Windows
Analysis Report
https://u3088939.ct.sendgrid.net/wf/open?upn=W77bTy6YRdHySgTK0Dy8RbHqJwtyg-2BYTVM42y7jOG-2FbzsiP3cYMZkliOaIs0ylEhwg4OlrakjbJ9U7Z6XHBrSGAG87jIcSw9Cs-2FWQVPhOoR44UNUqh30-2BaINtfiYSqnqgo74h720y5xQL6Bm9luNAxZzs5TztEKylD-2FQxmHa1wNCna9XAtJosub6MCOxoKtCRJS6F0U12fgowNtpSq0Pg-2FeyIf98QM3seavUMAGQR9k9iBhpJ0o
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5272 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA) chrome.exe (PID: 4892 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1936 --fi eld-trial- handle=187 6,i,507974 2507888510 088,920294 8063604146 20,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction /pre fetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
chrome.exe (PID: 6312 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://u30889 39.ct.send grid.net/w f/open?upn =W77bTy6YR dHySgTK0Dy 8RbHqJwtyg -2BYTVM42y 7jOG-2Fbzs iP3cYMZkli OaIs0ylEhw g4OlrakjbJ 9U7Z6XHBrS GAG87jIcSw 9Cs-2FWQVP hOoR44UNUq h30-2BaINt fiYSqnqgo7 4h720y5xQL 6Bm9luNAxZ zs5TztEKyl D-2FQxmHa1 wNCna9XAtJ osub6MCOxo KtCRJS6F0U 12fgowNtpS q0Pg-2FeyI f98QM3seav UMAGQR9k9i BhpJ0oThca 0wzj3nOrQq 140GAVkYcZ xsxHGxkr8d TWyJEac55F 01Gc-2BDxD K-2FgW1zi6 NWoSUb4LRB 38PilnhiTD bZgOYaJSqz WJpXYgcqw- 3D-3D MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 2 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 4 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 5 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 3 Ingress Tool Transfer | SIM Card Swap | Carrier Billing Fraud |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
u3088939.ct.sendgrid.net | 167.89.115.54 | true | false | high | |
accounts.google.com | 142.251.36.237 | true | false | high | |
www.google.com | 142.251.37.4 | true | false | high | |
clients.l.google.com | 172.217.16.174 | true | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.251.37.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.36.237 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
172.217.16.174 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
167.89.115.54 | u3088939.ct.sendgrid.net | United States | 11377 | SENDGRIDUS | false |
IP |
---|
192.168.2.1 |
Joe Sandbox Version: | 38.0.0 Beryl |
Analysis ID: | 1301130 |
Start date and time: | 2023-08-31 16:35:37 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 4m 24s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://u3088939.ct.sendgrid.net/wf/open?upn=W77bTy6YRdHySgTK0Dy8RbHqJwtyg-2BYTVM42y7jOG-2FbzsiP3cYMZkliOaIs0ylEhwg4OlrakjbJ9U7Z6XHBrSGAG87jIcSw9Cs-2FWQVPhOoR44UNUqh30-2BaINtfiYSqnqgo74h720y5xQL6Bm9luNAxZzs5TztEKylD-2FQxmHa1wNCna9XAtJosub6MCOxoKtCRJS6F0U12fgowNtpSq0Pg-2FeyIf98QM3seavUMAGQR9k9iBhpJ0oThca0wzj3nOrQq140GAVkYcZxsxHGxkr8dTWyJEac55F01Gc-2BDxDK-2FgW1zi6NWoSUb4LRB38PilnhiTDbZgOYaJSqzWJpXYgcqw-3D-3D |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@24/6@10/6 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, B ackgroundTransferHost.exe, WMI ADAP.exe, backgroundTaskHost.e xe, conhost.exe, svchost.exe, wuapihost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.37.3, 34.1 04.35.123, 172.217.16.163 - Excluded domains from analysis
(whitelisted): www.bing.com, ris.api.iris.microsoft.com, cl ient.wns.windows.com, edgedl.m e.gvt1.com, eudb.ris.api.iris. microsoft.com, update.googleap is.com, tse1.mm.bing.net, clie ntservices.googleapis.com, dis playcatalog.mp.microsoft.com, g.bing.com, arc.msn.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: https:
//u3088939.ct.sendgrid.net/wf/ open?upn=W77bTy6YRdHySgTK0Dy8R bHqJwtyg-2BYTVM42y7jOG-2FbzsiP 3cYMZkliOaIs0ylEhwg4OlrakjbJ9U 7Z6XHBrSGAG87jIcSw9Cs-2FWQVPhO oR44UNUqh30-2BaINtfiYSqnqgo74h 720y5xQL6Bm9luNAxZzs5TztEKylD- 2FQxmHa1wNCna9XAtJosub6MCOxoKt CRJS6F0U12fgowNtpSq0Pg-2FeyIf9 8QM3seavUMAGQR9k9iBhpJ0oThca0w zj3nOrQq140GAVkYcZxsxHGxkr8dTW yJEac55F01Gc-2BDxDK-2FgW1zi6NW oSUb4LRB38PilnhiTDbZgOYaJSqzWJ pXYgcqw-3D-3D
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1558 |
Entropy (8bit): | 5.11458514637545 |
Encrypted: | false |
SSDEEP: | 48:OBOCrYJ4rYJVwUCLHDy43HV713XEyMmZ3teTHn:LCrYJ4rYJVwUCHZ3Z13XtdUTH |
MD5: | EE002CB9E51BB8DFA89640A406A1090A |
SHA1: | 49EE3AD535947D8821FFDEB67FFC9BC37D1EBBB2 |
SHA-256: | 3DBD2C90050B652D63656481C3E5871C52261575292DB77D4EA63419F187A55B |
SHA-512: | D1FDCC436B8CA8C68D4DC7077F84F803A535BF2CE31D9EB5D0C466B62D6567B2C59974995060403ED757E92245DB07E70C6BDDBF1C3519FED300CC5B9BF9177C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1864 |
Entropy (8bit): | 6.0097580246970255 |
Encrypted: | false |
SSDEEP: | 24:pZRj/flTUyviYXcVmdt2qQO7aoX910U2pfsrTdGqZJ6IFFW4GhlXVKCoXh54ivJH:p/hUyXcAdtB7akgmdGqZsr9xVNkn4qH |
MD5: | 73AF75C733732B6BB9061865EC399680 |
SHA1: | 3FD5201E38F6083C209DBB96444D4CAB7E26828D |
SHA-256: | 5B2F66CA8E72FFA14759B36A3BDB3895A2F6D969097DB963A0952EA3EF3CE3E4 |
SHA-512: | BD645A1BB3125F006C1DA217497B64CF3D0FBBC7AA5994C9E78CBC0072988FEFE1DB595F1EF8346026CE4F21BA37536034E55DCD8315D561EB937E4B7B41C722 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3785 |
Entropy (8bit): | 5.974743905313121 |
Encrypted: | false |
SSDEEP: | 48:YDsaFVa7X+LaC8MRxFp9PCCJEMYhWYEWCi60PKEy/++taBDETAo7Usjcs3CFOL3h:UDyr+m0plhYvPuW+ozdswsDm4+y |
MD5: | 38C9D9117A37DFEA8C736FC669A7B6AC |
SHA1: | AEBC91479698F490F664C6B0AD7CE7CD3FDE2BDC |
SHA-256: | E7EA6CC2F11BB83068D18B955AF4F04D40032B8461C7CED05589DD3C52B24E77 |
SHA-512: | A171B4786DFF6A37506303C2BAF7A328FEEF839E58EC1D5DC431AE870B425A8838A30B3C50D4C59151534F98664C7077E36C57CE4BB480D9F2166C7429C681CE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66 |
Entropy (8bit): | 3.8352052955277816 |
Encrypted: | false |
SSDEEP: | 3:SWwdVYyW1KGnufTHVFRRobc:SWwdCyjGCzVFRZ |
MD5: | 1EF857009060A0AA6E199F0CF52E24F7 |
SHA1: | C532600F397886846022CD2A3FAC12BE6690CC46 |
SHA-256: | CB756BFED1B325C41523CC3DABB0350AFCB09FC6325B15256B876FC2ED59F923 |
SHA-512: | F2A092431A97B6343719553F5A4565DD8F711A44A025034F0BC3D00FF04C31FF43FB51D5C4C6043990700AF17F09A2A0A60848B767AA71D58DA74503CE5BC104 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 79 |
Entropy (8bit): | 4.452488350381251 |
Encrypted: | false |
SSDEEP: | 3:rR6TAulhFphifFIPgS1CdiPn:F6VlMyPgS1CYP |
MD5: | D02CE1ACD449934ED0ABD524BC3E79B2 |
SHA1: | 8BF5238F11D7A38BCE06CA15230BA68E3511A060 |
SHA-256: | 1956AB2AA1DF52193F5A1D59B0038655EF1888E207ACECABF6220738CBC3A457 |
SHA-512: | 7296ECEEC664B722C658E6C8515DC896F127A29A66CFE4D513774AAC661C9C3D21D0F5ECB0B6221B57D335000BC908B9A4D61AA7D5F2529D3DFF3A881E8B7DBD |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 564 |
Entropy (8bit): | 4.72971822420855 |
Encrypted: | false |
SSDEEP: | 12:TjeRHdHiHZdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH988DTPTPTPTPTPTc |
MD5: | 8E325DC2FEA7C8900FC6C4B8C6C394FE |
SHA1: | 1B3291D4EEA179C84145B2814CB53E6A506EC201 |
SHA-256: | 0B52C5338AF355699530A47683420E48C7344E779D3E815FF9943CBFDC153CF2 |
SHA-512: | 084C608F1F860FB08EF03B155658EA9988B3628D3C0F0E9561FDFF930E5912004CDDBCC43B1FA90C21FE7F5A481AC47C64B8CAA066C2BDF3CF533E152BF96C14 |
Malicious: | false |
Reputation: | low |
URL: | https://u3088939.ct.sendgrid.net/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 71
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 31, 2023 16:36:35.850105047 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.850157976 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:35.850222111 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.850826025 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:35.850852966 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:35.850907087 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:35.851375103 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:35.851397991 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:35.851774931 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.851795912 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:35.979470968 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:35.979501009 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:35.979851961 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.979912043 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:35.979943991 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:35.979960918 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:35.980473042 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:35.980556965 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.981652021 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:35.981657028 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:35.981741905 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.982980967 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:35.982980967 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:35.983095884 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:35.984110117 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:35.984148979 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:35.984307051 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.984412909 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:35.984483004 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:35.984507084 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:36.022181034 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:36.022372007 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:36.022418976 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:36.022453070 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:36.022527933 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:36.023838043 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:36.030204058 CEST | 49724 | 443 | 192.168.2.3 | 172.217.16.174 |
Aug 31, 2023 16:36:36.030255079 CEST | 443 | 49724 | 172.217.16.174 | 192.168.2.3 |
Aug 31, 2023 16:36:36.088237047 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:36.088517904 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:36.088634014 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:36.089533091 CEST | 49725 | 443 | 192.168.2.3 | 142.251.36.237 |
Aug 31, 2023 16:36:36.089566946 CEST | 443 | 49725 | 142.251.36.237 | 192.168.2.3 |
Aug 31, 2023 16:36:36.958439112 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:36.958534956 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:36.958641052 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:36.958817959 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:36.958878994 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:36.958957911 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:36.959093094 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:36.959124088 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:36.959352016 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:36.959372044 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.318023920 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.318439007 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.318470955 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.319941044 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.320025921 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.320204020 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.321221113 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.321260929 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.322462082 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.322539091 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.575056076 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.575314999 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.575334072 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.575635910 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.576204062 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.576395035 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.617265940 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.617297888 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.621262074 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.621277094 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.658269882 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.661238909 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.839893103 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.840127945 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.840231895 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.841555119 CEST | 49727 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:37.841571093 CEST | 443 | 49727 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:37.972929001 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:38.015486956 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:38.234606981 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:38.234721899 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:38.234778881 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:38.242561102 CEST | 49728 | 443 | 192.168.2.3 | 167.89.115.54 |
Aug 31, 2023 16:36:38.242589951 CEST | 443 | 49728 | 167.89.115.54 | 192.168.2.3 |
Aug 31, 2023 16:36:39.647110939 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:39.647177935 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:39.647264004 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:39.647855043 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:39.647878885 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:39.728482962 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:39.760312080 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:39.760413885 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:39.763709068 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:39.763828039 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:39.786232948 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:39.786679983 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:39.833417892 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:39.833498001 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:39.880295992 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:49.706353903 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:49.706506968 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:36:49.706667900 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:50.007858992 CEST | 49730 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:36:50.007924080 CEST | 443 | 49730 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:40.056170940 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:40.056260109 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:40.056365967 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:40.056839943 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:40.056881905 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:40.115324020 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:40.116034031 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:40.116123915 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:40.117448092 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:40.118069887 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:40.118285894 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:40.165807009 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:50.156420946 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:50.156603098 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Aug 31, 2023 16:37:50.156783104 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:50.243112087 CEST | 49772 | 443 | 192.168.2.3 | 142.251.37.4 |
Aug 31, 2023 16:37:50.243179083 CEST | 443 | 49772 | 142.251.37.4 | 192.168.2.3 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 31, 2023 16:36:35.803489923 CEST | 59489 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:35.803884983 CEST | 51739 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:35.804428101 CEST | 63604 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:35.804819107 CEST | 60000 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:35.833550930 CEST | 53 | 60000 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:35.838768959 CEST | 53 | 59489 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:35.846821070 CEST | 53 | 63604 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:35.849109888 CEST | 53 | 62054 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:35.850521088 CEST | 53 | 51739 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:36.191431999 CEST | 53 | 61636 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:36.918971062 CEST | 57045 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:36.919684887 CEST | 51854 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:36.947712898 CEST | 53 | 51854 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:36.948548079 CEST | 53 | 57045 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:39.623410940 CEST | 52097 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:39.623681068 CEST | 61084 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:36:39.638778925 CEST | 53 | 52097 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:36:39.647463083 CEST | 53 | 61084 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:37:34.940340996 CEST | 53 | 62200 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:37:40.015747070 CEST | 53073 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:37:40.016278982 CEST | 51904 | 53 | 192.168.2.3 | 8.8.8.8 |
Aug 31, 2023 16:37:40.031408072 CEST | 53 | 51904 | 8.8.8.8 | 192.168.2.3 |
Aug 31, 2023 16:37:40.040072918 CEST | 53 | 53073 | 8.8.8.8 | 192.168.2.3 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Aug 31, 2023 16:36:35.849198103 CEST | 192.168.2.3 | 8.8.8.8 | d039 | (Port unreachable) | Destination Unreachable |
Aug 31, 2023 16:36:39.647542953 CEST | 192.168.2.3 | 8.8.8.8 | d00a | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 31, 2023 16:36:35.803489923 CEST | 192.168.2.3 | 8.8.8.8 | 0x2c2c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 31, 2023 16:36:35.803884983 CEST | 192.168.2.3 | 8.8.8.8 | 0x11d1 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 31, 2023 16:36:35.804428101 CEST | 192.168.2.3 | 8.8.8.8 | 0xd319 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 31, 2023 16:36:35.804819107 CEST | 192.168.2.3 | 8.8.8.8 | 0x444f | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 31, 2023 16:36:36.918971062 CEST | 192.168.2.3 | 8.8.8.8 | 0x8e33 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 31, 2023 16:36:36.919684887 CEST | 192.168.2.3 | 8.8.8.8 | 0x3eb3 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 31, 2023 16:36:39.623410940 CEST | 192.168.2.3 | 8.8.8.8 | 0xaee2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 31, 2023 16:36:39.623681068 CEST | 192.168.2.3 | 8.8.8.8 | 0x793e | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 31, 2023 16:37:40.015747070 CEST | 192.168.2.3 | 8.8.8.8 | 0xcd52 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 31, 2023 16:37:40.016278982 CEST | 192.168.2.3 | 8.8.8.8 | 0xee6b | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 31, 2023 16:36:35.838768959 CEST | 8.8.8.8 | 192.168.2.3 | 0x2c2c | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:35.838768959 CEST | 8.8.8.8 | 192.168.2.3 | 0x2c2c | No error (0) | 172.217.16.174 | A (IP address) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:35.846821070 CEST | 8.8.8.8 | 192.168.2.3 | 0xd319 | No error (0) | 142.251.36.237 | A (IP address) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:35.850521088 CEST | 8.8.8.8 | 192.168.2.3 | 0x11d1 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:36.948548079 CEST | 8.8.8.8 | 192.168.2.3 | 0x8e33 | No error (0) | 167.89.115.54 | A (IP address) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:36.948548079 CEST | 8.8.8.8 | 192.168.2.3 | 0x8e33 | No error (0) | 167.89.118.28 | A (IP address) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:36.948548079 CEST | 8.8.8.8 | 192.168.2.3 | 0x8e33 | No error (0) | 167.89.115.121 | A (IP address) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:36.948548079 CEST | 8.8.8.8 | 192.168.2.3 | 0x8e33 | No error (0) | 167.89.118.35 | A (IP address) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:39.638778925 CEST | 8.8.8.8 | 192.168.2.3 | 0xaee2 | No error (0) | 142.251.37.4 | A (IP address) | IN (0x0001) | false | ||
Aug 31, 2023 16:36:39.647463083 CEST | 8.8.8.8 | 192.168.2.3 | 0x793e | No error (0) | 65 | IN (0x0001) | false | |||
Aug 31, 2023 16:37:40.031408072 CEST | 8.8.8.8 | 192.168.2.3 | 0xee6b | No error (0) | 65 | IN (0x0001) | false | |||
Aug 31, 2023 16:37:40.040072918 CEST | 8.8.8.8 | 192.168.2.3 | 0xcd52 | No error (0) | 142.251.37.4 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.3 | 49725 | 142.251.36.237 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-08-31 14:36:35 UTC | 0 | OUT | |
2023-08-31 14:36:35 UTC | 0 | OUT | |
2023-08-31 14:36:36 UTC | 3 | IN | |
2023-08-31 14:36:36 UTC | 4 | IN | |
2023-08-31 14:36:36 UTC | 4 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.3 | 49724 | 172.217.16.174 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-08-31 14:36:35 UTC | 0 | OUT | |
2023-08-31 14:36:36 UTC | 1 | IN | |
2023-08-31 14:36:36 UTC | 2 | IN | |
2023-08-31 14:36:36 UTC | 2 | IN | |
2023-08-31 14:36:36 UTC | 3 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.3 | 49727 | 167.89.115.54 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-08-31 14:36:37 UTC | 4 | OUT | |
2023-08-31 14:36:37 UTC | 5 | IN | |
2023-08-31 14:36:37 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.3 | 49728 | 167.89.115.54 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-08-31 14:36:37 UTC | 5 | OUT | |
2023-08-31 14:36:38 UTC | 6 | IN | |
2023-08-31 14:36:38 UTC | 7 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 16:36:32 |
Start date: | 31/08/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67bb30000 |
File size: | 3'219'224 bytes |
MD5 hash: | 8D1C4713ACB7CC2AAAEE4477C58A80BA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 16:36:33 |
Start date: | 31/08/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67bb30000 |
File size: | 3'219'224 bytes |
MD5 hash: | 8D1C4713ACB7CC2AAAEE4477C58A80BA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 16:36:35 |
Start date: | 31/08/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67bb30000 |
File size: | 3'219'224 bytes |
MD5 hash: | 8D1C4713ACB7CC2AAAEE4477C58A80BA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |