Analysis Report
Overview
General Information |
|---|
| Joe Sandbox Version: | 21.0.0 |
| Analysis ID: | 48021 |
| Start time: | 10:37:03 |
| Joe Sandbox Product: | Cloud |
| Start date: | 16.01.2018 |
| Overall analysis duration: | 0h 9m 31s |
| Hypervisor based Inspection enabled: | false |
| Report type: | full |
| Sample file name: | MaMi |
| Cookbook file name: | defaultmacfilecookbook.jbs |
| Analysis system description: | Virtual Machine, El Capitan 10.11.6 (MS Office 15.34, Java 1.8.0_131) |
| Detection: | MAL |
| Classification: | mal80.troj.spyw.evad.mac@0/43@5/0 |
Detection |
|---|
| Strategy | Score | Range | Reporting | Detection | |
|---|---|---|---|---|---|
| Threshold | 80 | 0 - 100 | Report FP / FN | ||
Classification |
|---|
Signature Overview |
|---|
Click to jump to signature section
Cryptography: |
|---|
| Imports (root) certificates into the systems keychain typically to intercept SSL traffic or bypass code integrity protections | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Certificate import: | ||
| Writes DER encoded certificate files to disk without the typical file extension | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | DER file created: | ||
Networking: |
|---|
| Downloads files from webservers via HTTP | Show sources | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Performs DNS lookups | Show sources | ||
| Source: unknown | DNS traffic detected: | ||
| Posts data to webserver | Show sources | ||
| Source: unknown | HTTP traffic detected: | ||
| Reads from file descriptors related to (network) sockets | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Reads from socket in process: | ||
| Urls found in memory or binary data | Show sources | ||
| Source: MaMi | String found in binary or memory: | ||
| Source: MaMi | String found in binary or memory: | ||
| Source: MaMi | String found in binary or memory: | ||
| Uses HTTPS | Show sources | ||
| Source: unknown | Network traffic detected: | ||
| Source: unknown | Network traffic detected: | ||
| Source: unknown | Network traffic detected: | ||
| Source: unknown | Network traffic detected: | ||
| Source: unknown | Network traffic detected: | ||
| Source: unknown | Network traffic detected: | ||
| Source: unknown | Network traffic detected: | ||
| Source: unknown | Network traffic detected: | ||
| Writes from file descriptors related to (network) sockets | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Writes from socket in process: | ||
| Executes the "networksetup" command used to configure network settings | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup executable: | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup executable: | ||
| Explicitly retrieves the order of network devices used for connecting to the network | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup with list network services order args: | ||
| Explicitly retrieves the configured DNS servers | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Networksetup with get DNS servers args: | ||
System Summary: |
|---|
| Classification label | Show sources | ||
| Source: classification engine | Classification label: | ||
Data Obfuscation: |
|---|
| Imports the IOKit library (often used to register services) | Show sources | ||
| Source: initial sample | Static MACH information: | ||
Persistence and Installation Behavior: |
|---|
| Executes the "awk" command used to scan for patterns (typically in standard output) | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Awk executable: | ||
| Reads data from the local random generator | Show sources | ||
| Source: /usr/libexec/diskmanagementd (PID: 509) | Random device file read: | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Random device file read: | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Random device file read: | ||
| Source: /usr/bin/security (PID: 598) | Random device file read: | ||
| Uses AppleKeyboardLayouts bundle containing keyboard layouts | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | AppleKeyboardLayouts info plist opened: | ||
| Writes property list (.plist) files to disk | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | XML plist file created: | ||
| Source: /bin/cp (PID: 518) | XML plist file created: | ||
| Source: /bin/cp (PID: 520) | XML plist file created: | ||
| Source: /bin/cp (PID: 524) | XML plist file created: | ||
| Source: /bin/cp (PID: 526) | XML plist file created: | ||
| Source: /bin/cp (PID: 537) | XML plist file created: | ||
| Source: /bin/cp (PID: 539) | XML plist file created: | ||
| Source: /bin/cp (PID: 543) | XML plist file created: | ||
| Source: /bin/cp (PID: 545) | XML plist file created: | ||
| Source: /bin/cp (PID: 549) | XML plist file created: | ||
| Source: /bin/cp (PID: 551) | XML plist file created: | ||
| Source: /bin/cp (PID: 555) | XML plist file created: | ||
| Source: /bin/cp (PID: 557) | XML plist file created: | ||
| Source: /bin/cp (PID: 561) | XML plist file created: | ||
| Source: /bin/cp (PID: 563) | XML plist file created: | ||
| Source: /bin/cp (PID: 567) | XML plist file created: | ||
| Source: /bin/cp (PID: 569) | XML plist file created: | ||
| Source: /bin/cp (PID: 573) | XML plist file created: | ||
| Source: /bin/cp (PID: 575) | XML plist file created: | ||
| Source: /bin/cp (PID: 579) | XML plist file created: | ||
| Source: /bin/cp (PID: 581) | XML plist file created: | ||
| Source: /bin/cp (PID: 585) | XML plist file created: | ||
| Source: /bin/cp (PID: 587) | XML plist file created: | ||
| Source: /bin/cp (PID: 595) | XML plist file created: | ||
| Source: /bin/cp (PID: 597) | XML plist file created: | ||
| Source: /bin/cp (PID: 603) | XML plist file created: | ||
| Source: /bin/cp (PID: 605) | XML plist file created: | ||
| Source: /bin/cp (PID: 609) | XML plist file created: | ||
| Source: /bin/cp (PID: 611) | XML plist file created: | ||
| Source: /bin/cp (PID: 615) | XML plist file created: | ||
| Source: /bin/cp (PID: 617) | XML plist file created: | ||
| Source: /bin/cp (PID: 621) | XML plist file created: | ||
| Source: /bin/cp (PID: 623) | XML plist file created: | ||
| Source: /bin/cp (PID: 627) | XML plist file created: | ||
| Source: /bin/cp (PID: 629) | XML plist file created: | ||
| Source: /bin/cp (PID: 633) | XML plist file created: | ||
| Source: /bin/cp (PID: 635) | XML plist file created: | ||
| Creates hidden files, links and/or directories | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Hidden file created: | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Hidden file created: | ||
| Executes commands using a shell command-line interpreter | Show sources | ||
| Source: /usr/sbin/networksetup (PID: 517) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 519) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 523) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 525) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 536) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 538) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 542) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 544) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 548) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 550) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 554) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 556) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 560) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 562) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 566) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 568) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 572) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 574) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 578) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 580) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 584) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 586) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 594) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 596) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 602) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 604) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 608) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 610) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 614) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 616) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 620) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 622) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 626) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 628) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 632) | Shell command executed: | ||
| Source: /usr/sbin/networksetup (PID: 634) | Shell command executed: | ||
| Executes the "scutil" command used to manage network related system configuration parameters | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Scutil executable: | ||
| Many shell processes execute programs via execve syscall (may be indicative for malicious behavior) | Show sources | ||
| Source: /bin/sh (PID: 518) | Shell process: | ||
| Source: /bin/sh (PID: 520) | Shell process: | ||
| Source: /bin/sh (PID: 524) | Shell process: | ||
| Source: /bin/sh (PID: 526) | Shell process: | ||
| Source: /bin/sh (PID: 537) | Shell process: | ||
| Source: /bin/sh (PID: 539) | Shell process: | ||
| Source: /bin/sh (PID: 543) | Shell process: | ||
| Source: /bin/sh (PID: 545) | Shell process: | ||
| Source: /bin/sh (PID: 549) | Shell process: | ||
| Source: /bin/sh (PID: 551) | Shell process: | ||
| Source: /bin/sh (PID: 555) | Shell process: | ||
| Source: /bin/sh (PID: 557) | Shell process: | ||
| Source: /bin/sh (PID: 561) | Shell process: | ||
| Source: /bin/sh (PID: 563) | Shell process: | ||
| Source: /bin/sh (PID: 567) | Shell process: | ||
| Source: /bin/sh (PID: 569) | Shell process: | ||
| Source: /bin/sh (PID: 573) | Shell process: | ||
| Source: /bin/sh (PID: 575) | Shell process: | ||
| Source: /bin/sh (PID: 579) | Shell process: | ||
| Source: /bin/sh (PID: 581) | Shell process: | ||
| Source: /bin/sh (PID: 585) | Shell process: | ||
| Source: /bin/sh (PID: 587) | Shell process: | ||
| Source: /bin/sh (PID: 595) | Shell process: | ||
| Source: /bin/sh (PID: 597) | Shell process: | ||
| Source: /bin/sh (PID: 603) | Shell process: | ||
| Source: /bin/sh (PID: 605) | Shell process: | ||
| Source: /bin/sh (PID: 609) | Shell process: | ||
| Source: /bin/sh (PID: 611) | Shell process: | ||
| Source: /bin/sh (PID: 615) | Shell process: | ||
| Source: /bin/sh (PID: 617) | Shell process: | ||
| Source: /bin/sh (PID: 621) | Shell process: | ||
| Source: /bin/sh (PID: 623) | Shell process: | ||
| Source: /bin/sh (PID: 627) | Shell process: | ||
| Source: /bin/sh (PID: 629) | Shell process: | ||
| Source: /bin/sh (PID: 633) | Shell process: | ||
| Source: /bin/sh (PID: 635) | Shell process: | ||
| Samples exit code indicates no error despite standard error output | Show sources | ||
| Source: submitted sample | Stderr: 2018-01-16 11:38:38.416 MaMi[513:4712] chmodding parent /var/root/Library/Cookies with perm 700: | ||
| Writes DER encoded certificate files to disk without the typical file extension | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | DER file created: | ||
Hooking and other Techniques for Hiding and Protection: |
|---|
| Moves itself during installation or deletes itself after installation | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | File deleted: | ||
Language, Device and Operating System Detection: |
|---|
| Reads the system or server version plist file | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | System or server version plist file read: | ||
| Reads the systems hostname | Show sources | ||
| Source: /bin/sh (PID: 518) | Sysctl requested: | ||
| Source: /bin/sh (PID: 520) | Sysctl requested: | ||
| Source: /bin/sh (PID: 524) | Sysctl requested: | ||
| Source: /bin/sh (PID: 526) | Sysctl requested: | ||
| Source: /bin/sh (PID: 537) | Sysctl requested: | ||
| Source: /bin/sh (PID: 539) | Sysctl requested: | ||
| Source: /bin/sh (PID: 543) | Sysctl requested: | ||
| Source: /bin/sh (PID: 545) | Sysctl requested: | ||
| Source: /bin/sh (PID: 549) | Sysctl requested: | ||
| Source: /bin/sh (PID: 551) | Sysctl requested: | ||
| Source: /bin/sh (PID: 555) | Sysctl requested: | ||
| Source: /bin/sh (PID: 557) | Sysctl requested: | ||
| Source: /bin/sh (PID: 561) | Sysctl requested: | ||
| Source: /bin/sh (PID: 563) | Sysctl requested: | ||
| Source: /bin/sh (PID: 567) | Sysctl requested: | ||
| Source: /bin/sh (PID: 569) | Sysctl requested: | ||
| Source: /bin/sh (PID: 573) | Sysctl requested: | ||
| Source: /bin/sh (PID: 575) | Sysctl requested: | ||
| Source: /bin/sh (PID: 579) | Sysctl requested: | ||
| Source: /bin/sh (PID: 581) | Sysctl requested: | ||
| Source: /bin/sh (PID: 585) | Sysctl requested: | ||
| Source: /bin/sh (PID: 587) | Sysctl requested: | ||
| Source: /bin/sh (PID: 595) | Sysctl requested: | ||
| Source: /bin/sh (PID: 597) | Sysctl requested: | ||
| Source: /bin/sh (PID: 603) | Sysctl requested: | ||
| Source: /bin/sh (PID: 605) | Sysctl requested: | ||
| Source: /bin/sh (PID: 609) | Sysctl requested: | ||
| Source: /bin/sh (PID: 611) | Sysctl requested: | ||
| Source: /bin/sh (PID: 615) | Sysctl requested: | ||
| Source: /bin/sh (PID: 617) | Sysctl requested: | ||
| Source: /bin/sh (PID: 621) | Sysctl requested: | ||
| Source: /bin/sh (PID: 623) | Sysctl requested: | ||
| Source: /bin/sh (PID: 627) | Sysctl requested: | ||
| Source: /bin/sh (PID: 629) | Sysctl requested: | ||
| Source: /bin/sh (PID: 633) | Sysctl requested: | ||
| Source: /bin/sh (PID: 635) | Sysctl requested: | ||
| Executes the "ioreg" command used to gather hardware information (I/O kit registry) | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | IOreg executable: | ||
| Queries the unique Apple serial number of the machine | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | IOPlatformSerialNumber keyword found in command: | ||
Stealing of Sensitive Information: |
|---|
| Executes the "security" command used to access the keychain | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Security executable: | ||
| Imports (root) certificates into the systems keychain typically to intercept SSL traffic or bypass code integrity protections | Show sources | ||
| Source: /Users/luke/Desktop/MaMi (PID: 513) | Certificate import: | ||
Runtime Messages |
|---|
| Command: | /Users/luke/Desktop/MaMi |
| Exitcode: | 0 |
| Killed: | False |
| Standard Output: | |
| Standard Error: | 2018-01-16 11:38:38.416 MaMi[513:4712] chmodding parent /var/root/Library/Cookies with perm 700 |
Behavior Graph |
|---|
Yara Overview |
|---|
Initial Sample |
|---|
| No yara matches |
|---|
PCAP (Network Traffic) |
|---|
| No yara matches |
|---|
Dropped Files |
|---|
| No yara matches |
|---|
Memory Dumps |
|---|
| No yara matches |
|---|
Unpacked PEs |
|---|
| No yara matches |
|---|
Antivirus Detection |
|---|
Screenshot |
|---|
Startup |
|---|
|
Created / dropped Files |
|---|
| File Type: | |
| Size (bytes): | 33696 |
| Entropy (8bit): | 4.249455295583855 |
| Encrypted: | false |
| MD5: | 9DD3851D5FB343992F7DB778C97C56A4 |
| SHA1: | 7FFCAD715CB343B468C24B3271950B4938FC72F7 |
| SHA-256: | 882B665925BE90D45ACCAED36325B31DB0BCB0D3074F14DC22D283A552C590B6 |
| SHA-512: | 8528848DD41D36E89FDD093A28F05307CF6D983A5B893D8DF2451A08AC1EC3ECC5E136962AEC8F7C676C399712D6F421E6D3AFBF9884E5C8731440E91FB177F5 |
| Malicious: | false |
| Reputation: | low |
| File Type: | |
| Size (bytes): | 12 |
| Entropy (8bit): | 2.0 |
| Encrypted: | false |
| MD5: | 08275E96591EEA52C64B0866004B02D3 |
| SHA1: | B5DC7150EC53B6B802A64DFF4E65149DBDECD2CE |
| SHA-256: | 959402A34FAB43E548CB7F1A4CBF53E341A3D536846A58E943C922ABE2FBC148 |
| SHA-512: | BAAE4EEC184623B23109463FAF4F86409B74C8DC701A1A278A9141D9F44CF16731F51D14B581F1EF723B024BFB36672860FD8C59603456D7EA2945977463BF20 |
| Malicious: | false |
| Reputation: | low |
| File Type: | |
| Size (bytes): | 4594 |
| Entropy (8bit): | 4.922151867635323 |
| Encrypted: | false |
| MD5: | D29D035A55239D6A77A94EECD344313C |
| SHA1: | 5C73FA173533B38F245B76B393ADBD4791EBBC84 |
| SHA-256: | 8838003894E4583853CEBCAB515338E0DB708AE15440B47BF5FAE254C80D0C14 |
| SHA-512: | 5F71B81D161E574DA1729A9E52262CD4C841B7E9CD395459220BACF149EA17067AAFD059A9A961C4B538678B2B3613A5BB5413E28DF7800CF3E05FDF745B45B5 |
| Malicious: | false |
| Reputation: | low |
| File Type: | |
| Size (bytes): | 4594 |
| Entropy (8bit): | 4.922151867635323 |
| Encrypted: | false |
| MD5: | D29D035A55239D6A77A94EECD344313C |
| SHA1: | 5C73FA173533B38F245B76B393ADBD4791EBBC84 |
| SHA-256: | 8838003894E4583853CEBCAB515338E0DB708AE15440B47BF5FAE254C80D0C14 |
| SHA-512: | 5F71B81D161E574DA1729A9E52262CD4C841B7E9CD395459220BACF149EA17067AAFD059A9A961C4B538678B2B3613A5BB5413E28DF7800CF3E05FDF745B45B5 |
| Malicious: | true |
| Reputation: | low |
| File Type: | |
| Size (bytes): | 1021 |
| Entropy (8bit): | 7.295459366431303 |
| Encrypted: | false |
| MD5: | 5FBB11485CD05D8986488D11EB22FEDD |
| SHA1: | 26D9E607FFF0C58C7844B47FF8B6E079E5A2220E |
| SHA-256: | C17861B640492388D50FF5DAC282ED502AEC9AD1AA4AA07DD977FA9AB2567C30 |
| SHA-512: | 99FFC26EBAACEC0155AA99FC6814CF0A7F1394DDA8B1796ED998F7B3B87472E512097ED7BBA1A834DDA1A73E90D17A76B0120F9C51AA7332265A98EF9C193713 |
| Malicious: | true |
| Reputation: | low |
| File Type: | |
| Size (bytes): | 100 |
| Entropy (8bit): | 5.6063701301561855 |
| Encrypted: | false |
| MD5: | FB86CDB211DF8ED5E11672C7E3479249 |
| SHA1: | B80C1DD0DF541674FD3B76906B52DF79E3553B62 |
| SHA-256: | 3BB51CC3D4ECD1E24C22AE17C635726A3875AAE5CDE4B125520D8E72633BF1B1 |
| SHA-512: | C473726F516939295536F7BE1E6172D0487C063B20862E5C8AEBF6ED6101CC6DD86285C8C003D78A6DFA1E69F9FFF1DFDC5BDB1AA7DE85B772C5A5F6AD977EDB |
| Malicious: | false |
| Reputation: | low |
| File Type: | |
| Size (bytes): | 29 |
| Entropy (8bit): | 4.306256857196538 |
| Encrypted: | false |
| MD5: | 5BB01FE1F6043852CD6138586BC463D7 |
| SHA1: | 2E2514514532E95DE6DD638C0C490E264801E658 |
| SHA-256: | 70780754EA748E33B105EB1FCA355B25777D4296A46D8CBC8C8B73FA7724DBA6 |
| SHA-512: | DB87579A98F4DF6F2A94F5318E51CD6F2634FAF307DEF7E2B98435F8D4F7D32157C452C6332E4E3BACEE4CF041101DE8AEC24B2915B9021CCF7D1E746618DBAF |
| Malicious: | false |
| Reputation: | low |
| File Type: | |
| Size (bytes): | 777 |
| Entropy (8bit): | 4.420222670133278 |
| Encrypted: | false |
| MD5: | BBE2E55DE6FE2A888EE4AEA9E5325A4D |
| SHA1: | 8A16748B5F1B3316C26781966714B6F57360B735 |
| SHA-256: | D5DB52D3BBFA3D7EAB97CE2496D2BE26C6F8A80A76DAFE8EAD0B732ACE722735 |
| SHA-512: | 423561D0BDE495F384AF06976D01BFC5E30A6180A38CA0A117F27E8FEF91B6625AEFBF25372D58426192610ECE1D2AB38E232521A1FDD10E6902B1CFF5232208 |
| Malicious: | false |
| Reputation: | low |
Contacted Domains/Contacted IPs |
|---|
Contacted Domains |
|---|
| Name | IP | Active | Malicious | Antivirus Detection |
|---|---|---|---|---|
| squartera.info | 104.31.80.139 | true | false | |
| gorensin.info | 104.27.134.218 | true | false | |
| honouncil.info | 104.28.13.190 | true | false |
Contacted IPs |
|---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
| IP | Country | Flag | ASN | ASN Name | Malicious |
|---|---|---|---|---|---|
| 104.28.13.190 | United States | 13335 | CLOUDFLARENET-CloudFlareIncUS | false | |
| 23.45.113.221 | United States | 20940 | AKAMAI-ASN1US | false | |
| 82.163.142.137 | United Kingdom | 204078 | GREENTEAMIL | false | |
| 23.45.112.74 | United States | 20940 | AKAMAI-ASN1US | false | |
| 72.21.91.29 | United States | 15133 | EDGECAST-MCICommunicationsServicesIncdbaVerizonB | false | |
| 8.8.8.8 | United States | 15169 | GOOGLE-GoogleIncUS | false | |
| 104.27.134.218 | United States | 13335 | CLOUDFLARENET-CloudFlareIncUS | false | |
| 82.163.143.135 | United Kingdom | 204078 | GREENTEAMIL | false | |
| 104.31.80.139 | United States | 13335 | CLOUDFLARENET-CloudFlareIncUS | false | |
| 17.253.54.125 | United States | 6185 | APPLE-AUSTIN-AppleIncUS | false |
Static File Info |
|---|
General | |
|---|---|
| File type: | |
| Entropy (8bit): | 6.047403534655477 |
| TrID: |
|
| File name: | MaMi |
| File size: | 565673 |
| MD5: | 6e6034c13cb949156888513211b1f1ef |
| SHA1: | f596b8ae209a1600a33a230e9904472b6d4ba1c0 |
| SHA256: | 5586be30d505216bdc912605481f9c8c7bfd52748f66c5e212160f6b31fd8571 |
| SHA512: | 5e67267e14cd1fa694c00ff4d7c854407888bfff11a54e3e63006fe332933ead3584efc2b584a95976c91785c0027fd2f4a936fa48984a381cef567b1a9d0b17 |
| File Content Preview: | ....................P.....!.........H...__PAGEZERO..............................................................__TEXT................... ............... ......................__text..........__TEXT...................@..................................... |
Static Mach Info |
|---|
General Informations for header0 | |
|---|---|
| Endian: | |
| Size: | |
| Architecture: | |
| Filetype: | |
| Nbr. of load commands: | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __PAGEZERO | |
| fileoff | 0 | |
| maxprot | 0 | |
| vmsize | 4294967296 | |
| nsects | 0 | |
| flags | 0 | |
| filesize | 0 | |
| vmaddr | 0 | |
| initprot | 0 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __TEXT | |
| fileoff | 0 | |
| maxprot | 7 | |
| vmsize | 335872 | |
| nsects | 11 | |
| flags | 0 | |
| filesize | 335872 | |
| vmaddr | 4294967296 | |
| initprot | 5 | |
| Datas | sectname | __text |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4294973824 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 2147484672 | |
| offset | 6528 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 213122 | |
| sectname | __stubs | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295186946 | |
| align | 1 | |
| nreloc | 0 | |
| flags | 2147484680 | |
| offset | 219650 | |
| reserved2 | 6 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1344 | |
| sectname | __stub_helper | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295188292 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 2147484672 | |
| offset | 220996 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 2216 | |
| sectname | __const | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295190512 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 223216 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1176 | |
| sectname | __gcc_except_tab | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295191688 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 224392 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 5364 | |
| sectname | __cstring | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295197056 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 229760 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 25864 | |
| sectname | __objc_methname | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295222920 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 255624 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 24247 | |
| sectname | __objc_classname | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295247167 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 279871 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 509 | |
| sectname | __objc_methtype | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295247676 | |
| align | 0 | |
| nreloc | 0 | |
| flags | 2 | |
| offset | 280380 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 3133 | |
| sectname | __unwind_info | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295250812 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 283516 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 4944 | |
| sectname | __eh_frame | |
| segname | __TEXT | |
| reloff | 0 | |
| addr | 4295255760 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 288464 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 47400 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __DATA | |
| fileoff | 335872 | |
| maxprot | 7 | |
| vmsize | 81920 | |
| nsects | 20 | |
| flags | 0 | |
| filesize | 77824 | |
| vmaddr | 4295303168 | |
| initprot | 3 | |
| Datas | sectname | __nl_symbol_ptr |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295303168 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 6 | |
| offset | 335872 | |
| reserved2 | 0 | |
| reserved1 | 224 | |
| reserved3 | 0 | |
| size | 16 | |
| sectname | __got | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295303184 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 6 | |
| offset | 335888 | |
| reserved2 | 0 | |
| reserved1 | 226 | |
| reserved3 | 0 | |
| size | 800 | |
| sectname | __la_symbol_ptr | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295303984 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 7 | |
| offset | 336688 | |
| reserved2 | 0 | |
| reserved1 | 326 | |
| reserved3 | 0 | |
| size | 1792 | |
| sectname | __const | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295305776 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 338480 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 592 | |
| sectname | __cfstring | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295306368 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 339072 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 19520 | |
| sectname | __objc_classlist | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295325888 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 358592 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 176 | |
| sectname | __objc_nlclslist | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295326064 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 358768 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8 | |
| sectname | __objc_catlist | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295326072 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 358776 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 16 | |
| sectname | __objc_protolist | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295326088 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 358792 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 64 | |
| sectname | __objc_imageinfo | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295326152 | |
| align | 2 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 358856 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 8 | |
| sectname | __objc_const | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295326160 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 358864 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 36840 | |
| sectname | __objc_selrefs | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295363000 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435461 | |
| offset | 395704 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 7472 | |
| sectname | __objc_protorefs | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295370472 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 403176 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 16 | |
| sectname | __objc_classrefs | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295370488 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 403192 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 592 | |
| sectname | __objc_superrefs | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295371080 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 268435456 | |
| offset | 403784 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 144 | |
| sectname | __objc_ivar | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295371224 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 403928 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1544 | |
| sectname | __objc_data | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295372768 | |
| align | 3 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 405472 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 1840 | |
| sectname | __data | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295374608 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 0 | |
| offset | 407312 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 3232 | |
| sectname | __bss | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295377840 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 1 | |
| offset | 0 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 5056 | |
| sectname | __common | |
| segname | __DATA | |
| reloff | 0 | |
| addr | 4295382896 | |
| align | 4 | |
| nreloc | 0 | |
| flags | 1 | |
| offset | 0 | |
| reserved2 | 0 | |
| reserved1 | 0 | |
| reserved3 | 0 | |
| size | 273 | |
segment_command_64 |
|---|
| Name | Value | |
|---|---|---|
| segname | __LINKEDIT | |
| fileoff | 413696 | |
| maxprot | 7 | |
| vmsize | 151552 | |
| nsects | 0 | |
| flags | 0 | |
| filesize | 149624 | |
| vmaddr | 4295385088 | |
| initprot | 1 | |
dyld_info_command |
|---|
| Name | Value | |
|---|---|---|
| lazy_bind_size | 7240 | |
| lazy_bind_off | 421768 | |
| weak_bind_size | 1496 | |
| rebase_size | 1264 | |
| export_off | 429008 | |
| export_size | 8160 | |
| bind_off | 414960 | |
| rebase_off | 413696 | |
| bind_size | 5312 | |
| weak_bind_off | 420272 | |
symtab_command |
|---|
| Name | Value | |
|---|---|---|
| strsize | 87504 | |
| symoff | 438672 | |
| stroff | 475816 | |
| nsyms | 2184 | |
dysymtab_command |
|---|
| Name | Value | |
|---|---|---|
| extreloff | 0 | |
| nlocrel | 0 | |
| indirectsymoff | 473616 | |
| modtaboff | 0 | |
| nextrel | 0 | |
| iundefsym | 1807 | |
| nmodtab | 0 | |
| ilocalsym | 0 | |
| nundefsym | 377 | |
| nextrefsyms | 0 | |
| locreloff | 0 | |
| ntoc | 0 | |
| nlocalsym | 1514 | |
| tocoff | 0 | |
| extrefsymoff | 0 | |
| nindirectsyms | 550 | |
| iextdefsym | 1514 | |
| nextdefsym | 293 | |
dylinker_command |
|---|
| Name | Value | |
|---|---|---|
| name | 12 | Data | /usr/lib/dyld |
uuid_command |
|---|
| Name | Value | |
|---|---|---|
| uuid | 300aca14e34b3e2d88eb0c2db0ed159c | |
version_min_command |
|---|
| Name | Value | |
|---|---|---|
| version | 657408 | |
| reserved | 658432 | |
source_version_command |
|---|
| Name | Value | |
|---|---|---|
| version | 0 | |
entry_point_command |
|---|
| Name | Value | |
|---|---|---|
| stacksize | 0 | |
| entryoff | 19417 | |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 1280.51.1 | Data | /usr/lib/libc++.1.dylib |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 520.1.0 | Data | /usr/lib/libz.1.dylib |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.44.1 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 16128.69.5 | Data | /System/Library/Frameworks/Foundation.framework/Versions/C/Foundation |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 0.228.0 | Data | /usr/lib/libobjc.A.dylib |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 12802.214.4 | Data | /usr/lib/libSystem.B.dylib |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.45.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 21096.224.5 | Data | /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 0.48.0 | Data | /System/Library/Frameworks/ApplicationServices.framework/Versions/A/ApplicationServices |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 1042.43.3 | Data | /System/Library/Frameworks/CFNetwork.framework/Versions/A/CFNetwork |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.150.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 16384.69.5 | Data | /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.64.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 5632.46.4 | Data | /System/Library/Frameworks/CoreGraphics.framework/Versions/A/CoreGraphics |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 4864.7.3 | Data | /System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 0.19.1 | Data | /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit |
dylib_command |
|---|
| Name | Value | |
|---|---|---|
| compatibility_version | 0.1.0 | |
| timestamp | Thu Jan 01 01:00:02 1970 | |
| name | 24 | |
| current_version | 13057.120.3 | Data | /System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfiguration |
linkedit_data_command |
|---|
| Name | Value | |
|---|---|---|
| dataoff | 437168 | |
| datassize | 1496 | |
linkedit_data_command |
|---|
| Name | Value | |
|---|---|---|
| dataoff | 438664 | |
| datassize | 8 | |
Network Behavior |
|---|
Network Port Distribution |
|---|
TCP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Jan 16, 2018 10:38:28.495457888 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:28.495830059 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.512610912 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.512631893 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:28.517251015 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.517293930 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:28.517833948 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.529958963 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.529979944 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:28.702174902 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.702208996 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:28.702867031 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.704881907 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:28.704902887 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.135426044 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.135977983 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.392107964 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.392664909 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.453325987 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.453691006 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.465013027 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.465497971 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.479163885 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.479202032 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.479254961 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.479266882 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.479273081 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.479284048 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.489674091 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.490376949 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.504399061 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.504420996 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.504453897 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.504462004 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:29.504484892 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:29.504492998 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.187161922 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.187697887 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:30.188889980 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:30.188913107 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.210139036 MEZ | 57875 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:30.257009029 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.257494926 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:30.258661032 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:30.258682013 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.612297058 MEZ | 53 | 57875 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.730536938 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:30.730557919 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.800291061 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:30.800935030 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:31.316409111 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:31.316910028 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:31.327824116 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:31.328321934 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:32.109383106 MEZ | 56351 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:32.109441996 MEZ | 53 | 56351 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:32.115458965 MEZ | 53017 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:32.115931034 MEZ | 63638 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:32.479837894 MEZ | 53 | 53017 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:32.683762074 MEZ | 53 | 63638 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:32.906513929 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:32.906542063 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:33.300405979 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:33.300728083 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:33.324394941 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
| Jan 16, 2018 10:38:33.936409950 MEZ | 80 | 49190 | 72.21.91.29 | 192.168.0.53 |
| Jan 16, 2018 10:38:33.936995983 MEZ | 49190 | 80 | 192.168.0.53 | 72.21.91.29 |
| Jan 16, 2018 10:38:35.064308882 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:35.064333916 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:35.712307930 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:35.712666988 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:35.750128984 MEZ | 56806 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:36.481611013 MEZ | 53 | 56806 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:36.482770920 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:36.482812881 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:36.483573914 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:36.485268116 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:36.485285997 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:36.485536098 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:36.485548973 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.105518103 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:37.105540037 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.335010052 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.335021019 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.335489988 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:37.360729933 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:37.360810995 MEZ | 80 | 49196 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.361323118 MEZ | 49196 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:37.363715887 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:37.363763094 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.364335060 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:37.366035938 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:37.366056919 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.366321087 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:37.366333961 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.854811907 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:37.855370045 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:38.219822884 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:38.219834089 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:38.220417976 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:38.221458912 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:38.221518993 MEZ | 80 | 49197 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:38.222062111 MEZ | 49197 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:38.224977970 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:38.225011110 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:38.225564957 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:38.227031946 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:38.227047920 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:38.227294922 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:38.227308035 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.037847042 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.037861109 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.038592100 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:39.231729984 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:39.231755018 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.257999897 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.258507967 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:39.259450912 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:39.259516001 MEZ | 80 | 49198 | 104.31.80.139 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.260143995 MEZ | 49198 | 80 | 192.168.0.53 | 104.31.80.139 |
| Jan 16, 2018 10:38:39.596726894 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:39.596867085 MEZ | 53 | 65226 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.597529888 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.142.137 |
| Jan 16, 2018 10:38:39.597626925 MEZ | 53 | 65226 | 82.163.142.137 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.597929001 MEZ | 50111 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:39.597970009 MEZ | 53 | 50111 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:40.078402996 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:40.078896999 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:40.114228010 MEZ | 57717 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.116482019 MEZ | 62127 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.118319988 MEZ | 50145 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.121865034 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.548860073 MEZ | 62965 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.841768026 MEZ | 53 | 57717 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.007045984 MEZ | 53 | 62127 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.063930988 MEZ | 53 | 50145 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.188694954 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:41.190223932 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.223583937 MEZ | 52922 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:41.347417116 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:41.347440004 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.392683029 MEZ | 53 | 62965 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.926094055 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.070797920 MEZ | 53 | 52922 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.071732998 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:42.071768999 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.072567940 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:42.074453115 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:42.074471951 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.184029102 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.184545994 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:42.817600012 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.817609072 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.818187952 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:42.872332096 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.872915030 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:42.873908043 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:42.873991966 MEZ | 80 | 49200 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.874522924 MEZ | 49200 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:42.876209021 MEZ | 54507 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:43.459681988 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:43.459707975 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:43.570421934 MEZ | 53 | 54507 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:43.571280956 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
| Jan 16, 2018 10:38:43.571336031 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
| Jan 16, 2018 10:38:43.571891069 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
| Jan 16, 2018 10:38:43.573754072 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
| Jan 16, 2018 10:38:43.573772907 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
| Jan 16, 2018 10:38:44.338212967 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
| Jan 16, 2018 10:38:44.338227987 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
| Jan 16, 2018 10:38:44.338785887 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
| Jan 16, 2018 10:38:44.340049982 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
| Jan 16, 2018 10:38:44.340171099 MEZ | 80 | 49201 | 104.27.134.218 | 192.168.0.53 |
| Jan 16, 2018 10:38:44.340754986 MEZ | 49201 | 80 | 192.168.0.53 | 104.27.134.218 |
| Jan 16, 2018 10:38:44.342609882 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:44.342668056 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:44.343724966 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:44.345383883 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:44.345405102 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:44.477978945 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:44.478610992 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:45.302794933 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:45.302805901 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:45.303338051 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:45.305030107 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:45.305094004 MEZ | 80 | 49202 | 104.28.13.190 | 192.168.0.53 |
| Jan 16, 2018 10:38:45.305697918 MEZ | 49202 | 80 | 192.168.0.53 | 104.28.13.190 |
| Jan 16, 2018 10:38:45.572709084 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:45.572732925 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:46.344804049 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:46.345326900 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:47.705620050 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:47.705643892 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:48.352015972 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:48.352549076 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:49.808871031 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:49.808897018 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:50.313086033 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:50.313602924 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:51.901590109 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:51.901609898 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:52.355698109 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:52.356184006 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:53.693825006 MEZ | 49190 | 80 | 192.168.0.53 | 72.21.91.29 |
| Jan 16, 2018 10:38:53.693854094 MEZ | 80 | 49190 | 72.21.91.29 | 192.168.0.53 |
| Jan 16, 2018 10:38:54.005795956 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:54.005820990 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:54.563170910 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:54.563838005 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:56.108951092 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:56.108979940 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:56.583056927 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:56.583508968 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:56.854804993 MEZ | 49184 | 443 | 192.168.0.53 | 23.45.112.74 |
| Jan 16, 2018 10:38:56.854892015 MEZ | 443 | 49184 | 23.45.112.74 | 192.168.0.53 |
| Jan 16, 2018 10:38:56.855150938 MEZ | 49184 | 443 | 192.168.0.53 | 23.45.112.74 |
| Jan 16, 2018 10:38:58.194991112 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:38:58.195014000 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:58.667030096 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:38:58.667691946 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:00.343030930 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:00.343055010 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:00.784032106 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:00.784590960 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:02.449940920 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:02.449966908 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:02.963887930 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:02.964428902 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:04.599488974 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:04.599519014 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:05.091592073 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:05.092231989 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:06.745258093 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:06.745282888 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:07.165596962 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:07.166117907 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:08.828758955 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:08.828780890 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:09.316236019 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:09.316829920 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:11.047348976 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:11.047378063 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:11.504631042 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:11.505038023 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:13.147633076 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:13.147654057 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:13.604799986 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:13.605537891 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:15.283921957 MEZ | 52805 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:39:15.309907913 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:15.309931993 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:15.659476995 MEZ | 53 | 52805 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:39:15.743515968 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:15.744064093 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:17.469773054 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:17.469801903 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:17.878190041 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:17.878729105 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:19.549875021 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:19.549900055 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:20.077354908 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:20.077850103 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:21.636038065 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:21.636063099 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:22.094731092 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:22.095200062 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:23.752785921 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:23.752808094 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:24.221636057 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:24.222160101 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:25.789092064 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:25.789118052 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:26.447158098 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:26.447531939 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:27.862070084 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:27.862096071 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:28.288945913 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:28.289412975 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:29.870589972 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:29.870615959 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:30.292367935 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:30.293275118 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:30.494515896 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:30.494605064 MEZ | 443 | 49192 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:30.495016098 MEZ | 49192 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:30.495086908 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:30.495168924 MEZ | 443 | 49191 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:30.495440960 MEZ | 49191 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:31.991152048 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:31.991179943 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:32.551772118 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:32.552283049 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:34.010811090 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:34.010837078 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:34.459500074 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:34.460496902 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:36.102005959 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:36.102027893 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:36.889048100 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:36.889590979 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:38.174233913 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:38.174257040 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:38.850723982 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:38.851217031 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:40.272917986 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:40.272943020 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:41.078850985 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:41.079226971 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:42.375071049 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:42.375092030 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:43.300342083 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:43.300893068 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:43.863850117 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
| Jan 16, 2018 10:39:44.417535067 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:44.417557955 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:45.272310019 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:45.272629023 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:46.501255035 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:46.501281023 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:47.300358057 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:47.300888062 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:49.043034077 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:39:49.043055058 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:49.716077089 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:39:49.716593027 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:40:32.424252987 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
| Jan 16, 2018 10:40:32.424417973 MEZ | 443 | 49189 | 23.45.113.221 | 192.168.0.53 |
| Jan 16, 2018 10:40:32.424876928 MEZ | 49189 | 443 | 192.168.0.53 | 23.45.113.221 |
UDP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Jan 16, 2018 10:38:30.210139036 MEZ | 57875 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:30.612297058 MEZ | 53 | 57875 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:32.109383106 MEZ | 56351 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:32.109441996 MEZ | 53 | 56351 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:32.115458965 MEZ | 53017 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:32.115931034 MEZ | 63638 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:32.479837894 MEZ | 53 | 53017 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:32.683762074 MEZ | 53 | 63638 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:33.324394941 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
| Jan 16, 2018 10:38:35.750128984 MEZ | 56806 | 53 | 192.168.0.53 | 8.8.8.8 |
| Jan 16, 2018 10:38:36.481611013 MEZ | 53 | 56806 | 8.8.8.8 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.596726894 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:39.596867085 MEZ | 53 | 65226 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.597529888 MEZ | 65226 | 53 | 192.168.0.53 | 82.163.142.137 |
| Jan 16, 2018 10:38:39.597626925 MEZ | 53 | 65226 | 82.163.142.137 | 192.168.0.53 |
| Jan 16, 2018 10:38:39.597929001 MEZ | 50111 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:39.597970009 MEZ | 53 | 50111 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:40.114228010 MEZ | 57717 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.116482019 MEZ | 62127 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.118319988 MEZ | 50145 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.121865034 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.548860073 MEZ | 62965 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:40.841768026 MEZ | 53 | 57717 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.007045984 MEZ | 53 | 62127 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.063930988 MEZ | 53 | 50145 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.188694954 MEZ | 59764 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:41.190223932 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.223583937 MEZ | 52922 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:41.392683029 MEZ | 53 | 62965 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:41.926094055 MEZ | 53 | 59764 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.070797920 MEZ | 53 | 52922 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:38:42.876209021 MEZ | 54507 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:38:43.570421934 MEZ | 53 | 54507 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:39:15.283921957 MEZ | 52805 | 53 | 192.168.0.53 | 82.163.143.135 |
| Jan 16, 2018 10:39:15.659476995 MEZ | 53 | 52805 | 82.163.143.135 | 192.168.0.53 |
| Jan 16, 2018 10:39:43.863850117 MEZ | 123 | 123 | 192.168.0.53 | 17.253.54.125 |
ICMP Packets |
|---|
| Timestamp | Source IP | Dest IP | Checksum | Code | Type |
|---|---|---|---|---|---|
| Jan 16, 2018 10:38:32.109935999 MEZ | 192.168.0.53 | 8.8.8.8 | 2089 | (Port unreachable) | Destination Unreachable |
| Jan 16, 2018 10:38:41.926675081 MEZ | 192.168.0.53 | 82.163.143.135 | 130f | (Port unreachable) | Destination Unreachable |
DNS Queries |
|---|
| Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
|---|---|---|---|---|---|---|---|
| Jan 16, 2018 10:38:32.115458965 MEZ | 192.168.0.53 | 8.8.8.8 | 0xaac4 | Standard query (0) | A (IP address) | IN (0x0001) | |
| Jan 16, 2018 10:38:32.115931034 MEZ | 192.168.0.53 | 8.8.8.8 | 0x6a12 | Standard query (0) | 28 | IN (0x0001) | |
| Jan 16, 2018 10:38:35.750128984 MEZ | 192.168.0.53 | 8.8.8.8 | 0x23d3 | Standard query (0) | A (IP address) | IN (0x0001) | |
| Jan 16, 2018 10:38:41.223583937 MEZ | 192.168.0.53 | 82.163.143.135 | 0xe0b0 | Standard query (0) | A (IP address) | IN (0x0001) | |
| Jan 16, 2018 10:38:42.876209021 MEZ | 192.168.0.53 | 82.163.143.135 | 0x5f26 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
|---|
| Timestamp | Source IP | Dest IP | Trans ID | Replay Code | Name | CName | Address | Type | Class |
|---|---|---|---|---|---|---|---|---|---|
| Jan 16, 2018 10:38:32.479837894 MEZ | 8.8.8.8 | 192.168.0.53 | 0xaac4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | |
| Jan 16, 2018 10:38:32.683762074 MEZ | 8.8.8.8 | 192.168.0.53 | 0x6a12 | Name error (3) | none | none | 28 | IN (0x0001) | |
| Jan 16, 2018 10:38:36.481611013 MEZ | 8.8.8.8 | 192.168.0.53 | 0x23d3 | No error (0) | 104.31.80.139 | A (IP address) | IN (0x0001) | ||
| Jan 16, 2018 10:38:42.070797920 MEZ | 82.163.143.135 | 192.168.0.53 | 0xe0b0 | No error (0) | 104.28.13.190 | A (IP address) | IN (0x0001) | ||
| Jan 16, 2018 10:38:43.570421934 MEZ | 82.163.143.135 | 192.168.0.53 | 0x5f26 | No error (0) | 104.27.134.218 | A (IP address) | IN (0x0001) |
HTTP Request Dependency Graph |
|---|
|
HTTP Packets |
|---|
| Session ID | Source IP | Source Port | Destination IP | Destination Port |
|---|---|---|---|---|
| 0 | 192.168.0.53 | 49196 | 104.31.80.139 | 80 |
| Timestamp | kBytes transferred | Direction | Data |
|---|---|---|---|
| Jan 16, 2018 10:38:36.485268116 MEZ | 17 | OUT | |
| Jan 16, 2018 10:38:36.485536098 MEZ | 19 | OUT | |
| Jan 16, 2018 10:38:37.335010052 MEZ | 21 | IN |