1.2
低危

22d415c78befeaf3c999e61884eabc603169a56adacc4d4b96f569815feb424b

22d415c78befeaf3c999e61884eabc603169a56adacc4d4b96f569815feb424b.exe

分析耗时

195s

最近分析

375天前

文件大小

137.8KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN BACKDOOR DELF
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.66
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Trojan-gen 20200514 18.4.3895.0
Baidu Win32.Trojan.Delf.j 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200514 2013.8.14.323
McAfee Exploit-Mydoom 20200514 6.0.6.653
Tencent Trojan.Win32.IRCbot.nrc 20200514 1.0.0.1
行为判定
动态指标
可执行文件使用UPX压缩 (2 个事件)
section UPX0 description 节名称指示UPX
section UPX1 description 节名称指示UPX
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 63 个反病毒引擎识别为恶意 (50 out of 63 个事件)
ALYac Trojan.GenericKD.32159591
APEX Malicious
AVG Win32:Trojan-gen
Acronis suspicious
Ad-Aware Trojan.GenericKD.32159591
AhnLab-V3 Backdoor/Win32.Delf.R238368
Antiy-AVL Trojan[Backdoor]/Win32.Delf
Arcabit Trojan.Generic.D1EAB767
Avast Win32:Trojan-gen
Avira WORM/Rbot.Gen
Baidu Win32.Trojan.Delf.j
BitDefender Trojan.GenericKD.32159591
BitDefenderTheta AI:Packer.1988990019
Bkav W32.AIDetectVM.malware
CAT-QuickHeal Trojan.Dorv.S4530269
CMC Backdoor.Win32.Delf!O
ClamAV Win.Malware.Delf-6717516-0
Comodo Backdoor.Win32.Agent.~AACE@2m6u4
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.c50686
Cylance Unsafe
Cyren W32/Delfloader.B.gen!Eldorado
DrWeb BackDoor.IRC.Sdbot.16412
ESET-NOD32 Win32/IRCBot.NEU
Emsisoft Trojan.GenericKD.32159591 (B)
Endgame malicious (high confidence)
F-Prot W32/Delfloader.B.gen!Eldorado
F-Secure Worm.WORM/Rbot.Gen
FireEye Generic.mg.493aff3c50686a2d
Fortinet W32/Delf.NRF!tr
GData Trojan.GenericKD.32159591
Ikarus P2P-Worm.Win32.Delf
Invincea heuristic
Jiangmin Backdoor/Delf.hxo
K7AntiVirus Trojan ( 7000000f1 )
K7GW Trojan ( 7000000f1 )
Kaspersky Backdoor.Win32.Delf.ars
MAX malware (ai score=87)
Malwarebytes Worm.MyDoom
MaxSecure Trojan.W32.Delf.Ars
McAfee Exploit-Mydoom
MicroWorld-eScan Trojan.GenericKD.32159591
Microsoft Backdoor:Win32/Delf.DU
NANO-Antivirus Trojan.Win32.Delf.dbtjno
Panda Bck/Delf.AAQ
Qihoo-360 Backdoor.Win32.Delf.A
Rising Malware.Heuristic!ET#83% (RDMK:cmRtazo1CHE8aoMSJRaKH3EbHekp)
SUPERAntiSpyware Trojan.Agent/Gen-Delf
Sangfor Malware
SentinelOne DFI - Malicious PE
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:22:17

PE Imphash

aae0990bf8ae1af65a22e31d4163da6c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0000f000 0x0000d400 5.242858506337089
UPX1 0x00010000 0x00006000 0x00005000 3.8094972813627055
.rsrc 0x00016000 0x00001000 0x00000800 3.7640536006953758
.imports 0x00017000 0x00001000 0x00000800 4.29845733461793

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00016154 0x000002e8 LANG_SPANISH SUBLANG_SPANISH_MODERN None
RT_RCDATA 0x00012448 0x000000a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x00012448 0x000000a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x00016440 0x00000014 LANG_SPANISH SUBLANG_SPANISH_MODERN None

Imports

Library KERNEL32.DLL:
0x40e1c0 WriteFile
0x40e1c4 WaitForSingleObject
0x40e1c8 Sleep
0x40e1cc ReadFile
0x40e1d0 LoadLibraryA
0x40e1d8 GetVersionExA
0x40e1dc GetTempPathA
0x40e1e0 GetSystemDirectoryA
0x40e1e4 GetProcAddress
0x40e1e8 GetModuleHandleA
0x40e1ec GetModuleFileNameA
0x40e1f0 GetLastError
0x40e1f4 GetFileAttributesA
0x40e1fc FindNextFileA
0x40e200 FindFirstFileA
0x40e204 FindClose
0x40e210 ExitProcess
0x40e214 DeleteFileA
0x40e218 CreateThread
0x40e21c CreateMutexA
0x40e220 CreateFileA
0x40e224 CreateDirectoryA
0x40e228 CopyFileA
0x40e22c CloseHandle
Library KERNEL32.DLL:
0x40e1a8 TlsSetValue
0x40e1ac TlsGetValue
0x40e1b0 LocalAlloc
0x40e1b4 GetModuleHandleA
Library KERNEL32.DLL:
0x40e100 VirtualFree
0x40e104 VirtualAlloc
0x40e108 LocalFree
0x40e10c LocalAlloc
0x40e110 GetTickCount
0x40e118 GetVersion
0x40e11c GetCurrentThreadId
0x40e120 WideCharToMultiByte
0x40e124 MultiByteToWideChar
0x40e128 GetThreadLocale
0x40e12c GetStartupInfoA
0x40e130 GetModuleFileNameA
0x40e134 GetLocaleInfoA
0x40e138 GetLastError
0x40e13c GetCommandLineA
0x40e140 FreeLibrary
0x40e144 ExitProcess
0x40e148 CreateThread
0x40e14c WriteFile
0x40e154 SetFilePointer
0x40e158 SetEndOfFile
0x40e15c RtlUnwind
0x40e160 ReadFile
0x40e164 RaiseException
0x40e168 GetStdHandle
0x40e16c GetFileSize
0x40e170 GetFileType
0x40e174 CreateFileA
0x40e178 CloseHandle
Library advapi32.dll:
0x40e190 RegQueryValueExA
0x40e194 RegOpenKeyExA
0x40e198 RegCloseKey
Library mpr.dll:
0x40e238 WNetAddConnection2A
Library oleaut32.dll:
0x40e1a0 SysFreeString
Library shell32.dll:
0x40e270 ShellExecuteA
Library URLMON.DLL:
0x40e280 URLDownloadToFileA
Library user32.dll:
0x40e180 GetKeyboardType
0x40e184 MessageBoxA
0x40e188 CharNextA
Library wininet.dll:
Library wsock32.dll:
0x40e240 WSACleanup
0x40e244 WSAStartup
0x40e248 gethostbyname
0x40e24c socket
0x40e250 send
0x40e254 recv
0x40e258 inet_ntoa
0x40e25c inet_addr
0x40e260 htons
0x40e264 connect
0x40e268 closesocket

L!This program must be run under Win32
.imports
StringX
TObject%x@
Z]_^[SVWU
;u3YZ]_^[
SVWUL$
]_^[SVWUL$
uZ]_^[
YZ]_^[
_^[U3Uh
d2d"h@
d2d"=5@
u3ZYYd
#_^[SVWU
SVW<$L$
]_^[USVW
d1d!=5@
2E3ZYYd
E_^[YY]
UQSVW3@
3Uhf"@
d1d!=5@
E3ZYYd
E_^[Y]
YZ]_^[
d2d"=5@
}3ZYYd
E_^[Y]
_^SVWU
< v;"u
3C<"u1S
>3Q<"u8S
< w]_^[
Ht Ht.g
6WHuv=L
&]3E?E3s
3EE_^[Y]
f=r/f=w)f%f=u
f=v)f=w#j
tY)_^[
RPCHP\t$
-CGL$
SVWPtl11
-tb+t_$t_xtZXtU0u
FxtHXtCt
~KxI[)G
Y12_^[
PRQYZXt5x
YXYX_^
@~d@PQ@
YXYX
t#PRZXu
uM3Uh3@
EP3ZYYd
f%fUf?f
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
Iu9u_^[
PRQQTj
YZXtpH
S1VWUd
SPRQT$(j
Zd$,1Yd
t=HtN`
r6t0R=
t/=t&,*&"
USVW @
USVW(@
d2d";~
P'v_^[]
SVWU @
^v]_^[
UU1h`9@
QRZX1Yd
PQuZXSVW
$ISVWRP1L
JZ_^[X$
thtkFW)w
9uXJt
8uAJt
t8JIt2S
PHXHI|
St-Xt&J|
t0JN|*9}&~")9~
tVSVWU
t@t1SVW
1Z)_^[
USVWE,@
t93UhCG@
d0d ]ES
u_^[YY]
UQE3UhG@
d2d"E@
t3ZYYd
U3UhbH@
33ZYYd
Ek[]U3UhH@
p3ZYYd
U3UhJ@
U3UhJ@
3U3UhiL@
U3UhL@
U3Uh9M@
U3UhyM@
TBisBotUQSU
E3UhN@
EPE!PC0P'3ZYYd
E0J[Y]
SVUEp3UhO@
3WEPUO@
EEPUO@
UE3UhO@
d0d SU
E3ZYYd
d0d SUP@
13ZYYd
ED^[Y]
PRIVMSG
UEm3UhQ@
d0d SUQ@
PRIVMSG
MUVUUh@
~sEPUh@
3~dhh@
S lX`u[{$
u*h4i@
u*h4i@
u*h4i@
umh4i@
S hpX\u
lPh$j@
3C(0{(
u*h4i@
.deC(@
`P\\j@
S z\XnuYEPXE;
EZGTh@
PPLxj@
EH@Phj@
@UYhj@
[8PEAUXhhj@
0PEDAUX U2
guh@k@
7uh\k@
(uh@k@
XHu^hl@
|PEAUX0
Xu^hl@
@PEqAUXM
Xnu[hl@
PEAUXYhl@
GPExAUXTUf|
S xXwu5
PC0P,t
tPp<m@
lPhdm@
S hXu8htm@
S NXXBub
S LXub
P 3 jP8tD{(
P3Pzt={(
urh4i@
u5h4i@
u7h4i@
ufh8o@
3Ph\o@
u*h4i@
Ht*G=x@
73ZYYd
PING :
PRIVMSG
PRIVMSG
:Logare corecta - Nivel:MASTER
dfisier
:Descarc Fisierul...
:Descarcare completa
:Fisier Executat
QUIT :Updating...
logout
silent
:Comanda Invalida
(Net:
(Sistem:
(Director Windows:
(Director Curent:
(netbios_infected:
(netbios_tries:
(netbios_failed:
(netbios_accessdenied:
(netbios_invalidpass:
(netbios_logonfailure:
(mydoom_infected:
(mydoom_tries:
(mydoom_failed:
(scan_infectedfiles:
(scan_infecteddirs:
(scan_copied:
File(%cur%\
File(%win%\
File(%sys%\
File(%tmp%\
File(\
restart
QUIT :Restartez la cerere ...
QUIT :Quiting
rndnick
:Uite ca am iesit
ascunde
%rnddir%
%sys%\
%win%\
%cur%\
%tmp%\
%rand%
:Ascuns ca (
:Imposibil sa ascund ca (
%rnddir%\%rand%.exe
:Ascund ca (
:Added Random Garbage To (
:Failed To Add Random Garbage To (
registry
system.ini
explorer.exe
:Adaugata copie in REGISTRY
spread
U3QQQQQS3UhOp@
d0d hdp@
.com "win2k" :
C4PC0Ptu
U3Uhkq@
o3ZYYd
d0d EEPEPt,P3
EU3ZYYd
EHb[Y]
UxSVW3
x|UEEN@
EPE1PEP
U=|Pxv@
xtrworm
TFileName@w@
TSearchRecX
U3QQQQQS3Uh?x@
Ku3ZYYd
win32dc
win32dc\
trainer
serial
BattleField 1942
Doom 3
Sims 2
FlatOut
Counter-Strike
Silent Hill 4
Half-Life 2
UT2004
Quake3
tDHtvH
UUUEE$3Uhz}@
d0d }@
cEUUOB0U
t-EPU}@
Euh,~@
DCPlusPlus.xml
<Description type="string">
<Description type="string">XTR</Description>
</Description>
<Share>
<Directory>
win32dc
</Directory>
IuMSMUEEEE
d0d EU|
hX]u\\UG\`^
tuDU^DWEh@
Fu@U0@)Et@
u0Ux0q,E
u # h@
dcplusplus.xml
upload
download
uTC,PZSC
[[U0SVW
EE;3Uh@
d0d 3Uhz@
d2d"U0
E*D_^[]
Ht!Ht,6
U3QQQQQSV3Uh[@
d0d cEp@
X>AEPEH@V
W3ZYYd
abcdefghijklmnopqrstuvwxyz
BFKu_^[
Unknown
Dial-up
UdSVW3
d0d 8lPh
3Uhj@
s3ZYYd
S3ZYYd
ZE.H_^[]
| v;}
N|7 vU+A
d0d 3Pj
Ea{[Y]
d0d Ph
2E*D[]
EEY3UhK@
d0d Ph
23ZYYd
:E2L[]
KuZ_^[
KuZ_^[
BFKu_^[
U3UhE@
q3ZYYd
TMyDoomU
UE;}3Uh@
PS7t[@
PRIVMSG
:MyDoom Infectat
d0d pP
_f3ZYYd
fuZ[U3Uh
TNetBIOSUhSVW3
hl3Uh@
d0d pPh
u3ZYYd
P3ZYYd
WM_^[]
USVWUE
!}]EPEPV
\Documents and Settings\All Users\Start Menu\Programs\Startup\
\WINDOWS\Start Menu\Programs\Startup\
\WINNT\Profiles\All Users\Start Menu\Programs\Startup\
Administrator
MMMMMMUEE
d0d 3EEp
EWPENPj
EJPU3oE7P
Z3ZYYd
PRIVMSG
:netbios_infected
UE3Uhx@
d0d 3E
U3E3E]t%EPEPEPh
EPEPh
uO]uNr%FE
EUoE_^[]
U3QQQQS3Uh
SVWU33C
netapi32.dll
NetRemoteTOD
NetScheduleJobAdd
NetShareEnum
NetApiBufferFree
NetBIOSThread2
334fuZ[U3Uh
U3Uh9@
d0d 3ZYYd
d0d <x@
/3ZYYd
%rnddir%\%rand%.com
%rnddir%
%rand%
%sys%\
%win%\
%cur%\
%tmp%\
us.undernet.org
XTRMASTER
fuck21
356746
Runtime error at 00000000
0123456789ABCDEF
Biscan
3Messages
System
SysInit
KWindows
UTypes
?WinInet
*ShellAPI
WinSock
apFunc
!uMyDoom
uNetBIOS
apInfect
&pWebServer
WritePrivateProfileStringA
WriteFile
WaitForSingleObject
ReadFile
LoadLibraryA
GetWindowsDirectoryA
GetVersionExA
GetTempPathA
GetSystemDirectoryA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLastError
GetFileAttributesA
GetCurrentDirectoryA
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitProcess
DeleteFileA
CreateThread
CreateMutexA
CreateFileA
CreateDirectoryA
CopyFileA
CloseHandle
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
WideCharToMultiByte
MultiByteToWideChar
GetThreadLocale
GetStartupInfoA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
ExitProcess
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
WNetCancelConnectionA
WNetAddConnection2A
SysFreeString
ShellExecuteA
URLDownloadToFileA
GetKeyboardType
MessageBoxA
CharNextA
InternetGetConnectedState
WSACleanup
WSAStartup
gethostbyname
socket
inet_ntoa
inet_addr
connect
closesocket
.idata
.rdata
P.reloc
P.rsrc
Rr@'v@
g)xa$b5X
/!Odcpp#$W
md#bat
h$;;o5
SDG):+\
A&C-XF'B!"
VP,[px
D9Sql'pABJa7B
5a?abcdefghijklmnopqruvKwxyzVSD`#2
A/P([^_e#(/=b
u_-[Ml`
HUnkn$
'NT^oI7
9598SE
PRLdLAND9&#-
uiS!(kPx
h/R)dd
C<-sV
92z%F\?|
D5+AU]JbHj0"
9d+C.;P
BZCI!.?,T
TMyy+=
h&Ke &K&
)9)<X5PS8
fZRh@N
xWn<"r
5 IatO0 clx :D %pu
A-:R8K?9
c}U-fu\rL
y%/9``z`"d
z$K.ll\vO3)%
h BH.9:
$Jl@,8D
Vr[#o!?>
s q S!
} M"u\Program
G%WINDOWS.A c/6NT">
;FO\O_kD
]dt` A$_c
/zcB}q3$
!_8;h0
`08 U[rab$tVd<
]uNr%F,>\/{t
Nu?6fA
S9`8dgs
wH3eDq
[P;ihp}
a7@pi32.d
[\duJobmA
o#ACBuf\rF
btt%h$
l&|r2A
Ug`@YS
X zW&j
kus.r.org
#vdm?I?fuck21735674 [F6
T$rf/
mxHErr/gR}Aime e
01234
89ABCDEFi-
$4M4@P`p4M
XhMtnO
p4M4|gM
J4Mtxq
N?GP&=O8
agmSv1
In&Tq9
Kv4UTyp$
@*S<API
o*bSopIMS
&pWebServ
Library>G
1c$*rV
TJLa^,
AtAlbu`s!
Closla[TiTol
iDeZ7#\TC~%
?%(Copy
`TlsSr%
iz0V;@ntu
ga8a cIe
bcp6e
/#&m/n.#d
Unh1wd.)pN
E)HOf7Rtl:wiK(
R<H)I3
.6O<nKey
`x6[>4N#5;clCn/A
2AkF:=ILST
(NuxIo
@SAXme=
ghobynaCZ-s
iZ_b5l
'BSSvS2Hs
+Orvdr
lSP'e!K
XPTPSWXaD$j
Gggfv@
&vvggd
wwgbvt
1wwwr"gf@
1wwwr"vv@
wr""gf@
wr""&f@
ww"w""@
1wr'""@
3333;31
333333
KERNEL32.DLL
advapi32.dll
mpr.dll
oleaut32.dll
shell32.dll
URLMON.DLL
user32.dll
wininet.dll
wsock32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
RegCloseKey
WNetAddConnection2A
SysFreeString
ShellExecuteA
URLDownloadToFileA
CharNextA
InternetGetConnectedState
KERNEL32.DLL
WritePrivateProfileStringA
WriteFile
WaitForSingleObject
ReadFile
LoadLibraryA
GetWindowsDirectoryA
GetVersionExA
GetTempPathA
GetSystemDirectoryA
GetProcAddress
GetModuleHandleA
GetModuleFileNameA
GetLastError
GetFileAttributesA
GetCurrentDirectoryA
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitProcess
DeleteFileA
CreateThread
CreateMutexA
CreateFileA
CreateDirectoryA
CopyFileA
CloseHandle
KERNEL32.DLL
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
KERNEL32.DLL
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetTickCount
QueryPerformanceCounter
GetVersion
GetCurrentThreadId
WideCharToMultiByte
MultiByteToWideChar
GetThreadLocale
GetStartupInfoA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
ExitProcess
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
mpr.dll
WNetCancelConnectionA
WNetAddConnection2A
oleaut32.dll
SysFreeString
shell32.dll
ShellExecuteA
URLMON.DLL
URLDownloadToFileA
user32.dll
GetKeyboardType
MessageBoxA
CharNextA
wininet.dll
InternetGetConnectedState
wsock32.dll
WSACleanup
WSAStartup
gethostbyname
socket
inet_ntoa
inet_addr
connect
closesocket
[Bb1~Fgc0ACNW?}I!zR"
248F(I`n
ov+W$(W{
^i*[MC`TDO
qwrPFx
]5m2H2i
]~\-6)
0cA{XB();&}9
=V.o?:
|K*sX4
xG%V|>f}
kFM#l!
TK~i4t {
7!3\Q
(^l<s0\*II6
}1](%|
Dt,ys:;:0bAe=g=-m
7hIv[B
;zl"({,UK
w"a/W
+/dG3YZ7
\7D9T"YB4
"N@>XHQ*
tyauDIrs
/[@*+R}9H=
PAq|:nM
vX<>U^=
nsxyLF3
KoW:@3
Lmi_Yj
%@3~q(E}gB&p
1#kwW6Th8
jPT;'@I
B>Gw4w%
XTv/eBPfe9R8
epE-9?r
vnTiq8
gvHg1>d
Ke#a#HBU\t
BQNNqLGm
gBNFa|L
abH]gj5C
ZjvU$}iI
0J[8~UZbMWcT0
(,Cl{TX
aBSal"QG
9d '_5O{y
9#oOhl+C~i,
wSM0}&
N%omBnUsyuY
EX`dyi5-
9HFVu@,
>dZ.xZ
WYe0TGW"42
PuBrik
N><J]
3C/L$vPm!
1i!<1|%VCH
}Adfl[&2.
d%3?A@
\u+Lpj
y} A%xJ,<pr
9QA;O9
p\w?4iQ]Oi~ZAPg
sbE`gS
=W25]
,.nr8'm
BM*OU.
_n8TCh
XC-Ez;Z
}'Y%?1f7d?
{mgfO(
T5:Pw>7o
Vq9u.sOAf
7lPJa]I
ZLvjclN M
Gucb#og
.s@o[^
9yMu\il
<tHnq;q6j
D<*h41
RC<KXbVA
*2$K@@C
AOMvL~+T
wZk5r_!A+
xcsEQb?cbz
|&`xOBslC/Rm
XjyRhu[y'yM2F}
|&()<jr
03k`$:
-GrM-g{]
ehk>J(3
'@MlMI
&o=PKBD
o5CyWB
Y] *-><Ia
.zxIm
O\fg%KfR]zeykd
4z UK8+
@cq-YH^_L@T^=07F
6`0F&0gI}lc!
?P\C@l
3^d\;A
!B|tXu{
`Qa`Cx$8D]M
j562><
O;^A=#
s|>ark
eKqw54Li~w
{2aXTRq
44o9lU*q/[X
{*}9c]u
g|]+}2y#
k4@\`[
fi<6XK
GUmC"q[
'KDeD}v'
7z&BYw
GkwdEb0Z3
@i'E6Q
$B&hl~Zgvdn%
W81UZ~g;w(l0|>m
s)k-[A|B;>cN
E~Ag~ex$`/3pd;!k
!~"5#s(tV
_u'uCR
`yd7,q_
wDOQy/H&
%z9"mDF]hI
Zvm~DO"U
)ztG{/'
e.%YSPk0^M;!
'GL[FoC
*}Hv8_mH
/7>Pb2C^,L
,r7h;g:5\y
]\%Ob<o
glz<Ws
?K!&dY?
dz%K}z#
VW,jMV1-
6/GR@x
GK^+du
L?#l-8I9
-._q>C;-
%Eo*JT
3;M2v.u
ZoK>5G`Ql;=2Ol
}jMe{5?i"
f]-iOgK}N
g`kMB(2t>d%<6oU,0
eu3-p/
qmR}IJN
y`/C$[\0xj{w}r~0\D
HEM[BhSAa
RM9AuC}AiZo=^7F
j5~*rTcY:
n-*=D bSg
MOZ[hu
XR\7QHOq{
+2XD8Q7
lK(>xk~Hw?-]TQ
r)w\F*%<
V&Of1hch3,= [v
%zIP]K
i[xI5`
~xWF5?I7\+;
aYs)!R`Ke
nhI_A{
@uh(gn$(`
`H]YDQ
Y.Ur|*Nu"uJ
]xc6CB7l|
D=*N>1
>pgsh$*
)vWI=V\>W
x@Q!gcC
c H7Cc2
W4npc:
3dquQae&@)P"
ZIE5@l/x;(h]uB{r,T[{=
mWIZ/VfD
B,e*d@I+
^x#}eYd4
is0=:a/
J=z/`w@
J{^OwRu
CpST S
2mvF,~x
SQqV`+AY|;s
\<#59I#
9pI795
F#>K#H f~
l@}{Myb
;`WpMz~#oHmX
V;];o^{0&j
J3w}?LJ
4W)Vz
`ge,zgw
M.t`H.~
85ZfghA
Z[b8M&7jI
6'[Vw?
>VQ:2DSV3
DdC}Cu
9zW("Bk1:
'<2<c,UW
vP@Y`l
=)"k@&
2k>nBH
VaqjYN
'VZ-ij
Lt+2c0LYk
D]Hn3>7(T#<A]az
t1"+N9
I.ix6
C 5I,_}
7zcsPUS[IF
5mb#m:
Q@[H[{AY0^
lX6sVL
OzbwRBSE
w1.ZT6vtBg~6l~
(55.!OP
H3I0wZ'98Vxo*
&Q(U>NsF'E
qafZ)@
$*}4s
08$^H143o|s[%S0
[IAj*I
3j3uMD(3
|[ RMY
$o-Lb6ya0;F>7.on"
juW<rBZ
$q:[9G/
*=cjvQm"a4{70]
7Hr|qYv<_E
fk\LrXPd^;<
C2z{iCE`6`G
niF:wU
t}1c|~
y$X pn
8f09;Lt
6'b+S#
'qJv71V"$
^k2`(QB?R%[
}c:U5I
\'[*=ShT
''q lV
sg29%-
(AK/)q
z`,gS,
=d!C4rl
`oK#?Z
h.<FMV7
Ba~Y8nu!wJPopQ./+>{U F
~A!E>Pidcq
1v!bZu,u
_YqI\_$
=2rZk3
77A</&>do
Q_U[TQ.
H_uI($
+_m=2I!0,GR
F<Ve]D~;'
,dB(Ib?aH
2zvjr}
]9NlMd
JDyPnss
`;ZBEo(kP&y$q]M&c4
SA/n9Wq
^`z+WiR "-B{$
i.)cw+-f
VdnC?a1akl]mi
iO>I~gq,<oda8<dYQk
fekzusT;
BG2m,B$M..
>^"LW@
f0B\5$
yu?k+
M-Y!PJ
q:?z%n
pp+bh4!1-`5$m2,l)
0R0<y/q&vf.
}s%$s5gzi
>E|! ,
ES!`>l#
aW!=x)J{k<HQ<KZz
Z2e}1zTYt.
>y!0fOs46(3W
PvdM!N0
e>Y:xT
k8g%U,B<yGa/
;myHECHnYqwJ&
B^]*ollXrB
,"3WurFdK
oJC78*
qKssSok
7{:Kst]v53E{l[
VS.~JMV0
>rn[|7]K
:JW0x({
3?&BlEk
~MN 5gQL
]"/Z[cmoU=
oUwlu#f(
-l+,OrG;
z|>Dse)9'*G
L80(61pO
?!Be#W:c'#p?(
=K+n~6[e],'
Q]5qw
Gr sLB[
[h/Ow|t
f8{ EFQ
M$p=fV
L"7H*NfF
G~ZLM6
3`@&Y}_lf%c
0lhnOnL].F
3<h=*
G7=7W
N`m[U
R;?&QG
}zwAPur#{YS
6ZXiB0
AT _7]+
)Vk.1E$`+
</dBn4:>3
7,eL-.
">i6}{d|x
W1[+wG#$
r0vOkE'P
3o#?Wc$0
J`(~6B
PO;E,z
_<$Obo
lIbF(hN+
)xBGo+K
#{VXpTy-$DlG
-#e3X}
|r!{eV
<ttm]R
ONLTq|uD
s/yP |Z
"7-U<<
D!]};~
u^J7]Lq
<Id.'tcL
(%Ut'v:3zGT
_yXt+c
ZbLRY{
b?-K;(=M
4nI4P\
6W| 4y-/,
{|X@N4enJy?
06&AMf
>-vCl`zY
LH[p*HOBOc1}\p;C
a>J-79%
>*~ ['h
)3sOn(l
LH[p*HOBOc1}\p;C
a>J-79%
>*~ ['h
)3sOn(l<+Pi
HCOfH_u
GO+{}F
mN7_At>~Re
5.o?H9tWz
5~c<wr6n
W1vr2W
EXi>Qsi7<y
}u!{jwfV5Y%R''tu
{;^"R}:w}l
61'snQB;
;0gBSejU/h'
,_g=H:?
::C$Uy
Yz}(O'aA5
X~P'.:\]'fk
b^=~E5{e
E}d2[mu
4ApC7sD
2]!a_{6K
5Rx[eUATau
Ncq-vy~
.fvu{z<x
EB~:1ix
>`OtbF
SA$2:'rQ
h1OYU
KVHEpxr;{
^7s66uE
K#MRryQg
tF%xe)f
,t5p
]}shWR#m$
vU!kn:7
EDid#~2V
#3!*huf
MKvbqRx
71|lPS=
~"Kzgw
'nG}yJ%
-kN\g9\
^|G%m@"E|
q*-M^,
[n0p&TQ
)Qa5s>
sk8:jpIeIFN
,kB4cPre7|h`TS?;pr
XRSn|:
5F/9I:IZjN9yX8
h}{k6r
WI7I N;
ybOH2JS
.vH{%~I
x9{vIR!x,)~ }
3f}m/|I)
5weDH9d-V2}
l*LpXi
7%#n&+ivw9q>ZswK
6!}5UN4
yX+G}K-t
Eici]6b
(}A 4<-8fs'tS
2=/m~@092
y:I?v}_mCF
sD!![~o/n8]/MS#gooiFG`/JvY
aooj!L/w4
OHe,S~
u4O'^W
t~>}=6K
?"R&qq
W*P`OA9vvv
kFIe9Wnmx
TZ0_Y9A
ioc*+287hB0WbhDWy5
KGVBQe
$<,avj
``?i6\
HO#wy@_H
e# ;1Q
BQD_:,a
T,*ugpVk\k@<We
#PEyl{j
}28MN! T
4u,dcN
SDydYR3N
frxR zcw[^
k!`=DN#
_#~IgV
oq,O+G
^jWQ+;
dBj1@H
|b>pZeeL+=
hDB{9c63
_bL!#u7k7qH
omi$sAswhz
zR uA=e-
/d7f|dM
L`@n!|68z
I8Sn$Z
<lruLAHh
=/Q=o{P~S
Qk|{\=x^E
qtD4(q,K'
e' e.Ft
?!monxU_]eT7DRx+
jy]q7yR
EG@:=nkLwn|
-lhI\IX<^
I)7`gL-U
n~=a:M
"~"RW@
T4h._K
@QJN9a
&3C^`aAJ
@?jeUsRhSE41~
CB6);ZmjMyW
;R>aY8
L2`O`E=
Ay(( L}7]oqi
]"fAD"s
EnXy^
o^/t8uI
OD6j4ERf<sm7;?o9
u+M\(!s
1g2B*~I
.)nmrK
\L2Tb[=
f~{>M3u
+f6^%^e
6u[xAd
Wl5~&!
j)KWT7(
ADk~D>1FsWuzPFe
&_v<;!A
o$mj.Cr
~8F2RT&tc'
#Z_}Uy\
Ve)&uLhK
Sp[Iw*Qi
E4(VmhYX[B?Dv
5],!m3LT["]S
seZhiR0]p$2
U(LK|v
p2"jdG
d:CL0!N>_UaJ1|
lJZ@t1w
dZnZT8
%NJ`m+T
&tH^p%
sM|8{Yf>
4qORNA4u]q
2h"cuT7/!
S!3t&~
UH-R{(
5tQ'mdKmVV
{s:RV{
OW5QW<Fz
~{SGB=wQ>
>j,m-G8qG
Br8c(71y
30[;;w
swuE9Fy)
i<4JI+.l
p|=J!<dGh;jt
bt,/s {
YUixa[
4fc9CG<
B[S?~hD0qEp}
Il\JF9[.S&+
zWl%9
1MC3@r~>L
+.;O#Gn
ky+Jnu
Ufsj e;
rqXI DQ
vKjx#SUw?r
DuvyY}N
t^PC8|
=H(/$={o{
FNJ$#&wN
+N8Tk <
N-"0rS
k#SCaE
^Q,,c6
&[m|]Xw10w.>vvnB+
>Ygei9e
tD)2Go+3
VS}E#b
-^I]=I^SX}
?"}:f<).0A
7LP5e}tJ3t/
f!YbPhieU&t
Sy<\Se@)
vCJ$3k{!WX
h46xw`,
,F2/}h
xtZptdDr
d"rp}CVH
+H-Tw+
WY6{H/"BsI
&a$+?r=
<ISOwEU|ke
u*=p52t*8,S6zO`V;
X}suF4,#e
IZ60Q^g
f5xC*CNqMzf|c,
<,4k<i
_PWBo-
X9SAG9u0HUyy0aVkPD
uxnXDq(ePN."
RzsT25ym
s&:3JO!.
2ee?H)K"J
<+5|0Z
Ly3^ssI
6H}3jXQ3
Vf:b^Q
lKBk}@
2`5lut
98,T0-v\V4,T-V}6jJ_
x1!&S9k
P;W9GX4RbD,
([{Swv
s8.Fm.9+*gVF
k%B8'5>?;$/3
WuB=qu
]Tq3&rLnx*
=>x"+R_V
aJEn%~
rK,WS[
b&/\Y
R >PST39^i
`Qu[fRpw
6@+Eas
lf.?]n
(#N7Mxu
IgtfJo
gYjD;Q
^x8kc}
AG$?3%`
__S]}5a}
eY'lyAHL~y@/Gm
LW;e|ff
})<:cIu
)Gb7m?GY 0
"y-Q/Tw
NZ[f"%5f3
U)1(SkZ
mbh1':
ME|CQ,}67LY~$/OM$_
E70A^n
v]VNfauy=
fTFu1E$;S#,_N
C#0GEVM%^Nqh;j
,p7Fu0G
}=Eml9
WqlYXrEAQ
}K'>Xo
XI"7M$
J0ss<2
f6P[4J
:a8Gg8
zT_Wns$d)
M+v2dM
MpDx2t=jbn
^8Jm~}I
!97Js\
B`_kpX:;8L"Q\h
+<3fv8L`x>
=6q?u
;_:3iO$IKa\
t[_D[eu
/mDc[w
2k6D<H:pm_
#n,j'4Q1bI:'
Bzv/E}!'\
cQA>P,N
N>_(Nc9j[<Z
2CP6iro.}2
b3NnOz
x!k~+dg'
TX6gC*ar
N=8<M@T)
AE.:GRs&
S%R7"fo!RbA
v}272C
E2YHNAO
]BxX=91vE
l i8}Svz
'QeQ6}
t@B^n$
}p}R'}k4Ck
;SFD9q
}~1H.
6ZIRO-
V~_{?|o;1O8
wHbO&{
O0cqZPZa
B/FA[N/C
)$'!Y}M.J
2"NJi.rlUz
O{/Tl#!1
{~nhp-
+>gX,#
?{gK`h
y;6ClDznejMfb
Ff#{1`<XB]
e'*`vw
'h!c1P{xo|/\1<~u
S:X@+*ODNqjY[?</wJ
ZwF"#v[49
}vYB-F06
qb2,*A_;1
!Jw!)D
nz Tx
YW3cr;
BwsqM{5n]
\EH7TFm
=m6\)#}EL
Mk!ri/5'i5
O{k[5viS;Mlz
d0@m+6
~g;W;FZ
N=w,7CY%:7
?`R41J4L^u ?B0
`fK}mC9eh*D
^.57%-5}
?DU$OH
M~'e3Z
` D5R#3?0wQ HQ
fm>bqJX
rpucbO
x,)}4f
REOXs,
Fxzp"8u
EW)N=bK-R
u')Ig4v#"qw
EqKrWC?o*|
:%((:\dCm
cQYM&_rG&a
aZUP8N_q
^#cF*^b7
5X:)z|
;y`h7WG?f
nyx?9R~#~
a?XgDc&
k1C~r
]6pq9
]::V3]#
3#\c^T&k"S4PR
sF'Jog|$E?fL|kx]Q
yJAeZR
#AQSrwMoU
dvZH@U,=
6w!k/\<f
gC?9$O+
w3)e*)
2l~RFDmMzJ
7MudX2dC;8
](yk^)a
)M?v>SoL9s_GCU
cS(uR6
j/nS1X[L
&z4C{"
nevY?=
kkq68~La lf
wy>)\`X#
E|~iS>O4(
\0C05K\o!
{-LfR;NxT
vSR67M&
szf'R1a
w;q8j'Gz9ZH{X
}R{~,=/t"'KHk
7L'E\y
4=pG (Q@
I1lo&mjJ
PGK]#4
v8DQCL
%x}zYZ(/mk{
JK]xddh
:e/!~pt75
_>mm,n
Kz"um_N-O
kuYr$K iG(*d
]P&Q-J
LaW^ep2<iX6NF
n,cY,7{
*wiRK@-uP
];V{+Y
|R8uLtpK
vLLgm<C?lt=@
9QT#1z7qPSV=N
Y0@&m:
8$N=#Nv^
s%.ZOl
kcODjD@9@
,n[.<J3
rX+pH:
,STYu(!sy}
K(U>cm,}
@Z1;OF0}
0$2?'
3sNN9=o
e\YJf_y
(|: PR/:
<!f2GB
\/q)SXp.fW#
T;rqJ|=h
Y&d'feL
G uaK-^*{
h8VzcT
}zUOcI
C''Gw9+1
Q?f|q5d
pD]#1s%\
eDCcz^^ISz4N
[a)=<mCy
f@>Gwh|3
e0I}3"]q
I:/=cB
Q\gi$i(nQ6o
<uvW/
ucID6K
Du*XGHQ
T{.1A\w)'w
CWq7j8p(8B
H(oqD'S\"
12E<1vZc`ApW9h
i@d&a
GM(wc5
au,exv{&
bEu"szU
nZ.vjw
MLF$o.P
)rw1o&F@0'6
XU+E5hX$mQiv<H@3#q
0oar8f)I
@,t+~?J:]
cpke/Z/U(8;Z
6-<-DD`bRP"fsx~.
ER";i;%T)Gy_>r7=
P5w..\f
yc0%wqs
gMS%]5V
8u[+Y\l\t|
\4)[;U
F$[Whj
b~?%NG:'Q"
^.~38p
.&Obx,,
1K|>YRJtQjR;(%pL,
\@2_9+Mr6d
i;LGMA
HIn$Z*
Euu>dL
a@M_ZC1
F^^!=:@MBZ.
AzlGg9h
+A*cS4
|?ZyLQTT
$Pt%8s
*MXSMD
E#80Ge
< FogbIpu
sx=vp{+
pO6Bf-t-
zs"Z;,$k[
NJ3;'$W
:{kn{m
.k Fa&B
rQNdiJ%
T.Pb=70g]4
2tmtRs
~4!B^le:
Z!$[rgwxd
v|<9VrZ
J1#jN[mGrT
b,!6o/8
;}4UV%
aw=8$-&
y]2{(5<"\d@k!Bso
ZBtrip
HYA7>h
/u Xk=
N`LTPx
53#V:L
w7r6TE
Ok;<EVuYYdiD
>?z8a(N5-XICdn
+7A=f=
|cY]'0
/fUf(i
!wnq(@=V^
,CuNLZ7
1f%C7<
LUt}>5Kb
upe.bn)HP$b
R*c_1a^I]m
k~+"c,
>[`}kE
<HhBN>
KK;MAS^
lKF*CP
B;]18
`xJp%4
UPsdS0pAZ
bi+zwW&_
FSNI(,5
?R\%{]n
;zxz+7
:/F^KgQ`w-
Y7lf#d
rfO~'Y
m5V:!(L
p:hr^r9
e/0]88@
oA-)?.40.WH_{~
kAXt() pt=_wF]%KF[OR
/1)YNg1s
dM/F>IFjlEk
@v_-h@
Y;N2@V
}YK*hD9q
78ly%y
t\Wse!1v
Jxw+}T;
no2F9.`'41G:
Lp%m"I
"f%6$C;Q!
gfRtt9
mO\\9H@
i?G![*=
<t-#3H&7i
tMc/\HRO
!Y~zlt_
:L)]n8J
R,/6BHx
,BM[kV
::0@:m.
IT*V"i
~\%*bDz
2S%pO )5}
Uw-E89+A
D6GMyXp
Z^'4a.>"
@pQE/$
8nB@7t*u=w_&V
Lj*4B
jAxq*n)U*
z}?!5B
f*JL%E[
3e#,x1^
lZ.D :
5K=@c6
t_Y|<B
<`W"i`I
/Q6xJ/V{^
sfD~""U!/
-jwU5N
a?r+-b
TJLA03[LxWC>Oil
)z')
53l$OY
a]B'NN
2%_XuYolmeq
qG[Bm/
D2I4=f0`
E+2@Ifw
.xel{?
:orCkJ
d{Ls7H
*'C&xH<
ta6KzR
$eeWr*[+|<\D$/Z
ODK]E-
|W|/%"X\
guk_P<T&Jyl,Ef}&
@VXws_Y;h`
\>7GSH/fIqm[c
A#,siy~e#
yX6H{A^
p}R$%TF
E*3z/m0|m
FY,<vq
D,mf0y
'h1m.F<
UFrJb
Gnq|mm|
xxo%Kk>YDF`
d(FSa6
QwA$Zy2KW+^\o
-bAC5%9
4ykH!H'`H
<5/sf<Hm~Ixeu,
4K{;G;Kop^Lc_
Nd%KR9bo
,6L3D6
"^'XJH|
[*Y1)^i4
TQ`AH3Ruy8U0C$v'rE
h[w~80
Y2`3]Rm_WVmpv
HZdQhnDW
fZMd[Mv>_u
yq7x43.w
A.FJX~
sOuq`,
fp6%c<%;oY!e{3
js:E,
B\w{Cl
TK]\.R
A@B\mtL3Xyx
:-UjXX
<n\I=nE_5X
_SK>{a$5$
@DbJMXH
X-r5km
hglf+'u!f
*V#dM$O
kd#e[5v
gsd[>*
P`$<hJc
FTA?A_EMM
>HsIOi-.U)
FM%T|qM
A._4w4
$4~#]&
t;1hk?
X'H#|I7MUw
FwdYZ
@ Kl+(
~vKF)]?
d#dxH12VL
akc?& G6~b7# 0e
]?,FRBs[
a>vY55
:u1!2Q:!P5*|}
*T@}cYmieL_
l+O2:3/)9
(^NgKiun>5p;C:wU
|"`}FA:
o4 "6W;
l/uqie
n|)|Zx
(O37rO^=8V<_y$
~5Iv_;Cw&-C-bn
=r:Q*\
5DD2r8
o:};UvuS<Z<Ub#T
t[^8}P&jb ec
C~6/U>1
@Nzy'W
[-;,Zj
RO6G~9
rB$f\Qi
1`>oATA
3p"eSQ
x%.6c=+j|@T@h
X1QryF)btR3w
pywINs
|g F1mCEe
l`K+Y
PT)[\`
fTUj|*-^a+
d^<ujpc
Cu]"l~<
KE=f[V i+,J
A2dZni
@aAn ,
=/0|zj$cK
Du<T^g dSde
DYY`MsV~
wkqb,ts%Z
W/Z?_aJ
y~Dt|t
2 8H\ZL8S JOBta`S\
T@GigP
h/DL)D
&D7,.r/
R?]6?`tf7
^8u|OD
P4,MA>i(lJ
c_S/#Ng
VpCEXV@)
jqhVe1X*x]_w'5
T#)JP_I
N|\J+)?'
Z.pe)>rx
Wjdk2<
+,5G)p_K<
"$m{)AWN|-9U]1
\*Qh3v
nD0X4z
>.k*!&
YgrAD}fHZiX
Ut'JP;+;NL.Kv<
EoejiNKA24X
cR|Zew%2
v&ca;EKdmF
oD=$|OQ
;i~s_olD
x5@T~pC
BRn",C
q}R_eE
({NW*_tRhM
zM569t
"t2fw3
yT0#Cp
EU9h7=(Iy
xU)<_;JS_-
"71npw
9Uzvm.U
yiKK->f
E flTo
|2%U?20;yMi,(f
u^uz-Y 4e7
TpomR{IS
u l%t3*6
K#Y'd~y)}
BKV}|R6L
/4WvQ%1@e
'{S'ig*B1
`>?*OQ. %"jN8
h|0B5d
E%<}wvK
a>2b-/
!M_UnnVN!>}X??
Y`{Zms)
Ea}B_uku
4sz~
06:tgnj
VFvU/I@MF
Y@0Ub1hs.yW
rJB7`3@3,:k
K}kW!8vA
eBl_Oi
lvYBQDT
CF$#J
w=e]6VC?5AAUKQS
jnEz ,
*qDe&a
r((N,D +
uFv~dL
5kRg>L
%7K\j?>
#y>kY&~D
$.bE+2k
$Z$#L0PIfu#Mw
Z?qR?WD
vd'9c&h;~Hc
kFn_8T.x
-I{ipNLJA+
w|@cJ`51
oaQ|B7
yOCl%k
)9k>gj
%4I'R!N:6S
XS(1*0`aMo
o~Pb*:D&:
N"e=]/
nZDg0=7;
'"Ogj1<AK
nz<nb08
A8[Qx:
p?rakk's
wWa-C1'
w-i]w
;cY9ji&F
1/KX%Pk>^
AJHxEh
g|a(G)^c,
[b^(MW|
<z [Jl_
GU[j4a56/Hm~
Rm{Q|'s]4;0
vGTlxZ&8PF|LUEq!b">N0
eb/>pN
T}c&pghcY?
"db[]yd@ej4UvF;j)azt
t B:#R_
Blpl$P#_f"g36
W1s]A{>h
y&Pl 6EC{xmN
:Dy+bE[amZ>;qp
:j}1'uq)nPGl
@@@@@@
DVCLAL
PACKAGEINFO
MAINICON
DVCLAL
PACKAGEINFO
MAINICON

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.