Analysis Report
Overview
General Information |
|---|
| Joe Sandbox Version: | 20.0.0 |
| Analysis ID: | 352751 |
| Start time: | 10:20:54 |
| Joe Sandbox Product: | Cloud |
| Start date: | 30.08.2017 |
| Overall analysis duration: | 0h 4m 24s |
| Hypervisor based Inspection enabled: | false |
| Report type: | full |
| Sample file name: | twdlphqg_v1.3.5_apkpure.com.apk |
| Cookbook file name: | defaultandroidfilecookbook.jbs |
| Analysis system description: | Android x86 5.1 |
| Detection: | MAL |
| Classification: | mal64.evad.troj.andAPK@0/251@4/0 |
| Warnings: | Show All
|
Detection |
|---|
| Strategy | Score | Range | Reporting | Detection | |
|---|---|---|---|---|---|
| Threshold | 64 | 0 - 100 | Report FP / FN | ||
Classification |
|---|
Signature Overview |
|---|
Click to jump to signature section
AV Detection: |
|---|
| Antivirus detection for submitted file | Show sources | ||
| Source: twdlphqg_v1.3.5_apkpure.com.apk | virustotal: | Perma Link | ||
Privilege Escalation: |
|---|
| Starts an activity on device admin enabled | Show sources | ||
| Source: com.twdlphqg.app.services.Rqdnonjuptjh;->onDisabled:11 | API Call: | ||
| Tries to add a new device administrator | Show sources | ||
| Source: com.twdlphqg.app.ExplorationActivity;->RequestAdmin:71 | API Call: | ||
E-Banking Fraud: |
|---|
| Has functionalty to add an overlay to other apps | Show sources | ||
| Source: com.twdlphqg.app.TouchInterceptor;->startDragging:76 | API Call: | ||
Networking: |
|---|
| Downloads compressed data via HTTP | Show sources | ||
| Source: global traffic | HTTP traffic detected: | ||
| Downloads files from webservers via HTTP | Show sources | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Source: global traffic | HTTP traffic detected: | ||
| Performs DNS lookups | Show sources | ||
| Source: unknown | DNS traffic detected: | ||
| Urls found in memory or binary data | Show sources | ||
| Source: android | String found in binary or memory: | ||
| Source: main_menu.xml, abc_action_menu_layout.xml | String found in binary or memory: | ||
| Source: abc_action_menu_layout.xml | String found in binary or memory: | ||
| Source: album_item_layout.xml, rectangle_bg_white.xml, abc_item_background_holo_dark.xml, abc_action_bar_decor.xml | String found in binary or memory: | ||
| Source: abc_expanded_menu_layout.xml | String found in binary or memory: | ||
| Source: abc_popup_menu_item_layout.xml | String found in binary or memory: | ||
| Source: abc_action_bar_decor_overlay.xml | String found in binary or memory: | ||
| Source: android | String found in binary or memory: | ||
| Loads a webpage with cache disabled | Show sources | ||
| Source: com.twdlphqg.app.services.Ryiidrxcjmfb;->snewxwricc:14 | API Call: | ||
| Source: com.twdlphqg.app.services.Ryiidrxcjmfb;->snewxwriii:53 | API Call: | ||
| Potential DDOS routine found | Show sources | ||
| Source: com.twdlphqg.app.services.Ryiidrxcjmfb;->snewxwriii:56 | API Calls in same method context: | ||
| Source: com.twdlphqg.app.services.Ryiidrxcjmfb;->snewxwricc:18 | API Calls in same method context: | ||
Data Obfuscation: |
|---|
| Uses reflection | Show sources | ||
| Source: unknown | API Call: | ||
| Source: unknown | API Call: | ||
| Source: unknown | API Call: | ||
System Summary: |
|---|
| Classification label | Show sources | ||
| Source: classification engine | Classification label: | ||
| Creates SQLiteDatabase table | Show sources | ||
| Source: com.twdlphqg.app.dals.DB;->onCreate:57 | API Call: | ||
| Requests potentially dangerous permissions | Show sources | ||
| Source: submitted apk | Request permission: | ||
| Source: submitted apk | Request permission: | ||
| Source: submitted apk | Request permission: | ||
Hooking and other Techniques for Hiding and Protection: |
|---|
| Aborts a broadcast event (this is often done to hide phone events such as incoming SMS) | Show sources | ||
| Source: com.twdlphqg.app.services.Rqdnonjuptjh;->onDisableRequested:2 | API Call: | ||
| Removes its application launcher (likely to stay hidden) | Show sources | ||
| Source: com.twdlphqg.app.ExplorationActivity;->snewxwrivv:174 | API Call: | ||
Antivirus Detection |
|---|
Initial Sample |
|---|
| Source | Ratio | Cloud | Link |
|---|---|---|---|
| twdlphqg_v1.3.5_apkpure.com.apk | 27/61 | virustotal | Browse |
Dropped Files |
|---|
| No Antivirus matches |
|---|
Domains |
|---|
Yara Overview |
|---|
Initial Sample |
|---|
| No yara matches |
|---|
PCAP (Network Traffic) |
|---|
| No yara matches |
|---|
Dropped Files |
|---|
| No yara matches |
|---|
Memory Dumps |
|---|
| No yara matches |
|---|
Screenshot |
|---|
Created / dropped Files |
|---|
| No created / dropped files found |
|---|
Contacted Domains/Contacted IPs |
|---|
Contacted Domains |
|---|
| Name | IP | Active | Malicious | Antivirus Detection |
|---|---|---|---|---|
| maxcdn.bootstrapcdn.com | 94.31.29.55 | true | false | 1/65, virustotal, Browse |
| u.axclick.store | 217.182.173.145 | true | false | 0/65, virustotal, Browse |
| g.axclick.store | 217.182.173.145 | true | false | 1/65, virustotal, Browse |
Contacted IPs |
|---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
| IP | Country | Flag | ASN | ASN Name | Malicious |
|---|---|---|---|---|---|
| 8.8.8.8 | United States | 15169 | GoogleInc | false | |
| 192.168.1.33 | unknown | unknown | unknown | false | |
| 94.31.29.55 | United Kingdom | 17025 | AbovenetCommunicationsInc | false | |
| 217.182.173.145 | United Kingdom | 5503 | RMEducationPLC | false |
Static File Info |
|---|
General | |
|---|---|
| File type: | |
| TrID: |
|
| File name: | twdlphqg_v1.3.5_apkpure.com.apk |
| File size: | 1070709 |
| MD5: | c3f25252f8bc3361e426564ac2715109 |
| SHA1: | 8e83d2bcf6a11d39acc63c2aa3f71f5950c37a56 |
| SHA256: | 168624d9d9368155b7601e7e488e23ddf1cd0c8ed91a50406484d57d15ac7cc3 |
| SHA512: | 68320d2b18315b0a09c238433721b4e76132cda6d6cefd1295a3aaacfc6d5686ff3874f1b2bebb30ca0ae0139fba65c62d24a94bdf02eda73930620a41d61c2e |
| File Content Preview: | PK.........|.J................AndroidManifest.xml.X]O.W.~g..U@@.*...D......[DE.#`..q..!......4.i.....]....i.....0.h....iz.4M..}......w..yvf.9..~.{..%Jq.~?.C...%z.....x....3.m....|.<...............w.3.G..@...d...O...o....(Q.x...\."..6.g./.o@{.Z......h.F4.| |
File Icon |
|---|
Static APK Info |
|---|
General | |
|---|---|
| Label: | Data Storage |
| Minimum SDK required: | 14 |
| Target SDK required: | 14 |
| Version Code: | 1 |
| Version Name: | 1 |
| Package Name: | com.twdlphqg.app |
| Is Activity: | true |
| Is Receiver: | true |
| Is Service: | true |
| Requests System Level Permissions: | false |
| Play Store Compatible: | true |
Activities |
|---|
| Name | Is Entrypoint |
|---|---|
| com.twdlphqg.appcom.twdlphqg.app.SplashActivity | true |
| com.twdlphqg.appcom.twdlphqg.app.ExplorationActivity | |
| com.twdlphqg.appcom.twdlphqg.app.TrackActivity | |
| com.twdlphqg.appcom.twdlphqg.app.PlayerActivity | |
| com.twdlphqg.appcom.twdlphqg.app.SearchActivity |
Receivers |
|---|
|
|
|
|
Services |
|---|
| |
| |
|
Permission Requested |
|---|
|
|
|
|
|
Certificate |
|---|
| Name: | classes.dex |
| Issuer: | CN=Android,OU=Android,O=Google Inc.,L=Mountain View,ST=California,C=US |
| Subject: | CN=Android,OU=Android,O=Google Inc.,L=Mountain View,ST=California,C=US |
Resources |
|---|
| Name | Type |
|---|---|
| abc_textfield_search_selected_holo_light.9.png | |
| abc_cab_background_bottom_holo_light.9.png | |
| player_fragment_layout.xml | |
| border_top.xml | |
| abc_ic_voice_search_api_holo_light.png | |
| ic_btn_shuffle_pressed.png | |
| seekbar_prg_bg.xml | |
| abc_cab_background_top_holo_dark.9.png | |
| abc_list_pressed_holo_dark.9.png | |
| abc_textfield_search_right_selected_holo_light.9.png | |
| abc_ic_commit_search_api_holo_light.png | |
| abc_ic_ab_back_holo_dark.png | |
| abc_ab_stacked_solid_dark_holo.9.png | |
| abc_search_view.xml | |
| ic_album.png | |
| abc_list_selector_disabled_holo_light.9.png | |
| abc_ic_ab_back_holo_light.png | |
| abc_spinner_ab_disabled_holo_dark.9.png | |
| abc_textfield_searchview_holo_light.xml | |
| abc_menu_dropdown_panel_holo_light.9.png | |
| abc_textfield_search_default_holo_light.9.png | |
| abc_list_divider_holo_light.9.png | |
| abc_spinner_ab_default_holo_light.9.png | |
| abc_menu_hardkey_panel_holo_dark.9.png | |
| abc_ab_bottom_transparent_light_holo.9.png | |
| abc_ab_solid_dark_holo.9.png | |
| splash_layout.xml | |
| abc_textfield_search_right_selected_holo_light.9.png | |
| abc_textfield_search_right_default_holo_dark.9.png | |
| abc_ic_clear_search_api_disabled_holo_light.png | |
| abc_ic_commit_search_api_holo_dark.png | |
| abc_textfield_search_right_default_holo_dark.9.png | |
| abc_ic_clear_search_api_holo_light.png | |
| ic_btn_sound_enabled.png | |
| abc_textfield_search_selected_holo_dark.9.png | |
| img_pr_blue_bg.png | |
| ic_btn_create_playlist.png | |
| resources.arsc | |
| abc_list_selector_disabled_holo_dark.9.png | |
| abc_ic_menu_share_holo_dark.png | |
| abc_action_menu_item_layout.xml | |
| playlist_item_select_layout.xml | |
| abc_ic_menu_moreoverflow_normal_holo_dark.png | |
| abc_ic_search_api_holo_light.png | |
| abc_spinner_ab_pressed_holo_dark.9.png | |
| abc_ic_cab_done_holo_dark.png | |
| abc_ic_voice_search.png | |
| abc_textfield_search_default_holo_dark.9.png | |
| abc_list_focused_holo.9.png | |
| abc_ab_share_pack_holo_light.9.png | |
| ic_back.png | |
| abc_ab_bottom_transparent_light_holo.9.png | |
| abc_ic_commit_search_api_holo_light.png | |
| abc_spinner_ab_focused_holo_light.9.png | |
| abc_spinner_ab_focused_holo_dark.9.png | |
| abc_textfield_search_default_holo_light.9.png | |
| abc_tab_selected_holo.9.png | |
| abc_list_divider_holo_dark.9.png | |
| img_pr_bg.png | |
| abc_tab_selected_pressed_holo.9.png | |
| abc_ab_transparent_light_holo.9.png | |
| abc_spinner_ab_pressed_holo_light.9.png | |
| player_activity_layout.xml | |
| abc_list_selector_background_transition_holo_light.xml | |
| abc_ab_bottom_solid_dark_holo.9.png | |
| abc_ab_stacked_transparent_light_holo.9.png | |
| main_menu.xml | |
| abc_list_pressed_holo_dark.9.png | |
| abc_list_selector_disabled_holo_dark.9.png | |
| abc_tab_selected_pressed_holo.9.png | |
| abc_spinner_ab_default_holo_light.9.png | |
| abc_cab_background_top_holo_dark.9.png | |
| abc_list_focused_holo.9.png | |
| abc_ab_stacked_solid_light_holo.9.png | |
| abc_cab_background_bottom_holo_dark.9.png | |
| abc_cab_background_top_holo_light.9.png | |
| abc_menu_dropdown_panel_holo_light.9.png | |
| abc_ic_clear_normal.png | |
| abc_tab_selected_focused_holo.9.png | |
| abc_spinner_ab_disabled_holo_light.9.png | |
| disc_fragment_layout.xml | |
| abc_list_longpressed_holo.9.png | |
| icon.png | |
| img_pr_fill_bg.png | |
| ic_btn_prev.png | |
| abc_ic_search_api_holo_light.png | |
| abc_ab_transparent_dark_holo.9.png | |
| abc_ab_stacked_solid_light_holo.9.png | |
| abc_textfield_searchview_right_holo_dark.xml | |
| abc_tab_selected_focused_holo.9.png | |
| abc_cab_background_bottom_holo_dark.9.png | |
| abc_tab_indicator_ab_holo.xml | |
| abc_menu_hardkey_panel_holo_light.9.png | |
| track_item_layout.xml | |
| abc_menu_hardkey_panel_holo_dark.9.png | |
| ic_spinner_arrow.png | |
| abc_ic_voice_search_api_holo_light.png | |
| abc_list_divider_holo_dark.9.png | |
| abc_ic_clear.xml | |
| abc_ab_stacked_solid_dark_holo.9.png | |
| abc_ic_voice_search.png | |
| abc_action_bar_home.xml | |
| img_circle.png | |
| abc_ab_transparent_dark_holo.9.png | |
| abc_ic_cab_done_holo_light.png | |
| track_item_select_layout.xml | |
| abc_list_selector_disabled_holo_light.9.png | |
| abc_menu_dropdown_panel_holo_dark.9.png | |
| abc_ab_bottom_solid_light_holo.9.png | |
| playlist_item_layout.xml | |
| abc_ab_stacked_solid_light_holo.9.png | |
| abc_textfield_search_right_default_holo_dark.9.png | |
| GOOGPLAY.RSA | |
| abc_spinner_ab_focused_holo_light.9.png | |
| abc_spinner_ab_default_holo_dark.9.png | |
| abc_action_bar_decor_overlay.xml | |
| abc_tab_unselected_pressed_holo.9.png | |
| abc_ic_clear_normal.png | |
| abc_textfield_search_default_holo_dark.9.png | |
| abc_ic_search.png | |
| abc_spinner_ab_pressed_holo_light.9.png | |
| abc_slide_out_bottom.xml | |
| abc_menu_hardkey_panel_holo_light.9.png | |
| abc_ic_clear_search_api_disabled_holo_light.png | |
| exploration_activity_layout.xml | |
| abc_ab_bottom_transparent_light_holo.9.png | |
| abc_search_dropdown_dark.xml | |
| abc_ic_menu_moreoverflow_normal_holo_dark.png | |
| ic_btn_repeat_pressed.png | |
| abc_spinner_ab_holo_dark.xml | |
| abc_ic_menu_share_holo_light.png | |
| abc_ic_menu_share_holo_light.png | |
| abc_ic_clear_search_api_disabled_holo_light.png | |
| abc_cab_background_top_holo_light.9.png | |
| abc_ic_clear_search_api_holo_light.png | |
| abc_spinner_ab_focused_holo_dark.9.png | |
| abc_list_longpressed_holo.9.png | |
| abc_ab_bottom_transparent_dark_holo.9.png | |
| abc_menu_dropdown_panel_holo_dark.9.png | |
| abc_list_selector_disabled_holo_dark.9.png | |
| abc_activity_chooser_view.xml | |
| abc_list_pressed_holo_light.9.png | |
| abc_ic_clear_disabled.png | |
| abc_spinner_ab_pressed_holo_dark.9.png | |
| abc_cab_background_top_holo_dark.9.png | |
| abc_spinner_ab_disabled_holo_light.9.png | |
| border_bottom.xml | |
| ic_btn_play.png | |
| abc_list_pressed_holo_light.9.png | |
| abc_ic_clear_disabled.png | |
| abc_ic_search_api_holo_light.png | |
| cd.png | |
| ic_download_dark.png | |
| abc_textfield_search_right_selected_holo_dark.9.png | |
| abc_ic_go.png | |
| abc_textfield_search_right_default_holo_light.9.png | |
| abc_action_bar_view_list_nav_layout.xml | |
| abc_ab_solid_dark_holo.9.png | |
| abc_ic_menu_share_holo_light.png | |
| listview_track_in_queue_layout.xml | |
| abc_popup_menu_item_layout.xml | |
| abc_expanded_menu_layout.xml | |
| ic_logo.png | |
| abc_ic_menu_moreoverflow_normal_holo_dark.png | |
| abc_ab_stacked_solid_dark_holo.9.png | |
| abc_action_bar_tabbar.xml | |
| grablines.xml | |
| abc_list_divider_holo_dark.9.png | |
| seekbar_prg.xml | |
| abc_menu_hardkey_panel_holo_light.9.png | |
| abc_textfield_search_right_selected_holo_dark.9.png | |
| abc_ab_stacked_transparent_light_holo.9.png | |
| abc_ab_solid_light_holo.9.png | |
| abc_ic_cab_done_holo_light.png | |
| ic_btn_shuffle.png | |
| abc_ab_stacked_transparent_dark_holo.9.png | |
| abc_textfield_search_selected_holo_light.9.png | |
| abc_spinner_ab_disabled_holo_dark.9.png | |
| rectangle_bg_orange.xml | |
| abc_textfield_search_right_selected_holo_dark.9.png | |
| abc_ic_menu_share_holo_dark.png | |
| abc_textfield_search_right_selected_holo_light.9.png | |
| MANIFEST.MF | |
| abc_search_dropdown_light.xml | |
| abc_action_menu_layout.xml | |
| abc_spinner_ab_default_holo_dark.9.png | |
| abc_activity_chooser_view_list_item.xml | |
| abc_menu_dropdown_panel_holo_dark.9.png | |
| abc_ab_transparent_light_holo.9.png | |
| abc_textfield_search_selected_holo_light.9.png | |
| list_item_pressed.xml | |
| abc_action_bar_decor_include.xml | |
| abc_ic_menu_moreoverflow_normal_holo_light.png | |
| abc_ic_voice_search.png | |
| abc_ic_search.png | |
| abc_ab_bottom_solid_dark_holo.9.png | |
| abc_ab_bottom_solid_light_holo.9.png | |
| abc_menu_hardkey_panel_holo_dark.9.png | |
| abc_ab_transparent_dark_holo.9.png | |
| abc_ab_transparent_light_holo.9.png | |
| track_in_queue_item_layout.xml | |
| abc_textfield_search_selected_holo_dark.9.png | |
| listview_container_layout.xml | |
| abc_ic_go_search_api_holo_light.png | |
| abc_list_selector_holo_light.xml | |
| abc_ab_bottom_solid_dark_holo.9.png | |
| abc_action_bar_decor.xml | |
| btn_repeat.xml | |
| abc_list_selector_background_transition_holo_dark.xml | |
| my_admin | |
| abc_ic_commit_search_api_holo_dark.png | |
| list_item_normal.xml | |
| abc_ab_solid_light_holo.9.png | |
| abc_tab_unselected_pressed_holo.9.png | |
| abc_slide_out_top.xml | |
| AndroidManifest.xml | |
| abc_spinner_ab_disabled_holo_light.9.png | |
| abc_list_focused_holo.9.png | |
| abc_ic_ab_back_holo_dark.png | |
| abc_textfield_search_default_holo_dark.9.png | |
| abc_fade_out.xml | |
| abc_list_pressed_holo_light.9.png | |
| abc_ic_go.png | |
| abc_ic_cab_done_holo_light.png | |
| abc_list_selector_holo_dark.xml | |
| abc_ic_menu_share_holo_dark.png | |
| abc_item_background_holo_light.xml | |
| menu_spinner.xml | |
| ic_small_logo.png | |
| abc_ab_stacked_transparent_dark_holo.9.png | |
| abc_spinner_ab_holo_light.xml | |
| abc_list_selector_disabled_holo_light.9.png | |
| abc_ab_share_pack_holo_dark.9.png | |
| abc_cab_background_bottom_holo_dark.9.png | |
| abc_activity_chooser_view.xml | |
| abc_tab_unselected_pressed_holo.9.png | |
| dropdown_menu_item_layout.xml | |
| abc_textfield_search_right_default_holo_light.9.png | |
| abc_cab_background_bottom_holo_light.9.png | |
| abc_tab_selected_holo.9.png | |
| abc_ab_stacked_transparent_dark_holo.9.png | |
| abc_textfield_searchview_holo_dark.xml | |
| ic_btn_next.png | |
| abc_ab_share_pack_holo_dark.9.png | |
| abc_ic_ab_back_holo_light.png | |
| abc_search_url_text_holo.xml | |
| album_item_layout.xml | |
| abc_list_divider_holo_light.9.png | |
| rectangle_bg_white.xml | |
| abc_item_background_holo_dark.xml | |
| abc_action_bar_decor.xml | |
| abc_textfield_search_right_default_holo_light.9.png | |
| ic_remove.png | |
| ic_btn_search.png | |
| abc_ic_menu_moreoverflow_normal_holo_light.png | |
| abc_tab_selected_holo.9.png | |
| GOOGPLAY.SF | |
| btn_shuffle.xml | |
| abc_ic_voice_search_api_holo_light.png | |
| abc_ic_ab_back_holo_dark.png | |
| abc_ic_commit_search_api_holo_light.png | |
| abc_ab_solid_light_holo.9.png | |
| abc_ic_menu_moreoverflow_normal_holo_light.png | |
| abc_ic_commit_search_api_holo_dark.png | |
| abc_cab_background_bottom_holo_light.9.png | |
| icon.png | |
| no_result_match_fragment.xml | |
| abc_spinner_ab_pressed_holo_light.9.png | |
| abc_slide_in_top.xml | |
| abc_spinner_ab_default_holo_dark.9.png | |
| abc_textfield_search_default_holo_light.9.png | |
| img_btn_thumb_pressed.png | |
| abc_ab_bottom_solid_light_holo.9.png | |
| abc_ic_ab_back_holo_light.png | |
| abc_tab_selected_pressed_holo.9.png | |
| abc_ic_search.png | |
| abc_ic_cab_done_holo_dark.png | |
| abc_spinner_ab_default_holo_light.9.png | |
| abc_list_longpressed_holo.9.png | |
| abc_ab_share_pack_holo_light.9.png | |
| abc_list_menu_item_radio.xml | |
| abc_menu_dropdown_panel_holo_light.9.png | |
| abc_cab_background_top_holo_light.9.png | |
| abc_list_menu_item_layout.xml | |
| abc_activity_chooser_view_include.xml | |
| classes.dex | |
| abc_list_menu_item_icon.xml | |
| artist_item_layout.xml | |
| abc_ab_stacked_transparent_light_holo.9.png | |
| abc_action_bar_title_item.xml | |
| abc_slide_in_bottom.xml | |
| abc_ic_clear_disabled.png | |
| searchable.xml | |
| ic_btn_pause.png | |
| abc_tab_selected_focused_holo.9.png | |
| ic_done.png | |
| abc_action_mode_close_item.xml | |
| ic_drag_drop.png | |
| abc_ic_clear_search_api_holo_light.png | |
| abc_spinner_ab_disabled_holo_dark.9.png | |
| abc_ab_share_pack_holo_light.9.png | |
| abc_action_bar_tab.xml | |
| abc_list_pressed_holo_dark.9.png | |
| abc_fade_in.xml | |
| ic_btn_sound_disabled.png | |
| abc_ab_bottom_transparent_dark_holo.9.png | |
| abc_ic_go.png | |
| seekbar_thumb.xml | |
| abc_ab_share_pack_holo_dark.9.png | |
| abc_textfield_search_selected_holo_dark.9.png | |
| abc_action_mode_bar.xml | |
| abc_ic_clear_holo_light.xml | |
| abc_spinner_ab_pressed_holo_dark.9.png | |
| abc_ic_go_search_api_holo_light.png | |
| ic_btn_repeat.png | |
| abc_ab_solid_dark_holo.9.png | |
| icon.png | |
| list_item.xml | |
| abc_ic_cab_done_holo_dark.png | |
| support_simple_spinner_dropdown_item.xml | |
| abc_list_menu_item_checkbox.xml | |
| abc_spinner_ab_focused_holo_light.9.png | |
| abc_ab_bottom_transparent_dark_holo.9.png | |
| abc_ic_go_search_api_holo_light.png | |
| abc_textfield_searchview_right_holo_light.xml | |
| abc_list_divider_holo_light.9.png | |
| abc_search_dropdown_item_icons_2line.xml | |
| abc_spinner_ab_focused_holo_dark.9.png |
Network Behavior |
|---|
Network Port Distribution |
|---|
TCP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Aug 30, 2017 10:21:12.890083075 CEST | 62131 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:13.073537111 CEST | 53 | 62131 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:36.550931931 CEST | 63130 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:36.751703024 CEST | 53 | 63130 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.153615952 CEST | 58446 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:40.153883934 CEST | 32941 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:40.597537994 CEST | 53 | 58446 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.598257065 CEST | 32899 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.598308086 CEST | 80 | 32899 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.598459005 CEST | 32899 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.599170923 CEST | 32899 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.599190950 CEST | 80 | 32899 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.743299961 CEST | 80 | 32899 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.743499041 CEST | 32899 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.759881973 CEST | 53 | 32941 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.760739088 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.760791063 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.760966063 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.761221886 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.761248112 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.858774900 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.858802080 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.858812094 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.859086037 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.859194994 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.859266996 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:40.864069939 CEST | 24587 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:40.867607117 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.867774010 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:41.094245911 CEST | 53 | 24587 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.094954967 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.094995975 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.095105886 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.095318079 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.095336914 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.169394016 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.169420958 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.169430971 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.169554949 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.169600964 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.169625998 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.180346012 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.180372000 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.180382013 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.180701017 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.180777073 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.180803061 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.198409081 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.198457956 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.198617935 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.198895931 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.198920965 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.264858961 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.264893055 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.264903069 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.265100956 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.265221119 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.265264988 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.267985106 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.268007994 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.268017054 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.268212080 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.268280029 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.268320084 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.268683910 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.268709898 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.268718958 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.268835068 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.268945932 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.268987894 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.273091078 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.273349047 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.279589891 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.279618025 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.279627085 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.279747963 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.279784918 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.279805899 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.280366898 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.280489922 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.287971973 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.287997961 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.288007021 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.288228035 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.288296938 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.288319111 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.294810057 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.294836044 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.294845104 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.295068979 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.295137882 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.295193911 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.296328068 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.296354055 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.296364069 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.296463013 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.296514988 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.296540976 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.297086954 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.297113895 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.297123909 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.297251940 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.297302961 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.297327995 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.303605080 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.303771019 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.306912899 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.306940079 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.306948900 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.307085991 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.307136059 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.307163954 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.317044973 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.317071915 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.317081928 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.317322016 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.317393064 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.317434072 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.319441080 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.319463968 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.319473028 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.319593906 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.319641113 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.319668055 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.327393055 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.327423096 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.327431917 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.327619076 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.327682018 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.327714920 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.332631111 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.332823992 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.334161997 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.334196091 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.334209919 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.334407091 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.334472895 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.334511995 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.336220980 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.336247921 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.336257935 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.336427927 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.336527109 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.336569071 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.347393036 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.347419977 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:41.347610950 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:41.347656012 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:45.157593012 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:45.197510004 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:45.254983902 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:45.293966055 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:50.748831987 CEST | 47928 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:50.748887062 CEST | 80 | 47928 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:50.749053001 CEST | 47929 | 80 | 192.168.1.33 | 94.31.29.55 |
| Aug 30, 2017 10:21:50.749072075 CEST | 80 | 47929 | 94.31.29.55 | 192.168.1.33 |
| Aug 30, 2017 10:21:56.649662971 CEST | 80 | 32899 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:56.689429045 CEST | 32899 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:21:56.837873936 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:21:56.877732992 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:22:00.751218081 CEST | 32899 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:22:00.751271963 CEST | 80 | 32899 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:22:00.751478910 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:22:00.751507044 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:22:13.078027964 CEST | 3756 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:22:13.405678988 CEST | 53 | 3756 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:22:25.013155937 CEST | 45150 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:22:25.409647942 CEST | 53 | 45150 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:22:39.952056885 CEST | 32903 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:22:39.952111006 CEST | 80 | 32903 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:22:39.952291965 CEST | 32903 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:22:39.952552080 CEST | 32903 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:22:39.952577114 CEST | 80 | 32903 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:22:40.120572090 CEST | 80 | 32903 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:22:40.120845079 CEST | 32903 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:22:56.044962883 CEST | 80 | 32903 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:22:56.084404945 CEST | 32903 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:23:00.123718023 CEST | 32903 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:23:00.123779058 CEST | 80 | 32903 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:23:39.966622114 CEST | 31076 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:23:40.570669889 CEST | 53 | 31076 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:23:40.571633101 CEST | 32904 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:23:40.571693897 CEST | 80 | 32904 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:23:40.571927071 CEST | 32904 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:23:40.572314978 CEST | 32904 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:23:40.572355032 CEST | 80 | 32904 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:23:40.731384039 CEST | 80 | 32904 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:23:40.731636047 CEST | 32904 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:23:42.951776981 CEST | 21462 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:23:42.953385115 CEST | 21930 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:23:43.210469007 CEST | 53 | 21462 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:23:43.268342972 CEST | 53 | 21930 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:23:56.655842066 CEST | 80 | 32904 | 217.182.173.145 | 192.168.1.33 |
| Aug 30, 2017 10:23:56.695504904 CEST | 32904 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:24:00.735451937 CEST | 32904 | 80 | 192.168.1.33 | 217.182.173.145 |
| Aug 30, 2017 10:24:00.735510111 CEST | 80 | 32904 | 217.182.173.145 | 192.168.1.33 |
UDP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP |
|---|---|---|---|---|
| Aug 30, 2017 10:21:12.890083075 CEST | 62131 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:13.073537111 CEST | 53 | 62131 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:36.550931931 CEST | 63130 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:36.751703024 CEST | 53 | 63130 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.153615952 CEST | 58446 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:40.153883934 CEST | 32941 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:40.597537994 CEST | 53 | 58446 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.759881973 CEST | 53 | 32941 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:21:40.864069939 CEST | 24587 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:21:41.094245911 CEST | 53 | 24587 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:22:13.078027964 CEST | 3756 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:22:13.405678988 CEST | 53 | 3756 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:22:25.013155937 CEST | 45150 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:22:25.409647942 CEST | 53 | 45150 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:23:39.966622114 CEST | 31076 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:23:40.570669889 CEST | 53 | 31076 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:23:42.951776981 CEST | 21462 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:23:42.953385115 CEST | 21930 | 53 | 192.168.1.33 | 8.8.8.8 |
| Aug 30, 2017 10:23:43.210469007 CEST | 53 | 21462 | 8.8.8.8 | 192.168.1.33 |
| Aug 30, 2017 10:23:43.268342972 CEST | 53 | 21930 | 8.8.8.8 | 192.168.1.33 |
DNS Queries |
|---|
| Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
|---|---|---|---|---|---|---|---|
| Aug 30, 2017 10:21:40.153615952 CEST | 192.168.1.33 | 8.8.8.8 | 0x2cb2 | Standard query (0) | g.axclick.store | A (IP address) | IN (0x0001) |
| Aug 30, 2017 10:21:40.153883934 CEST | 192.168.1.33 | 8.8.8.8 | 0x11e6 | Standard query (0) | u.axclick.store | A (IP address) | IN (0x0001) |
| Aug 30, 2017 10:21:40.864069939 CEST | 192.168.1.33 | 8.8.8.8 | 0x6314 | Standard query (0) | maxcdn.bootstrapcdn.com | A (IP address) | IN (0x0001) |
| Aug 30, 2017 10:23:39.966622114 CEST | 192.168.1.33 | 8.8.8.8 | 0x6044 | Standard query (0) | g.axclick.store | A (IP address) | IN (0x0001) |
DNS Answers |
|---|
| Timestamp | Source IP | Dest IP | Trans ID | Replay Code | Name | CName | Address | Type | Class |
|---|---|---|---|---|---|---|---|---|---|
| Aug 30, 2017 10:21:40.597537994 CEST | 8.8.8.8 | 192.168.1.33 | 0x2cb2 | No error (0) | g.axclick.store | 217.182.173.145 | A (IP address) | IN (0x0001) | |
| Aug 30, 2017 10:21:40.759881973 CEST | 8.8.8.8 | 192.168.1.33 | 0x11e6 | No error (0) | u.axclick.store | 217.182.173.145 | A (IP address) | IN (0x0001) | |
| Aug 30, 2017 10:21:41.094245911 CEST | 8.8.8.8 | 192.168.1.33 | 0x6314 | No error (0) | maxcdn.bootstrapcdn.com | 94.31.29.55 | A (IP address) | IN (0x0001) | |
| Aug 30, 2017 10:23:40.570669889 CEST | 8.8.8.8 | 192.168.1.33 | 0x6044 | No error (0) | g.axclick.store | 217.182.173.145 | A (IP address) | IN (0x0001) |
HTTP Request Dependency Graph |
|---|
|
HTTP Packets |
|---|
| Timestamp | Source Port | Dest Port | Source IP | Dest IP | Header | Total Bytes Transfered (KB) |
|---|---|---|---|---|---|---|
| Aug 30, 2017 10:21:40.599170923 CEST | 32899 | 80 | 192.168.1.33 | 217.182.173.145 | 25 | |
| Aug 30, 2017 10:21:40.743299961 CEST | 80 | 32899 | 217.182.173.145 | 192.168.1.33 | 25 | |
| Aug 30, 2017 10:21:40.761221886 CEST | 32900 | 80 | 192.168.1.33 | 217.182.173.145 | 26 | |
| Aug 30, 2017 10:21:40.858774900 CEST | 80 | 32900 | 217.182.173.145 | 192.168.1.33 |