Analysis Report
Overview
General Information |
---|
Joe Sandbox Version: | 21.0.0 |
Analysis ID: | 48021 |
Start time: | 10:37:03 |
Joe Sandbox Product: | Cloud |
Start date: | 16.01.2018 |
Overall analysis duration: | 0h 9m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | MaMi |
Cookbook file name: | defaultmacfilecookbook.jbs |
Analysis system description: | Virtual Machine, El Capitan 10.11.6 (MS Office 15.34, Java 1.8.0_131) |
Detection: | MAL |
Classification: | mal80.troj.spyw.evad.mac@0/43@5/0 |
Detection |
---|
Strategy | Score | Range | Reporting | Detection | |
---|---|---|---|---|---|
Threshold | 80 | 0 - 100 | Report FP / FN |
Classification |
---|
Signature Overview |
---|
Click to jump to signature section
Cryptography: |
---|
Imports (root) certificates into the systems keychain typically to intercept SSL traffic or bypass code integrity protections | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Certificate import: |
Writes DER encoded certificate files to disk without the typical file extension | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | DER file created: |
Networking: |
---|
Downloads files from webservers via HTTP | Show sources |
Source: global traffic | HTTP traffic detected: | ||
Source: global traffic | HTTP traffic detected: | ||
Source: global traffic | HTTP traffic detected: |
Performs DNS lookups | Show sources |
Source: unknown | DNS traffic detected: |
Posts data to webserver | Show sources |
Source: unknown | HTTP traffic detected: |
Reads from file descriptors related to (network) sockets | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Reads from socket in process: |
Urls found in memory or binary data | Show sources |
Source: MaMi | String found in binary or memory: | ||
Source: MaMi | String found in binary or memory: | ||
Source: MaMi | String found in binary or memory: |
Uses HTTPS | Show sources |
Source: unknown | Network traffic detected: | ||
Source: unknown | Network traffic detected: | ||
Source: unknown | Network traffic detected: | ||
Source: unknown | Network traffic detected: | ||
Source: unknown | Network traffic detected: | ||
Source: unknown | Network traffic detected: | ||
Source: unknown | Network traffic detected: | ||
Source: unknown | Network traffic detected: |
Writes from file descriptors related to (network) sockets | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Writes from socket in process: |
Executes the "networksetup" command used to configure network settings | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup executable: | ||
Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup executable: |
Explicitly retrieves the order of network devices used for connecting to the network | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup with list network services order args: |
Explicitly retrieves the configured DNS servers | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup with get DNS servers args: |
System Summary: |
---|
Classification label | Show sources |
Source: classification engine | Classification label: |
Data Obfuscation: |
---|
Imports the IOKit library (often used to register services) | Show sources |
Source: initial sample | Static MACH information: |
Persistence and Installation Behavior: |
---|
Executes the "awk" command used to scan for patterns (typically in standard output) | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Awk executable: |
Reads data from the local random generator | Show sources |
Source: /usr/libexec/diskmanagementd (PID: 509) | Random device file read: | ||
Source: /Users/luke/Desktop/MaMi (PID: 513) | Random device file read: | ||
Source: /Users/luke/Desktop/MaMi (PID: 513) | Random device file read: | ||
Source: /usr/bin/security (PID: 598) | Random device file read: |
Uses AppleKeyboardLayouts bundle containing keyboard layouts | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | AppleKeyboardLayouts info plist opened: |
Writes property list (.plist) files to disk | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | XML plist file created: | ||
Source: /bin/cp (PID: 518) | XML plist file created: | ||
Source: /bin/cp (PID: 520) | XML plist file created: | ||
Source: /bin/cp (PID: 524) | XML plist file created: | ||
Source: /bin/cp (PID: 526) | XML plist file created: | ||
Source: /bin/cp (PID: 537) | XML plist file created: | ||
Source: /bin/cp (PID: 539) | XML plist file created: | ||
Source: /bin/cp (PID: 543) | XML plist file created: | ||
Source: /bin/cp (PID: 545) | XML plist file created: | ||
Source: /bin/cp (PID: 549) | XML plist file created: | ||
Source: /bin/cp (PID: 551) | XML plist file created: | ||
Source: /bin/cp (PID: 555) | XML plist file created: | ||
Source: /bin/cp (PID: 557) | XML plist file created: | ||
Source: /bin/cp (PID: 561) | XML plist file created: | ||
Source: /bin/cp (PID: 563) | XML plist file created: | ||
Source: /bin/cp (PID: 567) | XML plist file created: | ||
Source: /bin/cp (PID: 569) | XML plist file created: | ||
Source: /bin/cp (PID: 573) | XML plist file created: | ||
Source: /bin/cp (PID: 575) | XML plist file created: | ||
Source: /bin/cp (PID: 579) | XML plist file created: | ||
Source: /bin/cp (PID: 581) | XML plist file created: | ||
Source: /bin/cp (PID: 585) | XML plist file created: | ||
Source: /bin/cp (PID: 587) | XML plist file created: | ||
Source: /bin/cp (PID: 595) | XML plist file created: | ||
Source: /bin/cp (PID: 597) | XML plist file created: | ||
Source: /bin/cp (PID: 603) | XML plist file created: | ||
Source: /bin/cp (PID: 605) | XML plist file created: | ||
Source: /bin/cp (PID: 609) | XML plist file created: | ||
Source: /bin/cp (PID: 611) | XML plist file created: | ||
Source: /bin/cp (PID: 615) | XML plist file created: | ||
Source: /bin/cp (PID: 617) | XML plist file created: | ||
Source: /bin/cp (PID: 621) | XML plist file created: | ||
Source: /bin/cp (PID: 623) | XML plist file created: | ||
Source: /bin/cp (PID: 627) | XML plist file created: | ||
Source: /bin/cp (PID: 629) | XML plist file created: | ||
Source: /bin/cp (PID: 633) | XML plist file created: | ||
Source: /bin/cp (PID: 635) | XML plist file created: |
Creates hidden files, links and/or directories | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Hidden file created: | ||
Source: /Users/luke/Desktop/MaMi (PID: 513) | Hidden file created: |
Executes commands using a shell command-line interpreter | Show sources |
Source: /usr/sbin/networksetup (PID: 517) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 519) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 523) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 525) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 536) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 538) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 542) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 544) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 548) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 550) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 554) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 556) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 560) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 562) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 566) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 568) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 572) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 574) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 578) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 580) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 584) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 586) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 594) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 596) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 602) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 604) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 608) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 610) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 614) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 616) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 620) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 622) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 626) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 628) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 632) | Shell command executed: | ||
Source: /usr/sbin/networksetup (PID: 634) | Shell command executed: |
Executes the "scutil" command used to manage network related system configuration parameters | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Scutil executable: |
Many shell processes execute programs via execve syscall (may be indicative for malicious behavior) | Show sources |
Source: /bin/sh (PID: 518) | Shell process: | ||
Source: /bin/sh (PID: 520) | Shell process: | ||
Source: /bin/sh (PID: 524) | Shell process: | ||
Source: /bin/sh (PID: 526) | Shell process: | ||
Source: /bin/sh (PID: 537) | Shell process: | ||
Source: /bin/sh (PID: 539) | Shell process: | ||
Source: /bin/sh (PID: 543) | Shell process: | ||
Source: /bin/sh (PID: 545) | Shell process: | ||
Source: /bin/sh (PID: 549) | Shell process: | ||
Source: /bin/sh (PID: 551) | Shell process: | ||
Source: /bin/sh (PID: 555) | Shell process: | ||
Source: /bin/sh (PID: 557) | Shell process: | ||
Source: /bin/sh (PID: 561) | Shell process: | ||
Source: /bin/sh (PID: 563) | Shell process: | ||
Source: /bin/sh (PID: 567) | Shell process: | ||
Source: /bin/sh (PID: 569) | Shell process: | ||
Source: /bin/sh (PID: 573) | Shell process: | ||
Source: /bin/sh (PID: 575) | Shell process: | ||
Source: /bin/sh (PID: 579) | Shell process: | ||
Source: /bin/sh (PID: 581) | Shell process: | ||
Source: /bin/sh (PID: 585) | Shell process: | ||
Source: /bin/sh (PID: 587) | Shell process: | ||
Source: /bin/sh (PID: 595) | Shell process: | ||
Source: /bin/sh (PID: 597) | Shell process: | ||
Source: /bin/sh (PID: 603) | Shell process: | ||
Source: /bin/sh (PID: 605) | Shell process: | ||
Source: /bin/sh (PID: 609) | Shell process: | ||
Source: /bin/sh (PID: 611) | Shell process: | ||
Source: /bin/sh (PID: 615) | Shell process: | ||
Source: /bin/sh (PID: 617) | Shell process: | ||
Source: /bin/sh (PID: 621) | Shell process: | ||
Source: /bin/sh (PID: 623) | Shell process: | ||
Source: /bin/sh (PID: 627) | Shell process: | ||
Source: /bin/sh (PID: 629) | Shell process: | ||
Source: /bin/sh (PID: 633) | Shell process: | ||
Source: /bin/sh (PID: 635) | Shell process: |
Samples exit code indicates no error despite standard error output | Show sources |
Source: submitted sample | Stderr: 2018-01-16 11:38:38.416 MaMi[513:4712] chmodding parent /var/root/Library/Cookies with perm 700: |
Writes DER encoded certificate files to disk without the typical file extension | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | DER file created: |
Hooking and other Techniques for Hiding and Protection: |
---|
Moves itself during installation or deletes itself after installation | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | File deleted: |
Language, Device and Operating System Detection: |
---|
Reads the system or server version plist file | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | System or server version plist file read: |
Reads the systems hostname | Show sources |
Source: /bin/sh (PID: 518) | Sysctl requested: | ||
Source: /bin/sh (PID: 520) | Sysctl requested: | ||
Source: /bin/sh (PID: 524) | Sysctl requested: | ||
Source: /bin/sh (PID: 526) | Sysctl requested: | ||
Source: /bin/sh (PID: 537) | Sysctl requested: | ||
Source: /bin/sh (PID: 539) | Sysctl requested: | ||
Source: /bin/sh (PID: 543) | Sysctl requested: | ||
Source: /bin/sh (PID: 545) | Sysctl requested: | ||
Source: /bin/sh (PID: 549) | Sysctl requested: | ||
Source: /bin/sh (PID: 551) | Sysctl requested: | ||
Source: /bin/sh (PID: 555) | Sysctl requested: | ||
Source: /bin/sh (PID: 557) | Sysctl requested: | ||
Source: /bin/sh (PID: 561) | Sysctl requested: | ||
Source: /bin/sh (PID: 563) | Sysctl requested: | ||
Source: /bin/sh (PID: 567) | Sysctl requested: | ||
Source: /bin/sh (PID: 569) | Sysctl requested: | ||
Source: /bin/sh (PID: 573) | Sysctl requested: | ||
Source: /bin/sh (PID: 575) | Sysctl requested: | ||
Source: /bin/sh (PID: 579) | Sysctl requested: | ||
Source: /bin/sh (PID: 581) | Sysctl requested: | ||
Source: /bin/sh (PID: 585) | Sysctl requested: | ||
Source: /bin/sh (PID: 587) | Sysctl requested: | ||
Source: /bin/sh (PID: 595) | Sysctl requested: | ||
Source: /bin/sh (PID: 597) | Sysctl requested: | ||
Source: /bin/sh (PID: 603) | Sysctl requested: | ||
Source: /bin/sh (PID: 605) | Sysctl requested: | ||
Source: /bin/sh (PID: 609) | Sysctl requested: | ||
Source: /bin/sh (PID: 611) | Sysctl requested: | ||
Source: /bin/sh (PID: 615) | Sysctl requested: | ||
Source: /bin/sh (PID: 617) | Sysctl requested: | ||
Source: /bin/sh (PID: 621) | Sysctl requested: | ||
Source: /bin/sh (PID: 623) | Sysctl requested: | ||
Source: /bin/sh (PID: 627) | Sysctl requested: | ||
Source: /bin/sh (PID: 629) | Sysctl requested: | ||
Source: /bin/sh (PID: 633) | Sysctl requested: | ||
Source: /bin/sh (PID: 635) | Sysctl requested: |
Executes the "ioreg" command used to gather hardware information (I/O kit registry) | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | IOreg executable: |
Queries the unique Apple serial number of the machine | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | IOPlatformSerialNumber keyword found in command: |
Stealing of Sensitive Information: |
---|
Executes the "security" command used to access the keychain | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Security executable: |
Imports (root) certificates into the systems keychain typically to intercept SSL traffic or bypass code integrity protections | Show sources |
Source: /Users/luke/Desktop/MaMi (PID: 513) | Certificate import: |
Runtime Messages |
---|
Command: | /Users/luke/Desktop/MaMi |
Exitcode: | 0 |
Killed: | False |
Standard Output: | |
Standard Error: | 2018-01-16 11:38:38.416 MaMi[513:4712] chmodding parent /var/root/Library/Cookies with perm 700 |
Behavior Graph |
---|
Yara Overview |
---|
Initial Sample |
---|
No yara matches |
---|
PCAP (Network Traffic) |
---|
No yara matches |
---|
Dropped Files |
---|
No yara matches |
---|
Memory Dumps |
---|
No yara matches |
---|
Unpacked PEs |
---|
No yara matches |
---|
Antivirus Detection |
---|
Screenshot |
---|
Startup |
---|
|
Created / dropped Files |
---|
File Type: | |
Size (bytes): | 33696 |
Entropy (8bit): | 4.249455295583855 |
Encrypted: | false |
MD5: | 9DD3851D5FB343992F7DB778C97C56A4 |
SHA1: | 7FFCAD715CB343B468C24B3271950B4938FC72F7 |
SHA-256: | 882B665925BE90D45ACCAED36325B31DB0BCB0D3074F14DC22D283A552C590B6 |
SHA-512: | 8528848DD41D36E89FDD093A28F05307CF6D983A5B893D8DF2451A08AC1EC3ECC5E136962AEC8F7C676C399712D6F421E6D3AFBF9884E5C8731440E91FB177F5 |
Malicious: | false |
Reputation: | low |
File Type: | |
Size (bytes): | 12 |
Entropy (8bit): | 2.0 |
Encrypted: | false |
MD5: | 08275E96591EEA52C64B0866004B02D3 |
SHA1: | B5DC7150EC53B6B802A64DFF4E65149DBDECD2CE |
SHA-256: | 959402A34FAB43E548CB7F1A4CBF53E341A3D536846A58E943C922ABE2FBC148 |
SHA-512: | BAAE4EEC184623B23109463FAF4F86409B74C8DC701A1A278A9141D9F44CF16731F51D14B581F1EF723B024BFB36672860FD8C59603456D7EA2945977463BF20 |
Malicious: | false |
Reputation: | low |
File Type: | |
Size (bytes): | 4594 |
Entropy (8bit): | 4.922151867635323 |
Encrypted: | false |
MD5: | D29D035A55239D6A77A94EECD344313C |
SHA1: | 5C73FA173533B38F245B76B393ADBD4791EBBC84 |
SHA-256: | 8838003894E4583853CEBCAB515338E0DB708AE15440B47BF5FAE254C80D0C14 |
SHA-512: | 5F71B81D161E574DA1729A9E52262CD4C841B7E9CD395459220BACF149EA17067AAFD059A9A961C4B538678B2B3613A5BB5413E28DF7800CF3E05FDF745B45B5 |
Malicious: | false |
Reputation: | low |
File Type: | |
Size (bytes): | 4594 |
Entropy (8bit): | 4.922151867635323 |
Encrypted: | false |
MD5: | D29D035A55239D6A77A94EECD344313C |
SHA1: | 5C73FA173533B38F245B76B393ADBD4791EBBC84 |
SHA-256: | 8838003894E4583853CEBCAB515338E0DB708AE15440B47BF5FAE254C80D0C14 |
SHA-512: | 5F71B81D161E574DA1729A9E52262CD4C841B7E9CD395459220BACF149EA17067AAFD059A9A961C4B538678B2B3613A5BB5413E28DF7800CF3E05FDF745B45B5 |
Malicious: | true |
Reputation: | low |
File Type: | |
Size (bytes): | 1021 |
Entropy (8bit): | 7.295459366431303 |
Encrypted: | false |
MD5: | 5FBB11485CD05D8986488D11EB22FEDD |
SHA1: | 26D9E607FFF0C58C7844B47FF8B6E079E5A2220E |
SHA-256: | C17861B640492388D50FF5DAC282ED502AEC9AD1AA4AA07DD977FA9AB2567C30 |
SHA-512: | 99FFC26EBAACEC0155AA99FC6814CF0A7F1394DDA8B1796ED998F7B3B87472E512097ED7BBA1A834DDA1A73E90D17A76B0120F9C51AA7332265A98EF9C193713 |
Malicious: | true |
Reputation: | low |
File Type: | |
Size (bytes): | 100 |
Entropy (8bit): | 5.6063701301561855 |
Encrypted: | false |
MD5: | FB86CDB211DF8ED5E11672C7E3479249 |
SHA1: | B80C1DD0DF541674FD3B76906B52DF79E3553B62 |
SHA-256: | 3BB51CC3D4ECD1E24C22AE17C635726A3875AAE5CDE4B125520D8E72633BF1B1 |
SHA-512: | C473726F516939295536F7BE1E6172D0487C063B20862E5C8AEBF6ED6101CC6DD86285C8C003D78A6DFA1E69F9FFF1DFDC5BDB1AA7DE85B772C5A5F6AD977EDB |
Malicious: | false |
Reputation: | low |
File Type: | |
Size (bytes): | 29 |
Entropy (8bit): | 4.306256857196538 |
Encrypted: | false |
MD5: | 5BB01FE1F6043852CD6138586BC463D7 |
SHA1: | 2E2514514532E95DE6DD638C0C490E264801E658 |
SHA-256: | 70780754EA748E33B105EB1FCA355B25777D4296A46D8CBC8C8B73FA7724DBA6 |
SHA-512: | DB87579A98F4DF6F2A94F5318E51CD6F2634FAF307DEF7E2B98435F8D4F7D32157C452C6332E4E3BACEE4CF041101DE8AEC24B2915B9021CCF7D1E746618DBAF |
Malicious: | false |
Reputation: | low |
File Type: | |
Size (bytes): | 777 |
Entropy (8bit): | 4.420222670133278 |
Encrypted: | false |
MD5: | BBE2E55DE6FE2A888EE4AEA9E5325A4D |
SHA1: | 8A16748B5F1B3316C26781966714B6F57360B735 |
SHA-256: | D5DB52D3BBFA3D7EAB97CE2496D2BE26C6F8A80A76DAFE8EAD0B732ACE722735 |
SHA-512: | 423561D0BDE495F384AF06976D01BFC5E30A6180A38CA0A117F27E8FEF91B6625AEFBF25372D58426192610ECE1D2AB38E232521A1FDD10E6902B1CFF5232208 |
Malicious: | false |
Reputation: | low |
Contacted Domains/Contacted IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection |
---|---|---|---|---|
squartera.info | 104.31.80.139 | true | false | |
gorensin.info | 104.27.134.218 | true | false | |
honouncil.info | 104.28.13.190 | true | false |
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|
104.28.13.190 | United States | 13335 | CLOUDFLARENET-CloudFlareIncUS | false | |
23.45.113.221 | United States | 20940 | AKAMAI-ASN1US | false | |
82.163.142.137 | United Kingdom | 204078 | GREENTEAMIL | false | |
23.45.112.74 | United States | 20940 | AKAMAI-ASN1US | false | |
72.21.91.29 | United States | 15133 | EDGECAST-MCICommunicationsServicesIncdbaVerizonB | false | |
8.8.8.8 | United States | 15169 | GOOGLE-GoogleIncUS | false | |
104.27.134.218 | United States | 13335 | CLOUDFLARENET-CloudFlareIncUS | false | |
82.163.143.135 | United Kingdom | 204078 | GREENTEAMIL | false | |
104.31.80.139 | United States | 13335 | CLOUDFLARENET-CloudFlareIncUS | false | |
17.253.54.125 | United States | 6185 | APPLE-AUSTIN-AppleIncUS | false |
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.047403534655477 |
TrID: |
|
File name: | MaMi |
File size: | 565673 |
MD5: | 6e6034c13cb949156888513211b1f1ef |
SHA1: | f596b8ae209a1600a33a230e9904472b6d4ba1c0 |
SHA256: | 5586be30d505216bdc912605481f9c8c7bfd52748f66c5e212160f6b31fd8571 |
SHA512: | 5e67267e14cd1fa694c00ff4d7c854407888bfff11a54e3e63006fe332933ead3584efc2b584a95976c91785c0027fd2f4a936fa48984a381cef567b1a9d0b17 |
File Content Preview: | ....................P.....!.........H...__PAGEZERO..............................................................__TEXT................... ............... ......................__text..........__TEXT...................@..................................... |
Static Mach Info |
---|
General Informations for header0 | |
---|---|
Endian: | |
Size: | |
Architecture: | |
Filetype: | |
Nbr. of load commands: |
segment_command_64 |
---|
Name | Value | |
---|---|---|
segname | __PAGEZERO | |
fileoff | 0 | |
maxprot | 0 | |
vmsize | 4294967296 | |
nsects | 0 | |
flags | 0 | |
filesize | 0 | |
vmaddr | 0 | |
initprot | 0 |
segment_command_64 |
---|
Name | Value | |
---|---|---|
segname | __TEXT | |
fileoff | 0 | |
maxprot | 7 | |
vmsize | 335872 | |
nsects | 11 | |
flags | 0 | |
filesize | 335872 | |
vmaddr | 4294967296 | |
initprot | 5 | |
Datas | sectname | __text |
segname | __TEXT | |
reloff | 0 | |
addr | 4294973824 | |
align | 4 | |
nreloc | 0 | |
flags | 2147484672 | |
offset | 6528 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 213122 | |
sectname | __stubs | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295186946 | |
align | 1 | |
nreloc | 0 | |
flags | 2147484680 | |
offset | 219650 | |
reserved2 | 6 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 1344 | |
sectname | __stub_helper | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295188292 | |
align | 2 | |
nreloc | 0 | |
flags | 2147484672 | |
offset | 220996 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 2216 | |
sectname | __const | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295190512 | |
align | 4 | |
nreloc | 0 | |
flags | 0 | |
offset | 223216 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 1176 | |
sectname | __gcc_except_tab | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295191688 | |
align | 2 | |
nreloc | 0 | |
flags | 0 | |
offset | 224392 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 5364 | |
sectname | __cstring | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295197056 | |
align | 4 | |
nreloc | 0 | |
flags | 2 | |
offset | 229760 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 25864 | |
sectname | __objc_methname | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295222920 | |
align | 0 | |
nreloc | 0 | |
flags | 2 | |
offset | 255624 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 24247 | |
sectname | __objc_classname | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295247167 | |
align | 0 | |
nreloc | 0 | |
flags | 2 | |
offset | 279871 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 509 | |
sectname | __objc_methtype | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295247676 | |
align | 0 | |
nreloc | 0 | |
flags | 2 | |
offset | 280380 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 3133 | |
sectname | __unwind_info | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295250812 | |
align | 2 | |
nreloc | 0 | |
flags | 0 | |
offset | 283516 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 4944 | |
sectname | __eh_frame | |
segname | __TEXT | |
reloff | 0 | |
addr | 4295255760 | |
align | 3 | |
nreloc | 0 | |
flags | 0 | |
offset | 288464 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 47400 |
segment_command_64 |
---|
Name | Value | |
---|---|---|
segname | __DATA | |
fileoff | 335872 | |
maxprot | 7 | |
vmsize | 81920 | |
nsects | 20 | |
flags | 0 | |
filesize | 77824 | |
vmaddr | 4295303168 | |
initprot | 3 | |
Datas | sectname | __nl_symbol_ptr |
segname | __DATA | |
reloff | 0 | |
addr | 4295303168 | |
align | 3 | |
nreloc | 0 | |
flags | 6 | |
offset | 335872 | |
reserved2 | 0 | |
reserved1 | 224 | |
reserved3 | 0 | |
size | 16 | |
sectname | __got | |
segname | __DATA | |
reloff | 0 | |
addr | 4295303184 | |
align | 3 | |
nreloc | 0 | |
flags | 6 | |
offset | 335888 | |
reserved2 | 0 | |
reserved1 | 226 | |
reserved3 | 0 | |
size | 800 | |
sectname | __la_symbol_ptr | |
segname | __DATA | |
reloff | 0 | |
addr | 4295303984 | |
align | 3 | |
nreloc | 0 | |
flags | 7 | |
offset | 336688 | |
reserved2 | 0 | |
reserved1 | 326 | |
reserved3 | 0 | |
size | 1792 | |
sectname | __const | |
segname | __DATA | |
reloff | 0 | |
addr | 4295305776 | |
align | 4 | |
nreloc | 0 | |
flags | 0 | |
offset | 338480 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 592 | |
sectname | __cfstring | |
segname | __DATA | |
reloff | 0 | |
addr | 4295306368 | |
align | 3 | |
nreloc | 0 | |
flags | 0 | |
offset | 339072 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 19520 | |
sectname | __objc_classlist | |
segname | __DATA | |
reloff | 0 | |
addr | 4295325888 | |
align | 3 | |
nreloc | 0 | |
flags | 268435456 | |
offset | 358592 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 176 | |
sectname | __objc_nlclslist | |
segname | __DATA | |
reloff | 0 | |
addr | 4295326064 | |
align | 3 | |
nreloc | 0 | |
flags | 268435456 | |
offset | 358768 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 8 | |
sectname | __objc_catlist | |
segname | __DATA | |
reloff | 0 | |
addr | 4295326072 | |
align | 3 | |
nreloc | 0 | |
flags | 268435456 | |
offset | 358776 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 16 | |
sectname | __objc_protolist | |
segname | __DATA | |
reloff | 0 | |
addr | 4295326088 | |
align | 3 | |
nreloc | 0 | |
flags | 0 | |
offset | 358792 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 64 | |
sectname | __objc_imageinfo | |
segname | __DATA | |
reloff | 0 | |
addr | 4295326152 | |
align | 2 | |
nreloc | 0 | |
flags | 0 | |
offset | 358856 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 8 | |
sectname | __objc_const | |
segname | __DATA | |
reloff | 0 | |
addr | 4295326160 | |
align | 3 | |
nreloc | 0 | |
flags | 0 | |
offset | 358864 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 36840 | |
sectname | __objc_selrefs | |
segname | __DATA | |
reloff | 0 | |
addr | 4295363000 | |
align | 3 | |
nreloc | 0 | |
flags | 268435461 | |
offset | 395704 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 7472 | |
sectname | __objc_protorefs | |
segname | __DATA | |
reloff | 0 | |
addr | 4295370472 | |
align | 3 | |
nreloc | 0 | |
flags | 0 | |
offset | 403176 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 16 | |
sectname | __objc_classrefs | |
segname | __DATA | |
reloff | 0 | |
addr | 4295370488 | |
align | 3 | |
nreloc | 0 | |
flags | 268435456 | |
offset | 403192 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 592 | |
sectname | __objc_superrefs | |
segname | __DATA | |
reloff | 0 | |
addr | 4295371080 | |
align | 3 | |
nreloc | 0 | |
flags | 268435456 | |
offset | 403784 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 144 | |
sectname | __objc_ivar | |
segname | __DATA | |
reloff | 0 | |
addr | 4295371224 | |
align | 3 | |
nreloc | 0 | |
flags | 0 | |
offset | 403928 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 1544 | |
sectname | __objc_data | |
segname | __DATA | |
reloff | 0 | |
addr | 4295372768 | |
align | 3 | |
nreloc | 0 | |
flags | 0 | |
offset | 405472 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 1840 | |
sectname | __data | |
segname | __DATA | |
reloff | 0 | |
addr | 4295374608 | |
align | 4 | |
nreloc | 0 | |
flags | 0 | |
offset | 407312 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 3232 | |
sectname | __bss | |
segname | __DATA | |
reloff | 0 | |
addr | 4295377840 | |
align | 4 | |
nreloc | 0 | |
flags | 1 | |
offset | 0 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 5056 | |
sectname | __common | |
segname | __DATA | |
reloff | 0 | |
addr | 4295382896 | |
align | 4 | |
nreloc | 0 | |
flags | 1 | |
offset | 0 | |
reserved2 | 0 | |
reserved1 | 0 | |
reserved3 | 0 | |
size | 273 |
segment_command_64 |
---|
Name | Value | |
---|---|---|
segname | __LINKEDIT | |
fileoff | 413696 | |
maxprot | 7 | |
vmsize | 151552 | |
nsects | 0 | |
flags | 0 | |
filesize | 149624 | |
vmaddr | 4295385088 | |
initprot | 1 |
dyld_info_command |
---|
Name | Value | |
---|---|---|
lazy_bind_size | 7240 | |
lazy_bind_off | 421768 | |
weak_bind_size | 1496 | |
rebase_size | 1264 | |
export_off | 429008 | |
export_size | 8160 | |
bind_off | 414960 | |
rebase_off | 413696 | |
bind_size | 5312 | |
weak_bind_off | 420272 |
symtab_command |
---|
Name | Value | |
---|---|---|
strsize | 87504 | |
symoff | 438672 | |
stroff | 475816 | |
nsyms | 2184 |
dysymtab_command |
---|
Name | Value | |
---|---|---|
extreloff | 0 | |
nlocrel | 0 | |
indirectsymoff | 473616 | |
modtaboff | 0 | |
nextrel | 0 | |
iundefsym | 1807 | |
nmodtab | 0 | |
ilocalsym | 0 | |
nundefsym | 377 | |
nextrefsyms | 0 | |
locreloff | 0 | |
ntoc | 0 | |
nlocalsym | 1514 | |
tocoff | 0 | |
extrefsymoff | 0 | |
nindirectsyms | 550 | |
iextdefsym | 1514 | |
nextdefsym | 293 |
dylinker_command |
---|
Name | Value | |
---|---|---|
name | 12 | Data | /usr/lib/dyld |
uuid_command |
---|
Name | Value | |
---|---|---|
uuid | 300aca14e34b3e2d88eb0c2db0ed159c |
version_min_command |
---|
Name | Value | |
---|---|---|
version | 657408 | |
reserved | 658432 |
source_version_command |
---|
Name | Value | |
---|---|---|
version | 0 |
entry_point_command |
---|
Name | Value | |
---|---|---|
stacksize | 0 | |
entryoff | 19417 |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 1280.51.1 | Data | /usr/lib/libc++.1.dylib |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 520.1.0 | Data | /usr/lib/libz.1.dylib |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.44.1 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 16128.69.5 | Data | /System/Library/Frameworks/Foundation.framework/Versions/C/Foundation |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 0.228.0 | Data | /usr/lib/libobjc.A.dylib |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 12802.214.4 | Data | /usr/lib/libSystem.B.dylib |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.45.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 21096.224.5 | Data | /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 0.48.0 | Data | /System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 1042.43.3 | Data | /System/Library/Frameworks/CFNetwork.framework/Versions/A/CFNetwork |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.150.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 16384.69.5 | Data | /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.64.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 5632.46.4 | Data | /System/Library/Frameworks/CoreGraphics.framework/Versions/A/CoreGraphics |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 4864.7.3 | Data | /System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 0.19.1 | Data | /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
dylib_command |
---|
Name | Value | |
---|---|---|
compatibility_version | 0.1.0 | |
timestamp | Thu Jan 01 01:00:02 1970 | |
name | 24 | |
current_version | 13057.120.3 | Data | /System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration |
linkedit_data_command |
---|
Name | Value | |
---|---|---|
dataoff | 437168 | |
datassize | 1496 |
linkedit_data_command |
---|
Name | Value | |
---|---|---|
dataoff | 438664 | |
datassize | 8 |
Network Behavior |
---|
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 16, 2018 10:38:28.495457888 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:28.495830059 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.512610912 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.512631893 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:28.517251015 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.517293930 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:28.517833948 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.529958963 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.529979944 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:28.702174902 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.702208996 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:28.702867031 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.704881907 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:28.704902887 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.135426044 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.135977983 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.392107964 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.392664909 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.453325987 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.453691006 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.465013027 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.465497971 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.479163885 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.479202032 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.479254961 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.479266882 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.479273081 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.479284048 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.489674091 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.490376949 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.504399061 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.504420996 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.504453897 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.504462004 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:29.504484892 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:29.504492998 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:30.187161922 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:30.187697887 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:30.188889980 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:30.188913107 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:30.210139036 MEZ | 57875 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:30.257009029 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:30.257494926 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:30.258661032 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:30.258682013 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:30.612297058 MEZ | 53 | 57875 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:30.730536938 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:30.730557919 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:30.800291061 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:30.800935030 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:31.316409111 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:31.316910028 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:31.327824116 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:31.328321934 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:32.109383106 MEZ | 56351 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:32.109441996 MEZ | 53 | 56351 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:32.115458965 MEZ | 53017 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:32.115931034 MEZ | 63638 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:32.479837894 MEZ | 53 | 53017 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:32.683762074 MEZ | 53 | 63638 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:32.906513929 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:32.906542063 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:33.300405979 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:33.300728083 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:33.324394941 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
Jan 16, 2018 10:38:33.936409950 MEZ | 80 | 49190 | 72.21.91.29 | 192.168.0.53 |
Jan 16, 2018 10:38:33.936995983 MEZ | 49190 | 80 | 192.168.0.53 | 72.21.91.29 |
Jan 16, 2018 10:38:35.064308882 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:35.064333916 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:35.712307930 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:35.712666988 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:35.750128984 MEZ | 56806 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:36.481611013 MEZ | 53 | 56806 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:36.482770920 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:36.482812881 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:36.483573914 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:36.485268116 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:36.485285997 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:36.485536098 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:36.485548973 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:37.105518103 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:37.105540037 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:37.335010052 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:37.335021019 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:37.335489988 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:37.360729933 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:37.360810995 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:37.361323118 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:37.363715887 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:37.363763094 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:37.364335060 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:37.366035938 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:37.366056919 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:37.366321087 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:37.366333961 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:37.854811907 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:37.855370045 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:38.219822884 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:38.219834089 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:38.220417976 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:38.221458912 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:38.221518993 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:38.222062111 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:38.224977970 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:38.225011110 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:38.225564957 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:38.227031946 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:38.227047920 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:38.227294922 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:38.227308035 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:39.037847042 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:39.037861109 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:39.038592100 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:39.231729984 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:39.231755018 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:39.257999897 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:39.258507967 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:39.259450912 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:39.259516001 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
Jan 16, 2018 10:38:39.260143995 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
Jan 16, 2018 10:38:39.596726894 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:39.596867085 MEZ | 53 | 65226 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:39.597529888 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.142.137 |
Jan 16, 2018 10:38:39.597626925 MEZ | 53 | 65226 | 82.163.142.137 | 192.168.0.53 |
Jan 16, 2018 10:38:39.597929001 MEZ | 50111 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:39.597970009 MEZ | 53 | 50111 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:40.078402996 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:40.078896999 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:40.114228010 MEZ | 57717 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.116482019 MEZ | 62127 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.118319988 MEZ | 50145 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.121865034 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.548860073 MEZ | 62965 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.841768026 MEZ | 53 | 57717 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.007045984 MEZ | 53 | 62127 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.063930988 MEZ | 53 | 50145 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.188694954 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:41.190223932 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.223583937 MEZ | 52922 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:41.347417116 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:41.347440004 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:41.392683029 MEZ | 53 | 62965 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.926094055 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:42.070797920 MEZ | 53 | 52922 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:42.071732998 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:42.071768999 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:42.072567940 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:42.074453115 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:42.074471951 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:42.184029102 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:42.184545994 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:42.817600012 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:42.817609072 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:42.818187952 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:42.872332096 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:42.872915030 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:42.873908043 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:42.873991966 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:42.874522924 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:42.876209021 MEZ | 54507 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:43.459681988 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:43.459707975 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:43.570421934 MEZ | 53 | 54507 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:43.571280956 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
Jan 16, 2018 10:38:43.571336031 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
Jan 16, 2018 10:38:43.571891069 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
Jan 16, 2018 10:38:43.573754072 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
Jan 16, 2018 10:38:43.573772907 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
Jan 16, 2018 10:38:44.338212967 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
Jan 16, 2018 10:38:44.338227987 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
Jan 16, 2018 10:38:44.338785887 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
Jan 16, 2018 10:38:44.340049982 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
Jan 16, 2018 10:38:44.340171099 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
Jan 16, 2018 10:38:44.340754986 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
Jan 16, 2018 10:38:44.342609882 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:44.342668056 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:44.343724966 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:44.345383883 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:44.345405102 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:44.477978945 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:44.478610992 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:45.302794933 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:45.302805901 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:45.303338051 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:45.305030107 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:45.305094004 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
Jan 16, 2018 10:38:45.305697918 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
Jan 16, 2018 10:38:45.572709084 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:45.572732925 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:46.344804049 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:46.345326900 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:47.705620050 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:47.705643892 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:48.352015972 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:48.352549076 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:49.808871031 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:49.808897018 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:50.313086033 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:50.313602924 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:51.901590109 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:51.901609898 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:52.355698109 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:52.356184006 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:53.693825006 MEZ | 49190 | 80 | 192.168.0.53 | 72.21.91.29 |
Jan 16, 2018 10:38:53.693854094 MEZ | 80 | 49190 | 72.21.91.29 | 192.168.0.53 |
Jan 16, 2018 10:38:54.005795956 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:54.005820990 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:54.563170910 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:54.563838005 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:56.108951092 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:56.108979940 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:56.583056927 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:56.583508968 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:56.854804993 MEZ | 49184 | 443 | 192.168.0.53 | 23.45.112.74 |
Jan 16, 2018 10:38:56.854892015 MEZ | 443 | 49184 | 23.45.112.74 | 192.168.0.53 |
Jan 16, 2018 10:38:56.855150938 MEZ | 49184 | 443 | 192.168.0.53 | 23.45.112.74 |
Jan 16, 2018 10:38:58.194991112 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:38:58.195014000 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:58.667030096 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:38:58.667691946 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:00.343030930 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:00.343055010 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:00.784032106 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:00.784590960 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:02.449940920 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:02.449966908 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:02.963887930 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:02.964428902 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:04.599488974 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:04.599519014 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:05.091592073 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:05.092231989 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:06.745258093 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:06.745282888 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:07.165596962 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:07.166117907 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:08.828758955 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:08.828780890 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:09.316236019 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:09.316829920 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:11.047348976 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:11.047378063 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:11.504631042 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:11.505038023 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:13.147633076 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:13.147654057 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:13.604799986 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:13.605537891 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:15.283921957 MEZ | 52805 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:39:15.309907913 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:15.309931993 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:15.659476995 MEZ | 53 | 52805 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:39:15.743515968 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:15.744064093 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:17.469773054 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:17.469801903 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:17.878190041 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:17.878729105 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:19.549875021 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:19.549900055 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:20.077354908 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:20.077850103 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:21.636038065 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:21.636063099 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:22.094731092 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:22.095200062 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:23.752785921 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:23.752808094 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:24.221636057 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:24.222160101 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:25.789092064 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:25.789118052 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:26.447158098 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:26.447531939 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:27.862070084 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:27.862096071 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:28.288945913 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:28.289412975 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:29.870589972 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:29.870615959 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:30.292367935 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:30.293275118 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:30.494515896 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:30.494605064 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:30.495016098 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:30.495086908 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:30.495168924 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:30.495440960 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:31.991152048 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:31.991179943 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:32.551772118 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:32.552283049 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:34.010811090 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:34.010837078 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:34.459500074 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:34.460496902 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:36.102005959 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:36.102027893 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:36.889048100 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:36.889590979 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:38.174233913 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:38.174257040 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:38.850723982 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:38.851217031 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:40.272917986 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:40.272943020 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:41.078850985 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:41.079226971 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:42.375071049 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:42.375092030 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:43.300342083 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:43.300893068 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:43.863850117 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
Jan 16, 2018 10:39:44.417535067 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:44.417557955 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:45.272310019 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:45.272629023 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:46.501255035 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:46.501281023 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:47.300358057 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:47.300888062 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:49.043034077 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:39:49.043055058 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:49.716077089 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:39:49.716593027 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:40:32.424252987 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
Jan 16, 2018 10:40:32.424417973 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
Jan 16, 2018 10:40:32.424876928 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 16, 2018 10:38:30.210139036 MEZ | 57875 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:30.612297058 MEZ | 53 | 57875 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:32.109383106 MEZ | 56351 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:32.109441996 MEZ | 53 | 56351 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:32.115458965 MEZ | 53017 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:32.115931034 MEZ | 63638 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:32.479837894 MEZ | 53 | 53017 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:32.683762074 MEZ | 53 | 63638 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:33.324394941 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
Jan 16, 2018 10:38:35.750128984 MEZ | 56806 | 53 | 192.168.0.53 | 8.8.8.8 |
Jan 16, 2018 10:38:36.481611013 MEZ | 53 | 56806 | 8.8.8.8 | 192.168.0.53 |
Jan 16, 2018 10:38:39.596726894 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:39.596867085 MEZ | 53 | 65226 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:39.597529888 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.142.137 |
Jan 16, 2018 10:38:39.597626925 MEZ | 53 | 65226 | 82.163.142.137 | 192.168.0.53 |
Jan 16, 2018 10:38:39.597929001 MEZ | 50111 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:39.597970009 MEZ | 53 | 50111 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:40.114228010 MEZ | 57717 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.116482019 MEZ | 62127 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.118319988 MEZ | 50145 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.121865034 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.548860073 MEZ | 62965 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:40.841768026 MEZ | 53 | 57717 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.007045984 MEZ | 53 | 62127 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.063930988 MEZ | 53 | 50145 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.188694954 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:41.190223932 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.223583937 MEZ | 52922 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:41.392683029 MEZ | 53 | 62965 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:41.926094055 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:42.070797920 MEZ | 53 | 52922 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:38:42.876209021 MEZ | 54507 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:38:43.570421934 MEZ | 53 | 54507 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:39:15.283921957 MEZ | 52805 | 53 | 192.168.0.53 | 82.163.143.135 |
Jan 16, 2018 10:39:15.659476995 MEZ | 53 | 52805 | 82.163.143.135 | 192.168.0.53 |
Jan 16, 2018 10:39:43.863850117 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
ICMP Packets |
---|
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 16, 2018 10:38:32.109935999 MEZ | 192.168.0.53 | 8.8.8.8 | 2089 | (Port unreachable) | Destination Unreachable |
Jan 16, 2018 10:38:41.926675081 MEZ | 192.168.0.53 | 82.163.143.135 | 130f | (Port unreachable) | Destination Unreachable |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Jan 16, 2018 10:38:32.115458965 MEZ | 192.168.0.53 | 8.8.8.8 | 0xaac4 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jan 16, 2018 10:38:32.115931034 MEZ | 192.168.0.53 | 8.8.8.8 | 0x6a12 | Standard query (0) | 28 | IN (0x0001) | |
Jan 16, 2018 10:38:35.750128984 MEZ | 192.168.0.53 | 8.8.8.8 | 0x23d3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jan 16, 2018 10:38:41.223583937 MEZ | 192.168.0.53 | 82.163.143.135 | 0xe0b0 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jan 16, 2018 10:38:42.876209021 MEZ | 192.168.0.53 | 82.163.143.135 | 0x5f26 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Replay Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Jan 16, 2018 10:38:32.479837894 MEZ | 8.8.8.8 | 192.168.0.53 | 0xaac4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | |
Jan 16, 2018 10:38:32.683762074 MEZ | 8.8.8.8 | 192.168.0.53 | 0x6a12 | Name error (3) | none | none | 28 | IN (0x0001) | |
Jan 16, 2018 10:38:36.481611013 MEZ | 8.8.8.8 | 192.168.0.53 | 0x23d3 | No error (0) | 104.31.80.139 | A (IP address) | IN (0x0001) | ||
Jan 16, 2018 10:38:42.070797920 MEZ | 82.163.143.135 | 192.168.0.53 | 0xe0b0 | No error (0) | 104.28.13.190 | A (IP address) | IN (0x0001) | ||
Jan 16, 2018 10:38:43.570421934 MEZ | 82.163.143.135 | 192.168.0.53 | 0x5f26 | No error (0) | 104.27.134.218 | A (IP address) | IN (0x0001) |
HTTP Request Dependency Graph |
---|
|
HTTP Packets |
---|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.0.53 | 49196 | 104.31.80.139 | 80 |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jan 16, 2018 10:38:36.485268116 MEZ | 17 | OUT | |
Jan 16, 2018 10:38:36.485536098 MEZ | 19 | OUT | |
Jan 16, 2018 10:38:37.335010052 MEZ | 21 | IN |