jun 23, 2022 17:54:38.845036030 CEST | 1152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
30 | 192.168.2.3 | 49836 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:40.617403984 CEST | 2774 | OUT | |
Jun 23, 2022 17:55:40.634340048 CEST | 2774 | OUT | |
Jun 23, 2022 17:55:40.986800909 CEST | 2775 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
31 | 192.168.2.3 | 49837 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:42.276335001 CEST | 2776 | OUT | |
Jun 23, 2022 17:55:42.295589924 CEST | 2776 | OUT | |
Jun 23, 2022 17:55:42.633047104 CEST | 2777 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
32 | 192.168.2.3 | 49843 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:45.763231993 CEST | 10854 | OUT | |
Jun 23, 2022 17:55:45.780632973 CEST | 10854 | OUT | |
Jun 23, 2022 17:55:46.128196955 CEST | 10855 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
33 | 192.168.2.3 | 49844 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:50.553164959 CEST | 10856 | OUT | |
Jun 23, 2022 17:55:50.585745096 CEST | 10856 | OUT | |
Jun 23, 2022 17:55:50.924413919 CEST | 10857 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
34 | 192.168.2.3 | 49845 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:53.427871943 CEST | 10858 | OUT | |
Jun 23, 2022 17:55:53.460439920 CEST | 10858 | OUT | |
Jun 23, 2022 17:55:53.809928894 CEST | 10859 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
35 | 192.168.2.3 | 49852 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:55.592533112 CEST | 12570 | OUT | |
Jun 23, 2022 17:55:55.625174046 CEST | 12570 | OUT | |
Jun 23, 2022 17:55:55.968697071 CEST | 12575 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
36 | 192.168.2.3 | 49859 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:55:58.152467966 CEST | 12585 | OUT | |
Jun 23, 2022 17:55:58.185668945 CEST | 12586 | OUT | |
Jun 23, 2022 17:55:58.564342022 CEST | 12589 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
37 | 192.168.2.3 | 49865 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:00.557523966 CEST | 12598 | OUT | |
Jun 23, 2022 17:56:00.574569941 CEST | 12599 | OUT | |
Jun 23, 2022 17:56:00.910413980 CEST | 12603 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
38 | 192.168.2.3 | 49872 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:02.086133957 CEST | 12614 | OUT | |
Jun 23, 2022 17:56:02.103677034 CEST | 12615 | OUT | |
Jun 23, 2022 17:56:02.444869041 CEST | 12617 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
39 | 192.168.2.3 | 49873 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:04.198158026 CEST | 12618 | OUT | |
Jun 23, 2022 17:56:04.230531931 CEST | 12618 | OUT | |
Jun 23, 2022 17:56:04.571379900 CEST | 12619 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
4 | 192.168.2.3 | 49745 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:39.886492014 CEST | 1153 | OUT | |
Jun 23, 2022 17:54:39.903673887 CEST | 1153 | OUT | |
Jun 23, 2022 17:54:40.249713898 CEST | 1154 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
40 | 192.168.2.3 | 49875 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:08.656582117 CEST | 12624 | OUT | |
Jun 23, 2022 17:56:08.689090967 CEST | 12625 | OUT | |
Jun 23, 2022 17:56:09.034661055 CEST | 12625 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
41 | 192.168.2.3 | 49876 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:11.073086023 CEST | 12626 | OUT | |
Jun 23, 2022 17:56:11.089920998 CEST | 12627 | OUT | |
Jun 23, 2022 17:56:11.421587944 CEST | 12627 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
42 | 192.168.2.3 | 49877 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:13.789082050 CEST | 12628 | OUT | |
Jun 23, 2022 17:56:13.821517944 CEST | 12628 | OUT | |
Jun 23, 2022 17:56:14.167265892 CEST | 12629 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
43 | 192.168.2.3 | 49881 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:16.928508997 CEST | 12638 | OUT | |
Jun 23, 2022 17:56:16.945166111 CEST | 12638 | OUT | |
Jun 23, 2022 17:56:17.284101009 CEST | 12640 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
44 | 192.168.2.3 | 49882 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:19.809047937 CEST | 12641 | OUT | |
Jun 23, 2022 17:56:19.841264963 CEST | 12641 | OUT | |
Jun 23, 2022 17:56:20.189312935 CEST | 12642 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
45 | 192.168.2.3 | 49883 | 104.21.40.153 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:56:20.757704973 CEST | 12642 | OUT | |
Jun 23, 2022 17:56:20.774715900 CEST | 12643 | OUT | |
Jun 23, 2022 17:56:21.122421980 CEST | 12643 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
5 | 192.168.2.3 | 49746 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:42.346945047 CEST | 1155 | OUT | |
Jun 23, 2022 17:54:42.383651018 CEST | 1155 | OUT | |
Jun 23, 2022 17:54:42.724734068 CEST | 1156 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
6 | 192.168.2.3 | 49747 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:44.305986881 CEST | 1156 | OUT | |
Jun 23, 2022 17:54:44.338661909 CEST | 1157 | OUT | |
Jun 23, 2022 17:54:44.695508003 CEST | 1157 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
7 | 192.168.2.3 | 49749 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:47.375833988 CEST | 1170 | OUT | |
Jun 23, 2022 17:54:47.408128023 CEST | 1183 | OUT | |
Jun 23, 2022 17:54:47.760540009 CEST | 1189 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
8 | 192.168.2.3 | 49757 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:50.135453939 CEST | 1286 | OUT | |
Jun 23, 2022 17:54:50.167802095 CEST | 1287 | OUT | |
Jun 23, 2022 17:54:50.515275002 CEST | 1300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
9 | 192.168.2.3 | 49762 | 172.67.154.72 | 80 | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 23, 2022 17:54:52.263394117 CEST | 1323 | OUT | |
Jun 23, 2022 17:54:52.295813084 CEST | 1323 | OUT | |
Jun 23, 2022 17:54:52.635915995 CEST | 1324 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 17:54:11 |
Start date: | 23/06/2022 |
Path: | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x4b0000 |
File size: | 497664 bytes |
MD5 hash: | 603FE9A434DA79407213DB7D4B907789 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
Target ID: | 4 |
Start time: | 17:54:23 |
Start date: | 23/06/2022 |
Path: | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x2b0000 |
File size: | 497664 bytes |
MD5 hash: | 603FE9A434DA79407213DB7D4B907789 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 5 |
Start time: | 17:54:25 |
Start date: | 23/06/2022 |
Path: | C:\Users\user\Desktop\Informe bancario.pdf.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6e0000 |
File size: | 497664 bytes |
MD5 hash: | 603FE9A434DA79407213DB7D4B907789 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Execution Graph
Execution Coverage: | 6.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 94 |
Total number of Limit Nodes: | 8 |
Graph
Function 00E3B7F8 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 125threadCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E3B808 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 120threadCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E35365 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E33DE8 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E3BA2F Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E3BA30 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E38F98 Relevance: 1.6, APIs: 1, Instructions: 55libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E39977 Relevance: 1.6, APIs: 1, Instructions: 52libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E396F0 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E396F2 Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BDD3D8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BED01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BED1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BED006 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BDD3D3 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BED1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BDD745 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BDD744 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05239F74 Relevance: .7, Instructions: 652COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E3E2F0 Relevance: .3, Instructions: 315COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05239F6E Relevance: .3, Instructions: 280COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0523B6FF Relevance: .3, Instructions: 275COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E3C37C Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E3E2E0 Relevance: .2, Instructions: 222COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA141 Relevance: .1, Instructions: 105COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA36E Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA276 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA841 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA741 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA641 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA541 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004BA96F Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 27.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 4.5% |
Total number of Nodes: | 1841 |
Total number of Limit Nodes: | 93 |
Graph
Function 00403D74 Relevance: 14.2, APIs: 4, Strings: 4, Instructions: 200fileCOMMON
Control-flow Graph
C-Code - Quality: 85% |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 78% |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402B7C Relevance: 3.0, APIs: 2, Instructions: 20memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406069 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404ED4 Relevance: 1.5, APIs: 1, Instructions: 9networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 75% |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404E17 Relevance: 7.6, APIs: 5, Instructions: 72networkCOMMON
Control-flow Graph
C-Code - Quality: 37% |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004040BB Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 129filememoryCOMMON
Control-flow Graph
C-Code - Quality: 74% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 79% |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004042CF Relevance: 4.6, APIs: 3, Instructions: 60fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00412D31 Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 178threadCOMMON
C-Code - Quality: 34% |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402C03 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 13libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 92% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004060BD Relevance: 1.6, APIs: 1, Instructions: 53COMMON
C-Code - Quality: 40% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403C62 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040642C Relevance: 1.5, APIs: 1, Instructions: 18COMMON
C-Code - Quality: 37% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404EEA Relevance: 1.5, APIs: 1, Instructions: 16networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403BD0 Relevance: 1.5, APIs: 1, Instructions: 14COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404DF3 Relevance: 1.5, APIs: 1, Instructions: 13networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040427D Relevance: 1.5, APIs: 1, Instructions: 13COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403C40 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403C08 Relevance: 1.5, APIs: 1, Instructions: 12fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402C1F Relevance: 1.5, APIs: 1, Instructions: 12libraryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403BEF Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403BB7 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403B64 Relevance: 1.5, APIs: 1, Instructions: 11COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404DE5 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403F9E Relevance: 1.3, APIs: 1, Instructions: 16COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406472 Relevance: 1.3, APIs: 1, Instructions: 12sleepCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004058EA Relevance: 1.3, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405924 Relevance: 1.3, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040D069 Relevance: 12.6, Strings: 10, Instructions: 138COMMON
C-Code - Quality: 88% |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040317B Relevance: .0, Instructions: 46COMMON
C-Code - Quality: 90% |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |