Windows
Analysis Report
nnxPt0Yydv.doc
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w7x64
- WINWORD.EXE (PID: 2476 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\WINWOR D.EXE" /Au tomation - Embedding MD5: 9EE74859D22DAE61F1750B3A1BACB6F5)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
EXPL_CVE_2021_40444_Document_Rels_XML | Detects indicators found in weaponized documents that exploit CVE-2021-40444 | Jeremy Brown / @alteredbytes |
|
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Exploits |
---|
Source: | Extracted files from sample: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | File created: | Jump to behavior |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Matched rule: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Key opened: | Jump to behavior |
Source: | LNK file: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Persistence and Installation Behavior |
---|
Source: | Extracted files from sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 13 Exploitation for Client Execution | Path Interception | Path Interception | 1 Masquerading | OS Credential Dumping | 1 File and Directory Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 2 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 2 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 13 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 2 Ingress Tool Transfer | SIM Card Swap | Carrier Billing Fraud |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
50% | ReversingLabs | Document-Office.Exploit.CVE-2021-40444 | ||
48% | Virustotal | Browse | ||
100% | Avira | EXP/CVE-2021-40444.Gen |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
2% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
3% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
qaz.im | 82.202.173.45 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
82.202.173.45 | qaz.im | Russian Federation | 29182 | THEFIRST-ASRU | true |
Joe Sandbox Version: | 35.0.0 Citrine |
Analysis ID: | 696518 |
Start date and time: | 2022-09-02 13:23:11 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 4m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | nnxPt0Yydv.doc |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 4 |
Number of new started drivers analysed: | 1 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal68.expl.evad.winDOC@1/17@9/1 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): mrxdav.sys, dllhost.exe
- Report size getting too big, too many NtQueryAttributesFile calls found.
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
qaz.im | Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
THEFIRST-ASRU | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
05af1f5ca1b87cc9cc9b25185115607d | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
7dcce5b76c8b17472d024758970a406b | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.28879490407012426 |
Encrypted: | false |
SSDEEP: | 48:I3ZrsRB68BT/wV0yYRzCmrWIdIP+ltUQ+VrXJkVIPpIPOH:K+LLoOd/xU5kOH |
MD5: | 30075DA75A69E03B91CDC295A738FE71 |
SHA1: | 5C8EB1D3F7DC5B502212314F6405B25C9766603C |
SHA-256: | 29A90C402102B1E2616519F5DE7AA09426AAAB3559494E5EBFDA3DA1DC16A660 |
SHA-512: | 172699B6B75DA2A3074DCBE0C418C34D00F964C84BF758940DEF4A4718394AFF0AED477B184D25C1A9280522E7ABBCC6083143CBA88500A40B7C2A67A7B6F363 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\FSD-{0CEDFB9A-672A-495E-A8C3-4E2E5CC4FEA5}.FSD
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.6734044956719611 |
Encrypted: | false |
SSDEEP: | 96:KOCyQlWIZP3wHLRN7Xrka3oGX16Ilkl2IYP9gzS6WtPWtuWtUgt:ZzuoLyGXPwQlgzUib5 |
MD5: | 848796E37A8642B8F3B45C6176D8E814 |
SHA1: | 2D1D922A49C8B09E7B9FB8E0FDFE9A642E65B624 |
SHA-256: | 92BB7EFDF1993B4DD43843D0595C911F5AE646CEC4047CEEC557E6B6E9C641DC |
SHA-512: | 15AA1AEF8EB965E8051358F3B98E7BE4EB0F7AE9D59783DA64F5DAFB8DB8461DDE5594B5B3842415DF26BCA06CF30EC2A4079A8DA68399B6C367F9D05C841DB9 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 114 |
Entropy (8bit): | 3.9508758081628756 |
Encrypted: | false |
SSDEEP: | 3:yVlgsRlztlZlULTINDtgI+F/YRogQ8lSR56aw27276:yPblzJyL8ZWI++qV8lSSBg22 |
MD5: | 99A54F4CFBDA747E27CF539D4A1807FF |
SHA1: | 5EFB6E4012D07C7820C1022141A6B658AEC2CDB1 |
SHA-256: | 98FB7578F8FE1FAFDBE7B2AFD3B37E39161F2C3622433387CCF7AE6E178CC83E |
SHA-512: | 0883837836C43A8201145CC9799409478863B1BF30ADE6E5A329B542EEC598427E4E31F3973F819D2B56723FEA6C7EA3B0DA0712EF56DF982BAAC1801AFA524E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.28847987121721 |
Encrypted: | false |
SSDEEP: | 48:I39yCRBk2B05avmHBRbgEo8vTvPO4JyP6LaRrCDr7evivDH:K9yCL6Hwlm7VUPgWCbsQDH |
MD5: | E5AF351D93FC6BA388AB48ABD23907E0 |
SHA1: | 5D4145B35593C774D5F88A1997109E79496E3821 |
SHA-256: | D42FB125C2C4BAE8CE74C54BD189F356B596582D3EA1CB96AB1532A586FAAA9B |
SHA-512: | D87BFEC3E1B73D65BC6D187CF4C6E69C1232A5F8CB203857CBD7FC6E577985E00DAA3C7696A6E50F57D124C0FDF8A10CAEFD4448D45C19EFCC21F82377F2F61D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-{5B8C97A2-8D5D-4690-A237-D6E0C46FC601}.FSD
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.22169434281918624 |
Encrypted: | false |
SSDEEP: | 24:I3mLwnM0B34BGDcSDzqSZ/yLfLSOeSg8YGILLK5zvfEKwJwz1w3m8Md505fZmjS/:I3mUrBzMjPZ2nhIgf5xT |
MD5: | 70560F4917331B2A17868068A1E9517E |
SHA1: | 359ADBCC510241A6528A866A1EA3B361D6EF93AF |
SHA-256: | 475591FE9EC37DCD8BDBDE7E426317FD418DFEABEE6CD0DD0477A2D01834D97E |
SHA-512: | F1250F280EB632638962459F43C5EF4DFE5A7FFDDE2284A434878B854FD58DB69F617C4AF0ACA5CA143AD5EDD2AB6307CBDD1E139E479971ED5997FFD5E4ECB9 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSF-{0E1EEE64-E8C6-4E2A-9759-63CF07FD8988}.FSF
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 114 |
Entropy (8bit): | 4.003507387110244 |
Encrypted: | false |
SSDEEP: | 3:yVlgsRlzISUW2SblLyVSclQlpgkLVgdUal276:yPblzZRLBOwNgkyUu22 |
MD5: | 46245F9209D2C7C555186D14DDE809A1 |
SHA1: | 295F3AA146AF9E9C14506927280087F0919DD24E |
SHA-256: | 21E9FB94661FAD6FB122E822A41EB27A2FDC31C0A526085D1A0BE3F732630FB9 |
SHA-512: | 918A990D8D30F9E3C37AB205EDC49E0967CD49BE5B377F99D8B219E89C0EB71F549295A603A31C2A576CC95AA023B21BDC3BBBDE00CAF6923B0BFF47020C463F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\1024203777.test[1].html
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 19364 |
Entropy (8bit): | 6.048046902595105 |
Encrypted: | false |
SSDEEP: | 384:hZJbWuYvXebbmk2RFGqL1vXipiIPq2L15j+h5i4rXgrE/M1eEScjy:hZJCXAbmDRFJ16pti2Lvaxb2rlW |
MD5: | C389F7EE1D9E6376B7D96E80D7A1FFE1 |
SHA1: | 2D0B931CF7CECDDDDB35457A5719353840F8CA66 |
SHA-256: | 8A01945C5951B6685768C155D938E7805B097477FCBB7E815FCB1CC26F1170DA |
SHA-512: | 7DE15CF2ED560A6FF7E7FD5D3C8B0E4F13CA585BAB09D40E89785FC12F5B4C79D9F4CEC4034B3F40F4CA54ABAB100E27947867558DBC7876366A8B614EEA0FFC |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\1024203777.test[1].html
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 19364 |
Entropy (8bit): | 6.048046902595105 |
Encrypted: | false |
SSDEEP: | 384:hZJbWuYvXebbmk2RFGqL1vXipiIPq2L15j+h5i4rXgrE/M1eEScjy:hZJCXAbmDRFJ16pti2Lvaxb2rlW |
MD5: | C389F7EE1D9E6376B7D96E80D7A1FFE1 |
SHA1: | 2D0B931CF7CECDDDDB35457A5719353840F8CA66 |
SHA-256: | 8A01945C5951B6685768C155D938E7805B097477FCBB7E815FCB1CC26F1170DA |
SHA-512: | 7DE15CF2ED560A6FF7E7FD5D3C8B0E4F13CA585BAB09D40E89785FC12F5B4C79D9F4CEC4034B3F40F4CA54ABAB100E27947867558DBC7876366A8B614EEA0FFC |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2EF4F663.html
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 19364 |
Entropy (8bit): | 6.048046902595105 |
Encrypted: | false |
SSDEEP: | 384:hZJbWuYvXebbmk2RFGqL1vXipiIPq2L15j+h5i4rXgrE/M1eEScjy:hZJCXAbmDRFJ16pti2Lvaxb2rlW |
MD5: | C389F7EE1D9E6376B7D96E80D7A1FFE1 |
SHA1: | 2D0B931CF7CECDDDDB35457A5719353840F8CA66 |
SHA-256: | 8A01945C5951B6685768C155D938E7805B097477FCBB7E815FCB1CC26F1170DA |
SHA-512: | 7DE15CF2ED560A6FF7E7FD5D3C8B0E4F13CA585BAB09D40E89785FC12F5B4C79D9F4CEC4034B3F40F4CA54ABAB100E27947867558DBC7876366A8B614EEA0FFC |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8E5395CD.jpg
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 22248 |
Entropy (8bit): | 7.567520825394468 |
Encrypted: | false |
SSDEEP: | 384:ma1KN3h8oGT1TS/TZs/r4VB5LuCBLAyB4KGO4v:7Zo21TSVur4z5Luy/BSF |
MD5: | 66EBF5C50A28236AD77C5A306A4543E1 |
SHA1: | F6EAA2DF964C95A2EB044AA94F5A691C1752E4B8 |
SHA-256: | E80BFCC0066D4DFCE09EE172F5082C14D8EED957E8BF14B60FFC57C2F0BB1BDB |
SHA-512: | D79CD58FF50AA0725C334CCA8151B96AF1BA87E0D15034528055ED96D1B6686727B6A03C23BD069154B19BDC0E7F275A016A0F181C201F449A37AAD6D5568F0D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BC5065FC.html
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 19364 |
Entropy (8bit): | 6.048046902595105 |
Encrypted: | false |
SSDEEP: | 384:hZJbWuYvXebbmk2RFGqL1vXipiIPq2L15j+h5i4rXgrE/M1eEScjy:hZJCXAbmDRFJ16pti2Lvaxb2rlW |
MD5: | C389F7EE1D9E6376B7D96E80D7A1FFE1 |
SHA1: | 2D0B931CF7CECDDDDB35457A5719353840F8CA66 |
SHA-256: | 8A01945C5951B6685768C155D938E7805B097477FCBB7E815FCB1CC26F1170DA |
SHA-512: | 7DE15CF2ED560A6FF7E7FD5D3C8B0E4F13CA585BAB09D40E89785FC12F5B4C79D9F4CEC4034B3F40F4CA54ABAB100E27947867558DBC7876366A8B614EEA0FFC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.025565480559654664 |
Encrypted: | false |
SSDEEP: | 6:I3DPcHPeAzRvxggLRjJ5zRXv//4tfnRujlw//+GtluJ/eRuj:I3DPylRXJ5FvYg3J/ |
MD5: | DAA1E7900566342CE799FAC7815E1AFA |
SHA1: | 27E2175C96A6DA395860F5B87CCA811689FA8DDC |
SHA-256: | 986189E409F4D446FDBC10306068115FB41CC06EFF771F10277DFAA969AEE504 |
SHA-512: | C18AE54E036937187ACEC39CFCF044F1D3FF96B1F420430C0BDF529D82CE0C465EF64B1701D332C8289291B9D3626F3391CA4C47D736F49B5D4571D28E257B26 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.025538895507565103 |
Encrypted: | false |
SSDEEP: | 6:I3DPctQUuy8RvxggLRXWvqq3RXv//4tfnRujlw//+GtluJ/eRuj:I3DP8Q/LWDvYg3J/ |
MD5: | 7B2A21167EF7DE65851D941C40B49C48 |
SHA1: | 3E31789057B2852AD41409CF2D5616E30A6A842B |
SHA-256: | 414B8D143DD15A3996171CB9AB5BD4EFC45F7915F7A65AF25441FBCE891B7CE2 |
SHA-512: | F042E28D1964CE4ED593886985AB4653F13784750540FAE3C07541EA1AF87DF0B4668906B1CABECC607620C597928B2F7AC0A47ACDDDDA7C7F3A7DF4F20A5F65 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 71 |
Entropy (8bit): | 4.683364951357434 |
Encrypted: | false |
SSDEEP: | 3:bDuMJlTUmYmX1V1QmYv:bCYUm91QmC |
MD5: | 82ED92CE73F3F2C3BF91D4C76D3A4760 |
SHA1: | CEFFA2857F6D2C211B5C08CEC9957C3EAF09289A |
SHA-256: | 83E793DEA3EBA35BCC76F8F6511BA90804AC6C71EA4B6A13AA5EA52C94C800FD |
SHA-512: | 17CAACAE5AF04A439529B6AE67BDAD4413CC60C2704748512D80B1485103863C917F158AB4673BCE9715EDB0FF206FDD3438B43E3C1EC92201009830290179C5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1014 |
Entropy (8bit): | 4.583562059208682 |
Encrypted: | false |
SSDEEP: | 12:8s46FgXg/XAlCPCHaXMBzB/nPyX+WeOcfY5i+icvbIszaHDtZ3YilMMEpxRljK34:8e/XT89dqcZdeMszqDv3qcTu7D |
MD5: | B33A705BC9650B7E27987D428B6A003A |
SHA1: | E56964067C53E7D6D18A4378B44EB33409244099 |
SHA-256: | F655020F81323BF78D21B11053DFD2C4B4F8C3673710F1854603736BDFC5ED7C |
SHA-512: | 12704B16A4214246CA1F265BC993824B97624814443A205A999B35DB03B85AEFD8478BD2DA1EEEE8482BD86BA00AF51BB863B70D7FE9C65EC7A7602DAC99633D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 162 |
Entropy (8bit): | 2.503835550707525 |
Encrypted: | false |
SSDEEP: | 3:vrJlaCkWtVyHH/cgQfmW+eMdln:vdsCkWtUb+8ll |
MD5: | D9C8F93ADB8834E5883B5A8AAAC0D8D9 |
SHA1: | 23684CCAA587C442181A92E722E15A685B2407B1 |
SHA-256: | 116394FEAB201D23FD7A4D7F6B10669A4CBCE69AF3575D9C1E13E735D512FA11 |
SHA-512: | 7742E1AC50ACB3B794905CFAE973FDBF16560A7B580B5CD6F27FEFE1CB3EF4AEC2538963535493DCC25F8F114E8708050EDF5F7D3D146DF47DA4B958F0526515 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 162 |
Entropy (8bit): | 2.503835550707525 |
Encrypted: | false |
SSDEEP: | 3:vrJlaCkWtVyHH/cgQfmW+eMdln:vdsCkWtUb+8ll |
MD5: | D9C8F93ADB8834E5883B5A8AAAC0D8D9 |
SHA1: | 23684CCAA587C442181A92E722E15A685B2407B1 |
SHA-256: | 116394FEAB201D23FD7A4D7F6B10669A4CBCE69AF3575D9C1E13E735D512FA11 |
SHA-512: | 7742E1AC50ACB3B794905CFAE973FDBF16560A7B580B5CD6F27FEFE1CB3EF4AEC2538963535493DCC25F8F114E8708050EDF5F7D3D146DF47DA4B958F0526515 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.956139045669752 |
TrID: |
|
File name: | nnxPt0Yydv.doc |
File size: | 23549 |
MD5: | 15b691f0c5d627e71fed8a5d34fb0328 |
SHA1: | 1c7cb38d8fc2f01a6331ade0fdf4cb9779a5ae74 |
SHA256: | 3833142e8b5a9174615c83c1165fa67bd9f46a230058adf8fc9cbb081bb92d30 |
SHA512: | 7e36de7c74b0b17d6a183125855da06a76c42e33506a76bc9450345d41267def85c0af982731a9d02c63ec80b7d8b425494ecde8cc2eb620012504801bdffb5d |
SSDEEP: | 384:6wbSPfEjTkNesdDL667HzVutGCWyDVwZekDN81WqiJo9RxvrvmWqNWNX/wv3eSNU:9AEXkNegL6eHEnTwZvZ81Wqi+vrvUoXr |
TLSH: | 3FB2D090C9B5045EE381E572D0887ACEF339F023C9A1A45C7332C5892BD759356A3A3B |
File Content Preview: | PK........4.!U...p`...T.......[Content_Types].xmlUT......c...c...c.T.N.0..#....U...B.i.,G.D......o.....7%B(4.m/..y.X..O.Zek.AZS.Q1$..n.4uI......BdF0e..d..L'.W...A..mBI.1.{J._.f....V*.5.x.5u......pxK.5.L.c. ..#Tl.b....&...H....WI.sJr..N.F.r....2.......@h.C |
Icon Hash: | e4eea2aaa4b4b4a4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 2, 2022 13:24:11.893163919 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:11.893210888 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:11.893363953 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:11.904119015 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:11.904153109 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.106446028 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.106641054 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.118447065 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.118464947 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.119035959 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.119194031 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.374012947 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.415391922 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.447335005 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.447459936 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.447472095 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.447525024 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.460880041 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.460917950 CEST | 443 | 49171 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:12.460963964 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:12.460978031 CEST | 49171 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:18.723443031 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:18.723489046 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:18.724262953 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:18.724852085 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:18.724877119 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:18.843628883 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:18.843907118 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:18.858563900 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:18.858592987 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:18.859313011 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:18.877919912 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:18.919394016 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:19.005238056 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:19.005317926 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:19.005392075 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:19.005716085 CEST | 49172 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:19.005734921 CEST | 443 | 49172 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.186294079 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.186338902 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.186407089 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.187663078 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.187686920 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.317841053 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.318058968 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.347040892 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.347084045 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.347831011 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.510687113 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.551390886 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.578166962 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.578267097 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.578324080 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.578752995 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.578778028 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.578821898 CEST | 49173 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.578836918 CEST | 443 | 49173 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.580574989 CEST | 49174 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.580615044 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.580679893 CEST | 49174 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.580837965 CEST | 49174 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.580856085 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.701263905 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.701677084 CEST | 49174 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.701705933 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.703433990 CEST | 49174 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.703454018 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.870610952 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.870650053 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.870712042 CEST | 443 | 49174 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:22.872196913 CEST | 49174 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:22.872539043 CEST | 49174 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.004606962 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.004674911 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.004776001 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.005217075 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.005239964 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.127108097 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.127208948 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.133275986 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.133318901 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.134169102 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.135266066 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.175379038 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.289026022 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.289143085 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.289319038 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.289421082 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.289455891 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.289505005 CEST | 49175 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.289520979 CEST | 443 | 49175 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.289912939 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.289964914 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.290060043 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.290260077 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.290277004 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.410973072 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.411715031 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.411742926 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.413580894 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.413614988 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.598203897 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.598242044 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.598305941 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.598320961 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.598351955 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.598398924 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.601039886 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.601064920 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.601077080 CEST | 49176 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.601084948 CEST | 443 | 49176 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.617666960 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.617749929 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.617851019 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.618004084 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.618022919 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.744013071 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.744776011 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.744827032 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.746637106 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.746658087 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.914016962 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.914156914 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.914272070 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.914381027 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.914413929 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.914443016 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.914453983 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.914465904 CEST | 49177 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.914478064 CEST | 443 | 49177 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.915098906 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.915163040 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:23.915273905 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.915394068 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:23.915411949 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.042021036 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.042623043 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.042649031 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.044333935 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.044347048 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.232089043 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.232157946 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.232265949 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.232327938 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.232357979 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.237682104 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.237713099 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.237730026 CEST | 49178 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.237741947 CEST | 443 | 49178 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.251384020 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.251449108 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.251538038 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.251704931 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.251723051 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.377898932 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.378470898 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.378509998 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.379750967 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.379770994 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.548592091 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.548713923 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.548829079 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.555773973 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.555828094 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.555865049 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.555881023 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.555891991 CEST | 49179 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.555900097 CEST | 443 | 49179 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.556355000 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.556399107 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.556505919 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.556612968 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.556627989 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.678282976 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.678761005 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.678791046 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.679898024 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.679910898 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.873868942 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.873935938 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.874044895 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.876353025 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.877455950 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.877486944 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.877516031 CEST | 49180 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.877525091 CEST | 443 | 49180 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.918842077 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.918929100 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:24.919025898 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.919188023 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:24.919203997 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.034212112 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.034322023 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.045315981 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.045335054 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.048325062 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.048340082 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.257338047 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.257394075 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.257442951 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.257565022 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.257596016 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.257616043 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.257736921 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.261219978 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.263252974 CEST | 49181 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.263277054 CEST | 443 | 49181 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.628216982 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.628283024 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.628413916 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.628915071 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.628938913 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.749334097 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.749469995 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.774008036 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.774034023 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.776751995 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.776767015 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.924491882 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.924540043 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.924626112 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.924657106 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.924977064 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.925005913 CEST | 443 | 49182 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:25.925020933 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:25.925064087 CEST | 49182 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.171884060 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.171927929 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.172344923 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.172534943 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.172544003 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.297657967 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.297729969 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.317229986 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.317254066 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.320019007 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.320030928 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.469254971 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.469381094 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.469582081 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.469819069 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.469840050 CEST | 443 | 49183 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.469880104 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.470036983 CEST | 49183 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.556929111 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.556968927 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.557070017 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.557473898 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.557492018 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.685995102 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.686091900 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.699223995 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.699244976 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.700035095 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.706851959 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.747369051 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.853168011 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.853286028 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.853384018 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.861366034 CEST | 49184 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.861394882 CEST | 443 | 49184 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.884521961 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.884589911 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:26.884685040 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.884943962 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:26.885004044 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.005764008 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.006418943 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.006444931 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.008321047 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.008338928 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.172365904 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.172487020 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.172638893 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.177921057 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.177954912 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.178010941 CEST | 49185 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.178025961 CEST | 443 | 49185 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.178498983 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.178534031 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.178628922 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.179280043 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.179295063 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.300115108 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.300517082 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.300534010 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.301480055 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.301491022 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.469640970 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.469671965 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.469738007 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.469825029 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.469871044 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.470244884 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.470280886 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.470336914 CEST | 49186 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.470350027 CEST | 443 | 49186 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.493421078 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.493474007 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.493571997 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.494168043 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.494187117 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.610224009 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.611579895 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.611609936 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.612926006 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.612948895 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.771157980 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.771261930 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.771387100 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.771579027 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.771601915 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.771718979 CEST | 49187 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.771732092 CEST | 443 | 49187 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.772330999 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.772392988 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.772548914 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.773075104 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.773113012 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.893675089 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.894490004 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.894524097 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:27.896410942 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:27.896430969 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.063087940 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.063153028 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.063239098 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.063260078 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.063323975 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.070012093 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.070060015 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.070079088 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.070091963 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.070102930 CEST | 49188 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.070112944 CEST | 443 | 49188 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.082968950 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.083033085 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.083123922 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.083307028 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.083327055 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.204646111 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.205641985 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.215804100 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.215838909 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.218364000 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.218400002 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.435931921 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.436047077 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.436167002 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.436270952 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.436301947 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.436321020 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.436332941 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.436424971 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.436430931 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.436595917 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.440187931 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.441576958 CEST | 49189 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.441603899 CEST | 443 | 49189 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.827261925 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.827295065 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.827404022 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.827625990 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.827641010 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.943757057 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.943856001 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.952480078 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.952502966 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:28.959297895 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:28.959317923 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.114829063 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.114999056 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.115210056 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.115246058 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.115403891 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.115432024 CEST | 443 | 49190 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.115508080 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.115557909 CEST | 49190 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.133202076 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.133276939 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.133439064 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.133662939 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.133683920 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.254767895 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.254934072 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.260881901 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.260899067 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.272063017 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.272089005 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487236977 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487308979 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487370968 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.487384081 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487390995 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.487437963 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.487452984 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487530947 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.487570047 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487643003 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.487653971 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487694025 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.487700939 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:29.487759113 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.489001036 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.549762964 CEST | 49191 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:29.549812078 CEST | 443 | 49191 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.106692076 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.106761932 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.106980085 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.107181072 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.107209921 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.235860109 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.236004114 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.242399931 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.242423058 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.245078087 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.245094061 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.477787971 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.477845907 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.477931976 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.478002071 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.478028059 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.478044033 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Sep 2, 2022 13:24:58.478063107 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.478176117 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.480907917 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.501635075 CEST | 49192 | 443 | 192.168.2.22 | 82.202.173.45 |
Sep 2, 2022 13:24:58.501671076 CEST | 443 | 49192 | 82.202.173.45 | 192.168.2.22 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 2, 2022 13:24:11.853436947 CEST | 55868 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:11.871222019 CEST | 53 | 55868 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:18.633838892 CEST | 49688 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:18.653536081 CEST | 53 | 49688 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:18.659006119 CEST | 58836 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:18.722076893 CEST | 53 | 58836 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:22.043364048 CEST | 50134 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:22.110351086 CEST | 53 | 50134 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:22.122073889 CEST | 55275 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:22.185585976 CEST | 53 | 55275 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:22.896694899 CEST | 59915 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:22.916980028 CEST | 53 | 59915 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:22.924175978 CEST | 54408 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:23.003745079 CEST | 53 | 54408 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:26.515650988 CEST | 50108 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:26.535551071 CEST | 53 | 50108 | 8.8.8.8 | 192.168.2.22 |
Sep 2, 2022 13:24:26.538368940 CEST | 54723 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 2, 2022 13:24:26.556077957 CEST | 53 | 54723 | 8.8.8.8 | 192.168.2.22 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Sep 2, 2022 13:24:11.853436947 CEST | 192.168.2.22 | 8.8.8.8 | 0xfbc4 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:18.633838892 CEST | 192.168.2.22 | 8.8.8.8 | 0xd915 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:18.659006119 CEST | 192.168.2.22 | 8.8.8.8 | 0xa259 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:22.043364048 CEST | 192.168.2.22 | 8.8.8.8 | 0xf2ca | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:22.122073889 CEST | 192.168.2.22 | 8.8.8.8 | 0xdc64 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:22.896694899 CEST | 192.168.2.22 | 8.8.8.8 | 0x646c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:22.924175978 CEST | 192.168.2.22 | 8.8.8.8 | 0x12f1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:26.515650988 CEST | 192.168.2.22 | 8.8.8.8 | 0x25fe | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 2, 2022 13:24:26.538368940 CEST | 192.168.2.22 | 8.8.8.8 | 0x9bb1 | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Sep 2, 2022 13:24:11.871222019 CEST | 8.8.8.8 | 192.168.2.22 | 0xfbc4 | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:18.653536081 CEST | 8.8.8.8 | 192.168.2.22 | 0xd915 | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:18.722076893 CEST | 8.8.8.8 | 192.168.2.22 | 0xa259 | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:22.110351086 CEST | 8.8.8.8 | 192.168.2.22 | 0xf2ca | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:22.185585976 CEST | 8.8.8.8 | 192.168.2.22 | 0xdc64 | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:22.916980028 CEST | 8.8.8.8 | 192.168.2.22 | 0x646c | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:23.003745079 CEST | 8.8.8.8 | 192.168.2.22 | 0x12f1 | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:26.535551071 CEST | 8.8.8.8 | 192.168.2.22 | 0x25fe | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) | ||
Sep 2, 2022 13:24:26.556077957 CEST | 8.8.8.8 | 192.168.2.22 | 0x9bb1 | No error (0) | 82.202.173.45 | A (IP address) | IN (0x0001) |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.22 | 49171 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:12 UTC | 0 | OUT | |
2022-09-02 11:24:12 UTC | 0 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.22 | 49172 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:18 UTC | 0 | OUT | |
2022-09-02 11:24:19 UTC | 0 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
10 | 192.168.2.22 | 49181 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:25 UTC | 22 | OUT | |
2022-09-02 11:24:25 UTC | 23 | IN | |
2022-09-02 11:24:25 UTC | 23 | IN | |
2022-09-02 11:24:25 UTC | 39 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
11 | 192.168.2.22 | 49182 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:25 UTC | 42 | OUT | |
2022-09-02 11:24:25 UTC | 42 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
12 | 192.168.2.22 | 49183 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:26 UTC | 43 | OUT | |
2022-09-02 11:24:26 UTC | 43 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
13 | 192.168.2.22 | 49184 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:26 UTC | 43 | OUT | |
2022-09-02 11:24:26 UTC | 43 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
14 | 192.168.2.22 | 49185 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:27 UTC | 44 | OUT | |
2022-09-02 11:24:27 UTC | 44 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
15 | 192.168.2.22 | 49186 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:27 UTC | 44 | OUT | |
2022-09-02 11:24:27 UTC | 44 | IN | |
2022-09-02 11:24:27 UTC | 45 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
16 | 192.168.2.22 | 49187 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:27 UTC | 49 | OUT | |
2022-09-02 11:24:27 UTC | 49 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
17 | 192.168.2.22 | 49188 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:27 UTC | 50 | OUT | |
2022-09-02 11:24:28 UTC | 50 | IN | |
2022-09-02 11:24:28 UTC | 50 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
18 | 192.168.2.22 | 49189 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:28 UTC | 55 | OUT | |
2022-09-02 11:24:28 UTC | 55 | IN | |
2022-09-02 11:24:28 UTC | 55 | IN | |
2022-09-02 11:24:28 UTC | 71 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
19 | 192.168.2.22 | 49190 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:28 UTC | 74 | OUT | |
2022-09-02 11:24:29 UTC | 74 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.22 | 49173 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:22 UTC | 1 | OUT | |
2022-09-02 11:24:22 UTC | 1 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
20 | 192.168.2.22 | 49191 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:29 UTC | 75 | OUT | |
2022-09-02 11:24:29 UTC | 75 | IN | |
2022-09-02 11:24:29 UTC | 76 | IN | |
2022-09-02 11:24:29 UTC | 91 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
21 | 192.168.2.22 | 49192 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:58 UTC | 94 | OUT | |
2022-09-02 11:24:58 UTC | 95 | IN | |
2022-09-02 11:24:58 UTC | 95 | IN | |
2022-09-02 11:24:58 UTC | 111 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.22 | 49174 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:22 UTC | 1 | OUT | |
2022-09-02 11:24:22 UTC | 1 | IN | |
2022-09-02 11:24:22 UTC | 2 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
4 | 192.168.2.22 | 49175 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:23 UTC | 6 | OUT | |
2022-09-02 11:24:23 UTC | 6 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
5 | 192.168.2.22 | 49176 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:23 UTC | 7 | OUT | |
2022-09-02 11:24:23 UTC | 7 | IN | |
2022-09-02 11:24:23 UTC | 7 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
6 | 192.168.2.22 | 49177 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:23 UTC | 11 | OUT | |
2022-09-02 11:24:23 UTC | 12 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
7 | 192.168.2.22 | 49178 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:24 UTC | 12 | OUT | |
2022-09-02 11:24:24 UTC | 12 | IN | |
2022-09-02 11:24:24 UTC | 13 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
8 | 192.168.2.22 | 49179 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:24 UTC | 17 | OUT | |
2022-09-02 11:24:24 UTC | 17 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
9 | 192.168.2.22 | 49180 | 82.202.173.45 | 443 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2022-09-02 11:24:24 UTC | 17 | OUT | |
2022-09-02 11:24:24 UTC | 18 | IN | |
2022-09-02 11:24:24 UTC | 18 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 13:23:18 |
Start date: | 02/09/2022 |
Path: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13f860000 |
File size: | 1423704 bytes |
MD5 hash: | 9EE74859D22DAE61F1750B3A1BACB6F5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |