Windows
Analysis Report
https://go.microsoft.com/fwlink/p/?linkid=857875
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w7x64
chrome.exe (PID: 3068 cmdline:
C:\Program Files (x8 6)\Google\ Chrome\App lication\c hrome.exe" --start-m aximized " about:blan k MD5: FFA2B8E17F645BCC20F0E0201FEF83ED) chrome.exe (PID: 1204 cmdline:
"C:\Progra m Files (x 86)\Google \Chrome\Ap plication\ chrome.exe " --type=u tility --u tility-sub -type=netw ork.mojom. NetworkSer vice --lan g=en-US -- service-sa ndbox-type =none --mo jo-platfor m-channel- handle=136 4 --field- trial-hand le=1240,i, 3538607393 442434681, 1107165727 6984323700 ,131072 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion /prefe tch:8 MD5: FFA2B8E17F645BCC20F0E0201FEF83ED)
chrome.exe (PID: 1520 cmdline:
C:\Program Files (x8 6)\Google\ Chrome\App lication\c hrome.exe" "https:// go.microso ft.com/fwl ink/p/?lin kid=857875 MD5: FFA2B8E17F645BCC20F0E0201FEF83ED)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Window detected: |
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior | ||
Source: | Directory created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 2 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 1 Ingress Tool Transfer | SIM Card Swap | Carrier Billing Fraud |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.251.2.84 | true | false | high | |
www.google.com | 142.251.2.99 | true | false | high | |
part-0043.t-0009.t-msedge.net | 13.107.246.71 | true | false | unknown | |
clients.l.google.com | 142.251.2.100 | true | false | high | |
js.monitor.azure.com | unknown | unknown | false | high | |
c.s-microsoft.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high | |
assets.onestore.ms | unknown | unknown | false | unknown | |
www.w3.org | unknown | unknown | false | high | |
i.s-microsoft.com | unknown | unknown | false | high | |
ajax.aspnetcdn.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | low | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.251.2.99 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.251.2.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
13.107.246.71 | part-0043.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.2.100 | clients.l.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
192.168.2.5 |
192.168.2.23 |
Joe Sandbox Version: | 38.0.0 Beryl |
Analysis ID: | 1305570 |
Start date and time: | 2023-09-07 19:06:56 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 9m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://go.microsoft.com/fwlink/p/?linkid=857875 |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 4 |
Number of new started drivers analysed: | 2 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@27/28@20/8 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): vga.dll, WMIADA P.exe - Excluded IPs from analysis (wh
itelisted): 67.27.3.254, 8.240 .193.254, 8.249.47.254, 8.253. 130.254, 8.249.49.254, 72.21.8 1.240, 142.251.2.94, 34.104.35 .123, 104.124.157.216, 23.36.1 18.31, 152.199.4.33, 23.55.249 .185, 104.124.157.96, 23.206.1 88.204, 23.206.188.212, 142.25 0.141.94, 52.171.212.228, 104. 18.23.19, 104.18.22.19, 13.69. 116.104 - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtCreateFile calls fou nd. - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: https:
//go.microsoft.com/fwlink/p/?l inkid=857875
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4054 |
Entropy (8bit): | 7.797012573497454 |
Encrypted: | false |
SSDEEP: | 48:zICvnyRHJ3BRZPcSPQ72N2xoiR4fTJX/rj4sFNMkk5/p1k2lPUmbm39o4aL7V9XH:10nvE724xoiRQJPrjpLKSFl9oX31Z1d |
MD5: | 9F14C20150A003D7CE4DE57C298F0FBA |
SHA1: | DAA53CF17CC45878A1B153F3C3BF47DC9669D78F |
SHA-256: | 112FEC798B78AA02E102A724B5CB1990C0F909BC1D8B7B1FA256EAB41BBC0960 |
SHA-512: | D4F6E49C854E15FE48D6A1F1A03FDA93218AB8FCDB2C443668E7DF478830831ACC2B41DAEFC25ED38FCC8D96C4401377374FED35C36A5017A11E63C8DAE5C487 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 51806 |
Entropy (8bit): | 5.230787209126987 |
Encrypted: | false |
SSDEEP: | 768:GV8Uysc49kfpCDAKfdyvpiLNlYWRPsNY2mohs2DxNkwLb9fm8nXJci7GN80:GV8Utc49k4DAKlyvpksnmJ |
MD5: | 49FF5EF8938892CCDCE2E9C0A4E3CB98 |
SHA1: | AD54BE134E5BC5CB0C6E173A009B6F57E39A991D |
SHA-256: | 2414D8F939483C16EB7D222EEB03673AE37648E6F5A433890CF304F73CF3E1F2 |
SHA-512: | 35BEBAC375F0072D5DA291521F43F549D5EBBDA28E4C2C086CBE44A860D3FF7A926E9ED3B99A6B5FA5487B844501EFBC7CE2211340E63E5CA2BFA2214BB9A9CC |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/mwf/js/MWF_20230313_66247431/alert/autosuggest/glyph/heading/image/list/pagebehaviors/skiptomain?apiVersion=1.0 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 171312 |
Entropy (8bit): | 5.043680996419841 |
Encrypted: | false |
SSDEEP: | 3072:jzCPZkTP3bDLH0tfRqQ0xtLfj4ZDSIpTt813viY8R1j35Ap7LQZLPPJH7PAbOCxx:jlZAW9kJeq8 |
MD5: | 21D2E4BC29CC9BA690164F896A04C2F3 |
SHA1: | B07F66E6B50916D4A636C2E91F633AC8F63E5B5D |
SHA-256: | 47E77D470102641070B066A5A73C34DBD14989F55A3D435EFAE0FDEAAFF3AE6D |
SHA-512: | 8432B3B49C14CE2B2787C99F6B5C9D88CF147EB1308B13E01655B39B3677AFF4010EC8549AB5100D31391DF88A347C58E3B0F22211A48531F418B022B8F9EA11 |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/west-european/shell/_scrf/css/themes=default.device=uplevel_web_pc/79-4cdd0a/33-ae3d41/a5-4bf7a2/13-8e1ceb/81-32f0c0/5c-b7b685/92-14707b/74-888e54?ver=2.0&_cf=02242021_3231 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 137850 |
Entropy (8bit): | 5.224875603440054 |
Encrypted: | false |
SSDEEP: | 3072:1f4HuF7pxnISP0J9d1EwgXA7nKRZMK/7b/:1f4Hu1IgKcb/ |
MD5: | 1A9B16E1A3CE074D6CAB7B6844D49FAD |
SHA1: | 98DB09786AB9B960EE250ADABB301383566F4C1C |
SHA-256: | D794F9BD321156A2A2BB02102AD0BDC09BDC8DEDF71EC42683FA53C3725FDD72 |
SHA-512: | 71A5CBB0B5C11EC80FE0D3AD751C3E7DD0B1FADF641F8C51A8C617048B6CCD80993018DCA2E4EAC28A2246725C326634EAB165D6F3E9EB531AEDC3F18FA8BA9A |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/shell/_scrf/js/themes=default/8e-e88b64/82-2a4f02/49-a00ab0/92-02e55d/7c-dcea75/75-fca72d/ed-e77ee7/d5-bf34c0/a9-078595/7a-7ea8cc/2d-40bdad/23-e8cd2b/96-eb5423/e6-6b0cce/d1-98d78a/c6-082272/a7-f7a340/1e-addbef/2e-ca165a/fc-169dd8/8e-60935c/87-fecbed/96-6ed6eb/c3-eb62e0/ad-ffd6bf/35-621acc/5b-6eff60/b0-07f293/1e-9d9d16/52-f0367f/af-abd754/bf-517249/e1-ed258e/20-0b10e2/6b-0f1117/fb-5e9831/a2-598841?ver=2.0&_cf=02242021_3231&iife=1 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 22904 |
Entropy (8bit): | 7.9904849358693575 |
Encrypted: | true |
SSDEEP: | 384:evl4zAZ+ssqWqPRSKLA4kM0aQfBn9M2+iW50SIPzp6+NPf72UReN2CtbvejX7Ij:YqW+7qHP8n4L0aYn9jFDSmzp6w72Uyvv |
MD5: | C654A623AD90BB3DCD769DBBAC34D863 |
SHA1: | 8719DE38F17D8E4D73E2A5E4E867D63DD3965BAA |
SHA-256: | DEEC787CCA1B9436E080478742A0299E0DB1A9712543A72D2CDC8373FC45A432 |
SHA-512: | B7440CEC44B71BCDBEFCD878A860EE3CC0163DC0905DC688EBCBCD7C6F5CFDFC187EA0C2B6247A362AD462450C34020933DF7825CF6CEAEB3138D65EB944ABAD |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/mwf/_h/v3.54/mwf.app/fonts/mwfmdl2-v3.54.woff2 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 85479 |
Entropy (8bit): | 5.050473954639077 |
Encrypted: | false |
SSDEEP: | 1536:S9zddgYHPbn/hL4fbv3DlFvE6yfsY6Ft6AJL55gGHUkzmEep1ZEuybM56IRgJ4JX:S9zddgYHPbn/hL4fbv3DlFvE6yfsY6FC |
MD5: | BB16419A83DEE6CAEDF3ED9E54EC26F6 |
SHA1: | 29E0F4F1498316FABBD71943837F99457571BE6B |
SHA-256: | 8F19C14D723FD8085332F70855D5144CF68293BB0D54A49FCEF4A39E3D6FB2DD |
SHA-512: | 2106594657F07D19EEF47A58CD6AB308DC07BA5A29F0EFB8DD7FA8EBE014F0197DFA7D1406C52340AABE25D451473FC3959214BB4376683EE9000C3C9B90D452 |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/west-european/concern/_scrf/css/themes=default.device=uplevel_web_pc_webkit_chrome/92-14707b/74-888e54?ver=2.0&_cf=02242021_3231 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 95931 |
Entropy (8bit): | 5.394232486761965 |
Encrypted: | false |
SSDEEP: | 1536:5P1vk7i6GUHdXXeyQazBu+4HhiO2AEeLNFoqqhJ7SerN5sVI6xcBgPv7E+nzms9d:A4Ud4qhJvNPqcB47MfWWca98HrB |
MD5: | 5790EAD7AD3BA27397AEDFA3D263B867 |
SHA1: | 8130544C215FE5D1EC081D83461BF4A711E74882 |
SHA-256: | 2ECD295D295BEC062CEDEBE177E54B9D6B19FC0A841DC5C178C654C9CCFF09C0 |
SHA-512: | 781ACEDC99DE4CE8D53D9B43A158C645EAB1B23DFDFD6B57B3C442B11ACC4A344E0D5B0067D4B78BB173ABBDED75FB91C410F2B5A58F71D438AA6266D048D98A |
Malicious: | false |
Reputation: | low |
URL: | https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.11.2.min.js |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1245 |
Entropy (8bit): | 5.037356170002841 |
Encrypted: | false |
SSDEEP: | 24:Ekd1Tk97hn5ZoK2kTL01MCJZ4ZVaeao1DphsILHJNM2WXgEXgf0Xgm:9da7d5d8pJZ4+BWIIPLQ73/ |
MD5: | 108A4DAFB6208F11604033C769DD54DE |
SHA1: | C636880762B6EF08C858AADF0B0423B3375C4D18 |
SHA-256: | B45282310AA60BE4271B36993FF203791B9FD961F1C59B6D59E02E8A2082EE38 |
SHA-512: | 2284518E03CD266F7F4CC0FCF78EE86ABED4D7B118296A258807176697E0336E7287840406A64B067DFA0BE1F61FCC175E43906621AA51290DB174F7DAE2B906 |
Malicious: | false |
Reputation: | low |
URL: | https://c.s-microsoft.com/en-us/CMSStyles/style.csx?k=b38e7b38-f2bd-90bd-16b5-45a457a50550 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 31463 |
Entropy (8bit): | 5.335245781249028 |
Encrypted: | false |
SSDEEP: | 384:ekorlyEMfQ8sW5hXDi/iE3adOdoIB4mqdRyedRyNWGyIWGyeoQys05DU7uj5hypb:0o1Di5+OOYbsp0yK3FJ12V2+vr/eoq |
MD5: | 7148585ECACB77E3EC38A7423D557F0A |
SHA1: | 3F4428AB18D492318AEC5AD51D4BD22B67BC3955 |
SHA-256: | 9AF3C8E1B582FEBECEF2A475989DC02902A772CEFAC1896C9BAAAFD218D2CA04 |
SHA-512: | 82E8B4FF7B55C9D7F4AE010ED2FBCA757547A88D2BB52C8C2E01AC416594B5CFD608260844FEA93501BD3C4B289A5EBA69412B2643A2C6BF01602163FF6F5B46 |
Malicious: | false |
Reputation: | low |
URL: | https://c.s-microsoft.com/en-us/CMSScripts/script.jsx?k=08e9f1ba-f4e7-80f5-d4c5-f75b4dc5cf51 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 41280 |
Entropy (8bit): | 7.99148680813376 |
Encrypted: | true |
SSDEEP: | 768:p6DwF7RdgMRl+TIRNdEwkoGy4q0vcZ7xaRefiwsoGuTs1txGTeG:p6DwF7PRl+TkvEYuGZdEefi6GuTo/eN |
MD5: | E8EA6DC81AB52C7D6124E89EBCAC926A |
SHA1: | B7BF79D3D738B06DFE9E567FEEE25D9B983135BB |
SHA-256: | 1EE846986FBF0BFC9F0996F563D748589A32B29AF6A6E444312C5A4DA27504C1 |
SHA-512: | B25A7582B9FB6A146AA927BEBC91D4F34B1820017C75DCC3DAFA8ACE22547579E3AAD82788C89C2F373330F71F970500BCDEE7C520C1A791F374A4E8DD5E3396 |
Malicious: | false |
Reputation: | low |
URL: | https://i.s-microsoft.com/fonts/segoe-ui/west-european/normal/latest.woff |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1534 |
Entropy (8bit): | 5.25269855164452 |
Encrypted: | false |
SSDEEP: | 24:49edFKiu8zm4d0lRWBL4QtNW4FArpNjQfbdSXU0SYKaBbUhDRWPW4VtbP1e1a+z6:rFKcowtntNcpNQjAUFGp4DwPW4HbP1em |
MD5: | DC8E5E64A697718763FB4B52E5E8B07D |
SHA1: | 7F275E3FC0B6CF86C7747F40E445094A7BD5F520 |
SHA-256: | F64CC1D922CEB1BA4F88E672E1514C745AD6E73719C98D923A3BBC451D3702C0 |
SHA-512: | 515DAC713EC278513AD86668DD0179FB8F2F477DD5FE81EFF8D746E3169FD2901C2A8865DEC518C15BF003DD2FA4B0DC1CD725F55E695A5511DC6C6AF7C9F658 |
Malicious: | false |
Reputation: | low |
URL: | https://concernapiv2.trafficmanager.net/Scripts/1DS.js |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4787 |
Entropy (8bit): | 4.892293533582146 |
Encrypted: | false |
SSDEEP: | 48:s1lREbxqN+zGfd1O/dO9/8+4gDFTA1u5mkW+H3PboyTwMrAQYECEd4zWhdrvqUwt:sDIwO/dK3zZ5mkdfVTw3V1uMGCr49ex/ |
MD5: | 8B4017EEFDA57F35D60424185367FF48 |
SHA1: | 8A94A3A058109B8DB42861C68B50CB617D465396 |
SHA-256: | 52A6A5770A4EE39DBFBDF4CADF515EBF95BAE4E6D413F17CCA758BFE2DDA6915 |
SHA-512: | D55B2A7F73A15E3C34AD93C807AA312ADD81B3E40AD4477FDD933845E611F5C844AB36A84D3A7D1FFD9309BF1C7CC23353BCBF24A551F7E6F045E4B4A75C170F |
Malicious: | false |
Reputation: | low |
URL: | https://concernapiv2.trafficmanager.net/api/resource/2/loaderRTFetch |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/favicon.ico?v2 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 82190 |
Entropy (8bit): | 5.036904170769404 |
Encrypted: | false |
SSDEEP: | 1536:tJzwN0CbUTqI34/9w6/Qua+1IGEbjBko230WBYT:vyA |
MD5: | 1F9995AB937AC429A73364B4390FF6E8 |
SHA1: | 81998DCC6407CEB5CEF236AD52B9F2A3A9528D3B |
SHA-256: | 49E5166F40D8586714F86E08AB76A977199DF979357147A0E81980A804151C2A |
SHA-512: | 6669AE352FF46DB734BB8F973D1C0527C3A5EC4119D534AAE4C33F29EFF970168ED5FE200A05D4E1B6A2EC0E090E2207549B926317D489DC7664B0D9C2085465 |
Malicious: | false |
Reputation: | low |
URL: | https://assets.onestore.ms/cdnfiles/onestorerolling-1510-19009/shell/v3/scss/shell.min.css |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 103 |
Entropy (8bit): | 4.1716187943968235 |
Encrypted: | false |
SSDEEP: | 3:GACW0RXxKbFEuFX4MfY1hgSF7nKXl0QgKHJu:SW0xxsFfX820QFpu |
MD5: | 96C5637E1EB8F8F8C34172F2D23EAFC6 |
SHA1: | 2A416F86C3C9E26F9C34BF1F8B1BB5DAA46E86F9 |
SHA-256: | 90B2D35CD5E08370ED20DB81197DD9DA1A4DBB421F71293FD5733EA49EB7B3E1 |
SHA-512: | 4686BA81D38403B2DCFDB0514F1151DF5BF555EB12EA47214FFA2E8EA2BED44348144D6731A01EBA38890B33726A76DFA26822B4233EB59BF12ED58E9EBB86D3 |
Malicious: | false |
Reputation: | low |
URL: | https://privacy.microsoft.com/en-US/updates/pspResource |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 163044 |
Entropy (8bit): | 5.107995640490776 |
Encrypted: | false |
SSDEEP: | 3072:zAwmaEZACGjzyP5kTP3bI0tfYqQ0xtLfj4ZDa813giY8R1j35Ap7zzN1n1JKfNkW:/EZACD |
MD5: | 9697E29A698541207E66222C78784E22 |
SHA1: | 205C587499BF882ACCEF920B1116F92F2866AAB7 |
SHA-256: | 88BCB6753785C13EDF27533A21903D7A2DDB616AE0863774C6C9A709D1690A30 |
SHA-512: | 90AE75260C55F8CBF9541E4780D220FBDB29C9151D24311D6FB69737111E2C5BFE77324EFAFC66B56612AC6AA3C42F01CF0ABF1E2EF05FE949DAB32075D6D59C |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/mwf/css/MWF_20230313_66247431/west-european/default/alert/autosuggest/glyph/heading/image/list/pagebehaviors/skiptomain?apiVersion=1.0&include_base=true |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 33556 |
Entropy (8bit): | 7.986987433752767 |
Encrypted: | false |
SSDEEP: | 768:agf2aMu68W993ufOSHOWuwtfLVebDm6r9j3oqlHH:hf2vuYb3IPHOdaJmp3Dn |
MD5: | 637B1F43DE4B96B9446ADCC107C5F688 |
SHA1: | 3FAD425F0C1CFE8711888CD877E122E5F8D2C15A |
SHA-256: | 0ED2DC761DDF650B9AAB0C366F43DDEA0DB81E13BBE603A21F2BFEF519387CE9 |
SHA-512: | 9B48ED55813F9A372F1E1BE5FEF737B0583E8990B9B0D57A7810EEC5F55D5C9CC55739D3DC3A2851009964C34C82F1D0D9B58EC05A212779667A023DB8804BF5 |
Malicious: | false |
Reputation: | low |
URL: | https://i.s-microsoft.com/fonts/segoe-ui/west-european/light/latest.woff |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 35900 |
Entropy (8bit): | 7.989413276112553 |
Encrypted: | false |
SSDEEP: | 768:d1DM2UJJ9OKKukRdfijklR4f0Ki9NkmeWkujUkTl68TEG4sI:LD7RKKukRdfukKiDq3ITEl |
MD5: | 70C1D43A35B7A48D088D830EA07FCF77 |
SHA1: | 025E0E281139C70C5538E09BFA7927141AF0CC0B |
SHA-256: | 942E5DD201200674506B0DF50C1AFEF021FFF6D5BD7BB7F600DED8617DBCB386 |
SHA-512: | E40B2CEAA1F672891BFF21F7C22A8B473DCF998FDC0A74B3DD1999190BA281C330C871D4BC82F89561E2AD7D97FE3169F33748AD368184BD1B4850941822D921 |
Malicious: | false |
Reputation: | low |
URL: | https://i.s-microsoft.com/fonts/segoe-ui/west-european/semibold/latest.woff |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2576 |
Entropy (8bit): | 7.719832273595377 |
Encrypted: | false |
SSDEEP: | 48:xMfPmA3TmKSBdfEFTIyRVoOpIdlDlkdLT14kjZ9IOy8mF:xOPp3pY9ETo+8l5kdLTKwYOy8a |
MD5: | 3352BC83EC12D2F2E46E66EB0FC20A0E |
SHA1: | 2C128CC55FD417D778E5213E5BFC836EB1D46A8B |
SHA-256: | 93FABDCFD57B85E0401518F827759AC29C7833D3E25E358E70232F86D41C643D |
SHA-512: | 74C4FCCC4D61E57F80E70243DF8536B72BEBBC9E6F3C3A3800E5D8715585D5581858A7B01C564D2BF3E855A18614E05DB654775879C65E5B702B098CAA2664AC |
Malicious: | false |
Reputation: | low |
URL: | https://assets.onestore.ms/cdnfiles/external/oneui/oneui1.16.2/dist/fonts/icons/icons.woff |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4054 |
Entropy (8bit): | 7.797012573497454 |
Encrypted: | false |
SSDEEP: | 48:zICvnyRHJ3BRZPcSPQ72N2xoiR4fTJX/rj4sFNMkk5/p1k2lPUmbm39o4aL7V9XH:10nvE724xoiRQJPrjpLKSFl9oX31Z1d |
MD5: | 9F14C20150A003D7CE4DE57C298F0FBA |
SHA1: | DAA53CF17CC45878A1B153F3C3BF47DC9669D78F |
SHA-256: | 112FEC798B78AA02E102A724B5CB1990C0F909BC1D8B7B1FA256EAB41BBC0960 |
SHA-512: | D4F6E49C854E15FE48D6A1F1A03FDA93218AB8FCDB2C443668E7DF478830831ACC2B41DAEFC25ED38FCC8D96C4401377374FED35C36A5017A11E63C8DAE5C487 |
Malicious: | false |
Reputation: | low |
URL: | https://img-prod-cms-rt-microsoft-com.akamaized.net/cms/api/am/imageFileData/RE1Mu3b?ver=5c31 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 338 |
Entropy (8bit): | 7.004897375379158 |
Encrypted: | false |
SSDEEP: | 6:6v/lhPkR/C+k790OCotr/vbXX3PHrLiBxwGFhGsznYUAlnEkPb6PL2+/pTp:6v/78/v4rrXX3u1XYRm4byp9 |
MD5: | 290AFB4165DD808A850D8920AEB5DBF4 |
SHA1: | 0B4BF844AED3A740A99B7415F6BD803E84DDDA4D |
SHA-256: | 882FDB8A4BF176D2A09427D6A5BDBA3051307F2605090DA848085B0D78B6FD99 |
SHA-512: | 197AD95E98C04B26AAD845DF7FF5C3C2CC6020E5273526970261F30A8EEAAB30A1C0DDC2BAE1D654095E8D47D399CCB526B32AD7CBE84CB1140E2D5F5142A7DB |
Malicious: | false |
Reputation: | low |
URL: | https://c.s-microsoft.com/en-us/CMSImages/Print-new-2.png?version=4eafce11-a3df-e971-f481-fed76428ffa1 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 92629 |
Entropy (8bit): | 5.303443527492463 |
Encrypted: | false |
SSDEEP: | 1536:dnu00HWWaRxkqJg09pYxoxDKMXJrg8hXXO4dK3kyfiLJBhdSZE+I+Qg7rbaN1RUx:ddkWgoBhcZRQgmW42qe |
MD5: | 397754BA49E9E0CF4E7C190DA78DDA05 |
SHA1: | AE49E56999D82802727455F0BA83B63ACD90A22B |
SHA-256: | C12F6098E641AACA96C60215800F18F5671039AECF812217FAB3C0D152F6ADB4 |
SHA-512: | 8C64754F77507AB2C24A6FC818419B9DD3F0CECCC9065290E41AFDBEE0743F0DA2CB13B2FBB00AFA525C082F1E697CB3FFD76EF9B902CB81D7C41CA1C641DFFB |
Malicious: | false |
Reputation: | low |
URL: | https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.9.1.min.js |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 115013 |
Entropy (8bit): | 5.229899931173904 |
Encrypted: | false |
SSDEEP: | 1536:uzUHQTAz7pxhXaOG+59gkpCIlIX8BJWxFuP09RhY81Oyd1EwgXA7GKaExAMKRNAh:uzUzpxnISP0B9d1EwgXA7nKRfMK/7bw |
MD5: | 201D4CC04296F0BD36024089889982A4 |
SHA1: | CB260C7F54BCB7D5EB721D4AB0809D34DE932A51 |
SHA-256: | DCE420C5A8D277AB6E42268385B715197B41D52C94E0F50D548A9B8B03A53B07 |
SHA-512: | AB9D1DB98A1D835F68274B18A5D801CA055C88302FE5E689BBA4A0ABC4ED193580D4A234BC586F32A50F760B28A5EC49AD92799F1CA67E25A9E4FAC5CD2D3E39 |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/concern/_scrf/js/themes=default/44-f01b50/79-851f4c/e6-6b0cce/38-612ec2/ed-0fe1b2/8f-f92bc5/d1-98d78a/c6-082272/a7-f7a340/1e-addbef/2e-ca165a/fc-169dd8/8e-60935c/87-fecbed/96-6ed6eb/c3-eb62e0/ad-ffd6bf/35-621acc/5b-6eff60/b0-07f293/2b-3c7e83/1e-9d9d16/52-f0367f/af-abd754/bf-517249/20-0b10e2/6b-0f1117/fb-5e9831/a2-598841/9f-763b80?ver=2.0&_cf=02242021_3231 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 68323 |
Entropy (8bit): | 5.370852538853382 |
Encrypted: | false |
SSDEEP: | 1536:gtV81ICDVRgJhAiUinqgDRQ7wYv6uxuBANIu:gv81+einqgD8f |
MD5: | 853F2B3864C0FB6DB5505F80FC4F9BA5 |
SHA1: | E9B51C95D2147C42906BC12FDF2B409B8B728F66 |
SHA-256: | 02A1C0B516C255A38618BAFD4F9FAE47FFAECCAB5E05D2BFD179D38A609ACFB8 |
SHA-512: | 725C8CBB3D41B2CB892635888061377F891C776AA46839B16B4BC7C2C7FA60AC1347FE020A93CED71F19FCA9A8E8A4C6D755D740240647F3B74101515252EFF6 |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/concern/_scrf/js/themes=default/5a-32b77f/a8-824cb9?ver=2.0&_cf=02242021_3231 |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 262641 |
Entropy (8bit): | 4.9463902181496096 |
Encrypted: | false |
SSDEEP: | 3072:u+Vd0pBbqPLYoyjFkxD2hAYwJb8ILm731Ss:u+Vd0DePLYoyjFkxD2hAYwJbZLM31Ss |
MD5: | 7C593B06759DB6D01614729D206738D6 |
SHA1: | 0D4F76D10944933B8DDECFFE9691081439A77A3C |
SHA-256: | F7D9FB0479DE843CF3FB0B78FC56BBB9E30BF0A238C6F79D9209FA8B22EFB574 |
SHA-512: | EF91B610CF17A17AAFB48984B4403EF175EB86096E3F12E23AE8D4C7C96EF60ED14DA3F69721E095CD2ACE3F0A06190186D000992823814BB906F7FB3576C2C1 |
Malicious: | false |
Reputation: | low |
URL: | https://assets.onestore.ms/cdnfiles/external/oneui/oneui1.16.2/dist/css/app.css |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 7.004897375379158 |
Encrypted: | false |
SSDEEP: | 6:6v/lhPkR/C+k790OCotr/vbXX3PHrLiBxwGFhGsznYUAlnEkPb6PL2+/pTp:6v/78/v4rrXX3u1XYRm4byp9 |
MD5: | 290AFB4165DD808A850D8920AEB5DBF4 |
SHA1: | 0B4BF844AED3A740A99B7415F6BD803E84DDDA4D |
SHA-256: | 882FDB8A4BF176D2A09427D6A5BDBA3051307F2605090DA848085B0D78B6FD99 |
SHA-512: | 197AD95E98C04B26AAD845DF7FF5C3C2CC6020E5273526970261F30A8EEAAB30A1C0DDC2BAE1D654095E8D47D399CCB526B32AD7CBE84CB1140E2D5F5142A7DB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 89478 |
Entropy (8bit): | 5.2899182577550565 |
Encrypted: | false |
SSDEEP: | 1536:/jExXUqrnxDjoXEZxkMV4SYSt0zvDD6ip3h8cApwEjOPrBeU6QLiTFbc0QlQvaks:/Yh8eip3huuf6IidlrvakdtQ47GK8 |
MD5: | B61AA6E2D68D21B3546B5B418BF0E9C3 |
SHA1: | 9C1398F0DE4C869DACB1C9AB1A8CC327F5421FF7 |
SHA-256: | F36844906AD2309877AAE3121B87FB15B9E09803CB4C333ADC7E1E35AC92E14B |
SHA-512: | 5882735D9A0239C5C63C5C87B81618E3C8DC09D7D743C3444C535B9547B9B65DEFA509D7804552C581CB84B61DD1225E2ADD5DCA6B120868EC201FA979504F4B |
Malicious: | false |
Reputation: | low |
URL: | https://www.microsoft.com/onerfstatics/marketingsites-wcus-prod/_h/dfa0b592/coreui.statics/externalscripts/jquery/jquery-3.5.1.min.js |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 97
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 7, 2023 19:07:58.773013115 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:58.773094893 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:58.773180962 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:58.775695086 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:58.775748968 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:07:58.775819063 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:58.777282000 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:58.777338982 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:58.779325008 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:58.779359102 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:07:59.214570045 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.216681004 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.216744900 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.217463970 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.217545986 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.219357014 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.219477892 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.220431089 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:07:59.222141981 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:59.222182035 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:07:59.224694967 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:07:59.224879980 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:59.640431881 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.640707970 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.674380064 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.674464941 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.687577009 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:59.687824011 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:07:59.688725948 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:59.688745975 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:07:59.883493900 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.883765936 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.886307001 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:07:59.917787075 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.918025017 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:07:59.918107033 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.977145910 CEST | 49163 | 443 | 192.168.2.22 | 142.251.2.100 |
Sep 7, 2023 19:07:59.977199078 CEST | 443 | 49163 | 142.251.2.100 | 192.168.2.22 |
Sep 7, 2023 19:08:00.158305883 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:08:00.158700943 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:08:00.158874989 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:08:00.160167933 CEST | 49164 | 443 | 192.168.2.22 | 142.251.2.84 |
Sep 7, 2023 19:08:00.160203934 CEST | 443 | 49164 | 142.251.2.84 | 192.168.2.22 |
Sep 7, 2023 19:08:02.957082033 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:02.957140923 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:02.957253933 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:02.957433939 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:02.957448959 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:03.398430109 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:03.399605989 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:03.399626017 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:03.400959015 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:03.401062012 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:03.404095888 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:03.404361963 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:03.602066040 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:03.602096081 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:03.802119970 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:13.388803005 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:13.388895988 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:08:13.388973951 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:13.770191908 CEST | 49171 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:08:13.770229101 CEST | 443 | 49171 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:02.819297075 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:02.819384098 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:02.819500923 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:02.820019007 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:02.820045948 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:03.253196001 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:03.253703117 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:03.253757000 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:03.254470110 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:03.256114006 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:03.256313086 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:03.464822054 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:13.267791033 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:13.267891884 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:13.268171072 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:13.732923985 CEST | 49219 | 443 | 192.168.2.22 | 142.251.2.99 |
Sep 7, 2023 19:09:13.732979059 CEST | 443 | 49219 | 142.251.2.99 | 192.168.2.22 |
Sep 7, 2023 19:09:26.062858105 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:26.062926054 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:26.063028097 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:26.063441038 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:26.063478947 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:26.591295004 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:26.591933012 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:26.591973066 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:26.594110966 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:26.594194889 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:26.595853090 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:26.595999956 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:26.596131086 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:26.596155882 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:26.789401054 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.139760017 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.139799118 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.139812946 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.139853954 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.139903069 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.139916897 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.139986992 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.139987946 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.139987946 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.140045881 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.140096903 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.140120983 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.307979107 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308044910 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308065891 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308144093 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308165073 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308223963 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308224916 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308224916 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308224916 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308320045 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308366060 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308366060 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308381081 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308720112 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308789015 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308813095 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308883905 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.308893919 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.308959961 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.309865952 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.309922934 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.309993982 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.310028076 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.310133934 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.312591076 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.475306988 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.475377083 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.475574970 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.475574970 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.475655079 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.475830078 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.475886106 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.475919008 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.475950956 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.475986958 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.476933956 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.476974010 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.477051020 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.477051020 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.477108955 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.477813005 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.477858067 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.477900982 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.477946997 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.477977037 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.478530884 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.478604078 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.478632927 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.478696108 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.483496904 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.483527899 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Sep 7, 2023 19:09:27.483679056 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.485131979 CEST | 49237 | 443 | 192.168.2.22 | 13.107.246.71 |
Sep 7, 2023 19:09:27.485492945 CEST | 443 | 49237 | 13.107.246.71 | 192.168.2.22 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 7, 2023 19:07:58.564136028 CEST | 52781 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:07:58.564583063 CEST | 63926 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:07:58.565637112 CEST | 65510 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:07:58.566082001 CEST | 62672 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:07:58.732018948 CEST | 53 | 54998 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:07:58.768949986 CEST | 53 | 52781 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:07:58.769845009 CEST | 53 | 63926 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:07:58.770091057 CEST | 53 | 65510 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:07:58.770303965 CEST | 53 | 62672 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:08:00.308738947 CEST | 53 | 54842 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:08:02.752408981 CEST | 50446 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:02.758670092 CEST | 55939 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:02.949459076 CEST | 53 | 50446 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:08:02.955826998 CEST | 53 | 55939 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:08:05.333300114 CEST | 62453 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:05.334582090 CEST | 50568 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:05.345616102 CEST | 54422 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:05.345830917 CEST | 52074 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:05.351149082 CEST | 50337 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:05.351428032 CEST | 61826 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:18.459060907 CEST | 65084 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:18.559451103 CEST | 63373 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:19.417957067 CEST | 51955 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:19.418502092 CEST | 58971 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:08:58.580133915 CEST | 53 | 57998 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:09:24.914803982 CEST | 54333 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:09:24.915191889 CEST | 55388 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:09:25.195116043 CEST | 53 | 60624 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:09:25.196579933 CEST | 53 | 58974 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:09:25.489625931 CEST | 53 | 54154 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:09:25.695888042 CEST | 53 | 49263 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:09:25.696701050 CEST | 53 | 60981 | 8.8.8.8 | 192.168.2.22 |
Sep 7, 2023 19:09:25.827418089 CEST | 50357 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:09:25.827773094 CEST | 58291 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 7, 2023 19:09:25.901298046 CEST | 53 | 51161 | 8.8.8.8 | 192.168.2.22 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Sep 7, 2023 19:08:05.653317928 CEST | 192.168.2.22 | 8.8.8.8 | d0b6 | (Port unreachable) | Destination Unreachable |
Sep 7, 2023 19:08:33.335908890 CEST | 192.168.2.22 | 8.8.8.8 | d0ae | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 7, 2023 19:07:58.564136028 CEST | 192.168.2.22 | 8.8.8.8 | 0xc68f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:07:58.564583063 CEST | 192.168.2.22 | 8.8.8.8 | 0x7f7e | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:07:58.565637112 CEST | 192.168.2.22 | 8.8.8.8 | 0x45b2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:07:58.566082001 CEST | 192.168.2.22 | 8.8.8.8 | 0x6245 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:08:02.752408981 CEST | 192.168.2.22 | 8.8.8.8 | 0x6f6c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:08:02.758670092 CEST | 192.168.2.22 | 8.8.8.8 | 0x98a4 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:08:05.333300114 CEST | 192.168.2.22 | 8.8.8.8 | 0x491 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:08:05.334582090 CEST | 192.168.2.22 | 8.8.8.8 | 0x4eca | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:08:05.345616102 CEST | 192.168.2.22 | 8.8.8.8 | 0xedb2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:08:05.345830917 CEST | 192.168.2.22 | 8.8.8.8 | 0x7a5e | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:08:05.351149082 CEST | 192.168.2.22 | 8.8.8.8 | 0xdaad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:08:05.351428032 CEST | 192.168.2.22 | 8.8.8.8 | 0x9e0c | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:08:18.459060907 CEST | 192.168.2.22 | 8.8.8.8 | 0xaed2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:08:18.559451103 CEST | 192.168.2.22 | 8.8.8.8 | 0x68bc | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:08:19.417957067 CEST | 192.168.2.22 | 8.8.8.8 | 0xcd9b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:08:19.418502092 CEST | 192.168.2.22 | 8.8.8.8 | 0xb543 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:09:24.914803982 CEST | 192.168.2.22 | 8.8.8.8 | 0xfdf3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:09:24.915191889 CEST | 192.168.2.22 | 8.8.8.8 | 0xa4c3 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 7, 2023 19:09:25.827418089 CEST | 192.168.2.22 | 8.8.8.8 | 0x5f24 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 7, 2023 19:09:25.827773094 CEST | 192.168.2.22 | 8.8.8.8 | 0x62ec | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 7, 2023 19:07:58.768949986 CEST | 8.8.8.8 | 192.168.2.22 | 0xc68f | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.768949986 CEST | 8.8.8.8 | 192.168.2.22 | 0xc68f | No error (0) | 142.251.2.100 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.768949986 CEST | 8.8.8.8 | 192.168.2.22 | 0xc68f | No error (0) | 142.251.2.138 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.768949986 CEST | 8.8.8.8 | 192.168.2.22 | 0xc68f | No error (0) | 142.251.2.101 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.768949986 CEST | 8.8.8.8 | 192.168.2.22 | 0xc68f | No error (0) | 142.251.2.113 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.768949986 CEST | 8.8.8.8 | 192.168.2.22 | 0xc68f | No error (0) | 142.251.2.102 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.768949986 CEST | 8.8.8.8 | 192.168.2.22 | 0xc68f | No error (0) | 142.251.2.139 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.769845009 CEST | 8.8.8.8 | 192.168.2.22 | 0x7f7e | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:07:58.770091057 CEST | 8.8.8.8 | 192.168.2.22 | 0x45b2 | No error (0) | 142.251.2.84 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:02.949459076 CEST | 8.8.8.8 | 192.168.2.22 | 0x6f6c | No error (0) | 142.251.2.99 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:02.949459076 CEST | 8.8.8.8 | 192.168.2.22 | 0x6f6c | No error (0) | 142.251.2.103 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:02.949459076 CEST | 8.8.8.8 | 192.168.2.22 | 0x6f6c | No error (0) | 142.251.2.106 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:02.949459076 CEST | 8.8.8.8 | 192.168.2.22 | 0x6f6c | No error (0) | 142.251.2.147 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:02.949459076 CEST | 8.8.8.8 | 192.168.2.22 | 0x6f6c | No error (0) | 142.251.2.104 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:02.949459076 CEST | 8.8.8.8 | 192.168.2.22 | 0x6f6c | No error (0) | 142.251.2.105 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:02.955826998 CEST | 8.8.8.8 | 192.168.2.22 | 0x98a4 | No error (0) | 65 | IN (0x0001) | false | |||
Sep 7, 2023 19:08:05.531526089 CEST | 8.8.8.8 | 192.168.2.22 | 0x4eca | No error (0) | mscomajax.vo.msecnd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:05.544430017 CEST | 8.8.8.8 | 192.168.2.22 | 0x491 | No error (0) | mscomajax.vo.msecnd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:05.548413992 CEST | 8.8.8.8 | 192.168.2.22 | 0xedb2 | No error (0) | c-s.cms.ms.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:05.563519955 CEST | 8.8.8.8 | 192.168.2.22 | 0x9e0c | No error (0) | assets.onestore.ms.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:05.569639921 CEST | 8.8.8.8 | 192.168.2.22 | 0xdaad | No error (0) | assets.onestore.ms.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:05.653211117 CEST | 8.8.8.8 | 192.168.2.22 | 0x7a5e | No error (0) | c-s.cms.ms.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:18.670883894 CEST | 8.8.8.8 | 192.168.2.22 | 0xaed2 | No error (0) | i.s-microsoft.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:18.757982016 CEST | 8.8.8.8 | 192.168.2.22 | 0x68bc | No error (0) | i.s-microsoft.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:19.639477968 CEST | 8.8.8.8 | 192.168.2.22 | 0xcd9b | No error (0) | c-s.cms.ms.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:08:19.733598948 CEST | 8.8.8.8 | 192.168.2.22 | 0xb543 | No error (0) | c-s.cms.ms.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:23.671736002 CEST | 8.8.8.8 | 192.168.2.22 | 0x1e7c | No error (0) | waws-prod-sn1-d6325e78.vip.p.azurewebsites.windows.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:23.671736002 CEST | 8.8.8.8 | 192.168.2.22 | 0x1e7c | No error (0) | waws-prod-sn1-d6325e78.cloudapp.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:23.677983999 CEST | 8.8.8.8 | 192.168.2.22 | 0xd17a | No error (0) | waws-prod-sn1-d6325e78.vip.p.azurewebsites.windows.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:23.677983999 CEST | 8.8.8.8 | 192.168.2.22 | 0xd17a | No error (0) | waws-prod-sn1-d6325e78.cloudapp.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:25.116688967 CEST | 8.8.8.8 | 192.168.2.22 | 0xa4c3 | No error (0) | www.w3.org.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:25.127463102 CEST | 8.8.8.8 | 192.168.2.22 | 0xfdf3 | No error (0) | www.w3.org.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:26.040311098 CEST | 8.8.8.8 | 192.168.2.22 | 0x5f24 | No error (0) | aijscdn2.azureedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:26.040311098 CEST | 8.8.8.8 | 192.168.2.22 | 0x5f24 | No error (0) | part-0043.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:26.040311098 CEST | 8.8.8.8 | 192.168.2.22 | 0x5f24 | No error (0) | 13.107.246.71 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:26.040311098 CEST | 8.8.8.8 | 192.168.2.22 | 0x5f24 | No error (0) | 13.107.213.71 | A (IP address) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:26.061933041 CEST | 8.8.8.8 | 192.168.2.22 | 0x62ec | No error (0) | aijscdn2.azureedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 7, 2023 19:09:26.061933041 CEST | 8.8.8.8 | 192.168.2.22 | 0x62ec | No error (0) | part-0043.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.22 | 49163 | 142.251.2.100 | 443 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-09-07 17:07:59 UTC | 0 | OUT | |
2023-09-07 17:07:59 UTC | 1 | IN | |
2023-09-07 17:07:59 UTC | 2 | IN | |
2023-09-07 17:07:59 UTC | 2 | IN | |
2023-09-07 17:07:59 UTC | 2 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.22 | 49164 | 142.251.2.84 | 443 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-09-07 17:07:59 UTC | 0 | OUT | |
2023-09-07 17:07:59 UTC | 1 | OUT | |
2023-09-07 17:08:00 UTC | 2 | IN | |
2023-09-07 17:08:00 UTC | 4 | IN | |
2023-09-07 17:08:00 UTC | 4 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.22 | 49237 | 13.107.246.71 | 443 | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-09-07 17:09:26 UTC | 4 | OUT | |
2023-09-07 17:09:27 UTC | 5 | IN | |
2023-09-07 17:09:27 UTC | 6 | IN | |
2023-09-07 17:09:27 UTC | 21 | IN | |
2023-09-07 17:09:27 UTC | 37 | IN | |
2023-09-07 17:09:27 UTC | 53 | IN | |
2023-09-07 17:09:27 UTC | 69 | IN | |
2023-09-07 17:09:27 UTC | 85 | IN | |
2023-09-07 17:09:27 UTC | 101 | IN | |
2023-09-07 17:09:27 UTC | 117 | IN | |
2023-09-07 17:09:27 UTC | 132 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 19:07:54 |
Start date: | 07/09/2023 |
Path: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13fca0000 |
File size: | 3'151'128 bytes |
MD5 hash: | FFA2B8E17F645BCC20F0E0201FEF83ED |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 19:07:56 |
Start date: | 07/09/2023 |
Path: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13fca0000 |
File size: | 3'151'128 bytes |
MD5 hash: | FFA2B8E17F645BCC20F0E0201FEF83ED |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 19:08:00 |
Start date: | 07/09/2023 |
Path: | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13fca0000 |
File size: | 3'151'128 bytes |
MD5 hash: | FFA2B8E17F645BCC20F0E0201FEF83ED |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |