Windows
Analysis Report
https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5540 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA) chrome.exe (PID: 5376 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1988 --fi eld-trial- handle=166 4,i,118808 0216242883 7991,10559 6510485647 41493,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
chrome.exe (PID: 6396 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://u17062 22.ct.send grid.net/l s/click?up n=7l-2fyec tmlqal6uwj qzr9drqesq zg1gwwmhjt 9dhsfumkmj xf6bym6ntb a6tbtj2pex bkvqcrr0tl xf-2bignod 2jfu-2fm3e fiijypxi7m q99qi2vk-2 bdampbn4ax ui6usm7vzs ggx7trzelq kizaxqlj6u xmzxmdo1yi ziyh-2fti9 3zvgj8cqwn ivdyeqnbew ikcgsp7uxs h6ujuj1obw mtpk8dp-2f bychkvzb7s gvpuxjvcql yibx-2b1vk ld80re7psi v-2fraclla -2brb-2fkq hq7dwx42qd pioi7nspvs 1rgrkvqpjs fn6nptcu5h svcpqne2zi kg-2f0af7v h17ryeociw kn49j1x-2b 94oyzn2-2b ktgbt4ybgn lott6knxfy 5qwcumrecb uk_7xr_dyl jizserkoqx 9pq1-2b98b esfph4urhk taednxbruf kuohqio-2f yuqn29luyz dg9l1-2fpp g3vowy6wy3 pdgfystx2s azagcxbfqs dfkirxwy-2 bukgrupirb feqxq3w78p mboy7wdqeb 2cztv-2brd jqerc8ozw6 mao5ams6gp nlqfqxxry1 6dsbb7a7ow rqkjwhjwp0 doctslhex5 uudubdhdyu 5fecntgljh bbwrwufmca 4ycvcngqxw 6b66swge3p blhr-2fbom us1scdunxb nhfn04sczt esz7zqztw- 2b1vbb9gvq tgjrptzor0 xdlwknfsad xbxq3uaz-2 brgodqqvru jn4kkl6it1 xf-2b49aog aufyg5qgoq l-2bzv-2b4 lsivmeohcl a58g5fjt2b cvkrrtb-2b t7q3npw0rd qfge2z-2bv -2bae16p3b wpt7ml-2fe b18camx-2b fatf5no6lw 2za0emgjhr qopuk9rvms la9bdu-2fu 8brd4adocd f-2fdpj9fm cc8mhb4zyq ixxltkoebq pfqszjutrk worbwgok5r y9mbezlhqv ytsr3cdysw iyatrvzem- 2f0s2dz10y uzd6gbr6ao onuhrd03cr dtgslvipy6 pkymz7kon4 tup5dhas1o euurdmhclq q9xwz MD5: 8D1C4713ACB7CC2AAAEE4477C58A80BA)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Directory created: | Jump to behavior |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTP traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Directory created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 2 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 4 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 5 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 3 Ingress Tool Transfer | SIM Card Swap | Carrier Billing Fraud |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 172.217.13.141 | true | false | high | |
www.google.com | 172.217.13.100 | true | false | high | |
clients.l.google.com | 172.217.13.174 | true | false | high | |
u1706222.ct.sendgrid.net | 167.89.115.121 | true | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
167.89.115.121 | u1706222.ct.sendgrid.net | United States | 11377 | SENDGRIDUS | false | |
172.217.13.100 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.217.13.141 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
172.217.13.174 | clients.l.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.30 |
192.168.2.1 |
Joe Sandbox Version: | 38.0.0 Beryl |
Analysis ID: | 1310902 |
Start date and time: | 2023-09-19 17:56:33 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 2m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@18/2@8/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, B ackgroundTransferHost.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe, wuapihost.exe - Excluded IPs from analysis (wh
itelisted): 20.54.24.169, 104. 127.77.185, 172.217.13.99, 34. 104.35.123, 172.217.13.195 - Excluded domains from analysis
(whitelisted): www.bing.com, geo.prod.do.dsp.trafficmanager .net, geo.prod.do.dsp.mp.micro soft.com, e12358.d.akamaiedge. net, tse1.mm.bing.net, clients ervices.googleapis.com, arc.ms n.com, array613.prod.do.dsp.mp .microsoft.com, kv601.prod.do. dsp.mp.microsoft.com, kv601.pr od.do.dsp.mp.microsoft.com.edg ekey.net, edgedl.me.gvt1.com, update.googleapis.com, display catalog.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: https:
//u1706222.ct.sendgrid.net/ls/ click?upn=7l-2fyectmlqal6uwjqz r9drqesqzg1gwwmhjt9dhsfumkmjxf 6bym6ntba6tbtj2pexbkvqcrr0tlxf -2bignod2jfu-2fm3efiijypxi7mq9 9qi2vk-2bdampbn4axui6usm7vzsgg x7trzelqkizaxqlj6uxmzxmdo1yizi yh-2fti93zvgj8cqwnivdyeqnbewik cgsp7uxsh6ujuj1obwmtpk8dp-2fby chkvzb7sgvpuxjvcqlyibx-2b1vkld 80re7psiv-2fraclla-2brb-2fkqhq 7dwx42qdpioi7nspvs1rgrkvqpjsfn 6nptcu5hsvcpqne2zikg-2f0af7vh1 7ryeociwkn49j1x-2b94oyzn2-2bkt gbt4ybgnlott6knxfy5qwcumrecbuk _7xr_dyljizserkoqx9pq1-2b98bes fph4urhktaednxbrufkuohqio-2fyu qn29luyzdg9l1-2fppg3vowy6wy3pd gfystx2sazagcxbfqsdfkirxwy-2bu kgrupirbfeqxq3w78pmboy7wdqeb2c ztv-2brdjqerc8ozw6mao5ams6gpnl qfqxxry16dsbb7a7owrqkjwhjwp0do ctslhex5uudubdhdyu5fecntgljhbb wrwufmca4ycvcngqxw6b66swge3pbl hr-2fbomus1scdunxbnhfn04scztes z7zqztw-2b1vbb9gvqtgjrptzor0xd lwknfsadxbxq3uaz-2brgodqqvrujn 4kkl6it1xf-2b49aogaufyg5qgoql- 2bzv-2b4lsivmeohcla58g5fjt2bcv krrtb-2bt7q3npw0rdqfge2z-2bv-2 bae16p3bwpt7ml-2feb18camx-2bfa tf5no6lw2za0emgjhrqopuk9rvmsla 9bdu-2fu8brd4adocdf-2fdpj9fmcc 8mhb
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 291 |
Entropy (8bit): | 4.477778146874743 |
Encrypted: | false |
SSDEEP: | 6:qzxUsjMR1X96b2+Ubghxc8le3rn9MGzMd4aa6++Oix9qD:kxBMR1knUkhGXpPoa6++3xMD |
MD5: | F0C66914A58FC74FC98A7C9BB4C288F2 |
SHA1: | 3E0E43F567138623CABFF91C14100D144AC56949 |
SHA-256: | 54E173BE753D03B2C163CEBBEE02BE7F4BDC1D6663154D4D60A3833F7BA3436B |
SHA-512: | 7AEDAEBA112D43E2B2FF845355199A11A141D637C0306155BE2356AE297DF118D2C0D2768D44C35A1D89841DB428E95686E29E9D15DEADF4233F3713893514BF |
Malicious: | false |
Reputation: | low |
URL: | https://u1706222.ct.sendgrid.net/ls/click?upn=7l-2fyectmlqal6uwjqzr9drqesqzg1gwwmhjt9dhsfumkmjxf6bym6ntba6tbtj2pexbkvqcrr0tlxf-2bignod2jfu-2fm3efiijypxi7mq99qi2vk-2bdampbn4axui6usm7vzsggx7trzelqkizaxqlj6uxmzxmdo1yiziyh-2fti93zvgj8cqwnivdyeqnbewikcgsp7uxsh6ujuj1obwmtpk8dp-2fbychkvzb7sgvpuxjvcqlyibx-2b1vkld80re7psiv-2fraclla-2brb-2fkqhq7dwx42qdpioi7nspvs1rgrkvqpjsfn6nptcu5hsvcpqne2zikg-2f0af7vh17ryeociwkn49j1x-2b94oyzn2-2bktgbt4ybgnlott6knxfy5qwcumrecbuk_7xr_dyljizserkoqx9pq1-2b98besfph4urhktaednxbrufkuohqio-2fyuqn29luyzdg9l1-2fppg3vowy6wy3pdgfystx2sazagcxbfqsdfkirxwy-2bukgrupirbfeqxq3w78pmboy7wdqeb2cztv-2brdjqerc8ozw6mao5ams6gpnlqfqxxry16dsbb7a7owrqkjwhjwp0doctslhex5uudubdhdyu5fecntgljhbbwrwufmca4ycvcngqxw6b66swge3pblhr-2fbomus1scdunxbnhfn04scztesz7zqztw-2b1vbb9gvqtgjrptzor0xdlwknfsadxbxq3uaz-2brgodqqvrujn4kkl6it1xf-2b49aogaufyg5qgoql-2bzv-2b4lsivmeohcla58g5fjt2bcvkrrtb-2bt7q3npw0rdqfge2z-2bv-2bae16p3bwpt7ml-2feb18camx-2bfatf5no6lw2za0emgjhrqopuk9rvmsla9bdu-2fu8brd4adocdf-2fdpj9fmcc8mhb4zyqixxltkoebqpfqszjutrkworbwgok5ry9mbezlhqvytsr3cdyswiyatrvzem-2f0s2dz10yuzd6gbr6aoonuhrd03crdtgslvipy6pkymz7kon4tup5dhas1oeuurdmhclqq9xwz |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 564 |
Entropy (8bit): | 4.72971822420855 |
Encrypted: | false |
SSDEEP: | 12:TjeRHdHiHZdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH988DTPTPTPTPTPTc |
MD5: | 8E325DC2FEA7C8900FC6C4B8C6C394FE |
SHA1: | 1B3291D4EEA179C84145B2814CB53E6A506EC201 |
SHA-256: | 0B52C5338AF355699530A47683420E48C7344E779D3E815FF9943CBFDC153CF2 |
SHA-512: | 084C608F1F860FB08EF03B155658EA9988B3628D3C0F0E9561FDFF930E5912004CDDBCC43B1FA90C21FE7F5A481AC47C64B8CAA066C2BDF3CF533E152BF96C14 |
Malicious: | false |
Reputation: | low |
URL: | https://u1706222.ct.sendgrid.net/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 68
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 19, 2023 17:57:23.037506104 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.037600040 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.037672997 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.037826061 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.037843943 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.037909985 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.038117886 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.038151026 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.038423061 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.038451910 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.332925081 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.333086967 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.333151102 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.333190918 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.333267927 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.333301067 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.333853960 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.333930969 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.335103989 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.335105896 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.335211039 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.335211039 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.336416006 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.336510897 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.336951017 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.336982012 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.337107897 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.337208986 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.337234974 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.380650043 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.384716034 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.385426044 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.385457993 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.431613922 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.537391901 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.537579060 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.537666082 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.539540052 CEST | 49728 | 443 | 192.168.2.5 | 172.217.13.174 |
Sep 19, 2023 17:57:23.539581060 CEST | 443 | 49728 | 172.217.13.174 | 192.168.2.5 |
Sep 19, 2023 17:57:23.544841051 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.545211077 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:23.545290947 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.546206951 CEST | 49727 | 443 | 192.168.2.5 | 172.217.13.141 |
Sep 19, 2023 17:57:23.546221972 CEST | 443 | 49727 | 172.217.13.141 | 192.168.2.5 |
Sep 19, 2023 17:57:25.486531019 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.486582041 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.486668110 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.486975908 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.486989975 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.487703085 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.487761021 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.487814903 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.487947941 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.487963915 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.790292978 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.801934004 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.825992107 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.826016903 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.826186895 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.826239109 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.827254057 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.827331066 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.829293966 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.829423904 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.829588890 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.829607010 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.830138922 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.830228090 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.831269979 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.831496000 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.870289087 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.871290922 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.871361017 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.911297083 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.927226067 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.927331924 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:25.927390099 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.929637909 CEST | 49729 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:25.929666996 CEST | 443 | 49729 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:26.058727980 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:26.058901072 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:26.156611919 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:26.156721115 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:26.156809092 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:26.158633947 CEST | 49730 | 443 | 192.168.2.5 | 167.89.115.121 |
Sep 19, 2023 17:57:26.158662081 CEST | 443 | 49730 | 167.89.115.121 | 192.168.2.5 |
Sep 19, 2023 17:57:27.259624004 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:27.259684086 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:27.259783983 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:27.260391951 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:27.260411024 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:27.483747005 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:27.484173059 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:27.484198093 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:27.485274076 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:27.485363007 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:27.796657085 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:27.797245026 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:27.838053942 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:27.838139057 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:27.884991884 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:37.462780952 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:37.462857008 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:57:37.462934017 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:40.744401932 CEST | 49731 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:57:40.744426966 CEST | 443 | 49731 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:27.215591908 CEST | 49755 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:58:27.215626001 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:27.215748072 CEST | 49755 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:58:27.216375113 CEST | 49755 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:58:27.216388941 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:27.443079948 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:27.443851948 CEST | 49755 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:58:27.443886995 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:27.444575071 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:27.445705891 CEST | 49755 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:58:27.445806980 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:27.491050959 CEST | 49755 | 443 | 192.168.2.5 | 172.217.13.100 |
Sep 19, 2023 17:58:37.430303097 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:37.430468082 CEST | 443 | 49755 | 172.217.13.100 | 192.168.2.5 |
Sep 19, 2023 17:58:37.430572033 CEST | 49755 | 443 | 192.168.2.5 | 172.217.13.100 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 19, 2023 17:57:22.936233997 CEST | 64219 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:22.936567068 CEST | 55252 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:22.937063932 CEST | 64997 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:22.937321901 CEST | 62449 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:23.033134937 CEST | 53 | 60422 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:23.033447981 CEST | 53 | 64219 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:23.033484936 CEST | 53 | 55252 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:23.035062075 CEST | 53 | 64997 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:23.036506891 CEST | 53 | 62449 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:23.687011957 CEST | 53 | 53007 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:25.369009972 CEST | 56046 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:25.369354963 CEST | 51513 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:25.466939926 CEST | 53 | 56046 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:25.469073057 CEST | 53 | 51513 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:27.164680958 CEST | 54947 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:27.165328979 CEST | 52465 | 53 | 192.168.2.5 | 8.8.8.8 |
Sep 19, 2023 17:57:27.255800962 CEST | 53 | 54947 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:27.255887032 CEST | 53 | 52465 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:40.842190027 CEST | 53 | 63275 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:47.805288076 CEST | 53 | 63240 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:57:58.401904106 CEST | 53 | 64101 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:58:16.120711088 CEST | 53 | 51649 | 8.8.8.8 | 192.168.2.5 |
Sep 19, 2023 17:58:22.643099070 CEST | 53 | 60070 | 8.8.8.8 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 19, 2023 17:57:22.936233997 CEST | 192.168.2.5 | 8.8.8.8 | 0x8b51 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 19, 2023 17:57:22.936567068 CEST | 192.168.2.5 | 8.8.8.8 | 0xabd1 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 19, 2023 17:57:22.937063932 CEST | 192.168.2.5 | 8.8.8.8 | 0xe02d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 19, 2023 17:57:22.937321901 CEST | 192.168.2.5 | 8.8.8.8 | 0x70cc | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 19, 2023 17:57:25.369009972 CEST | 192.168.2.5 | 8.8.8.8 | 0xfde2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 19, 2023 17:57:25.369354963 CEST | 192.168.2.5 | 8.8.8.8 | 0x7866 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 19, 2023 17:57:27.164680958 CEST | 192.168.2.5 | 8.8.8.8 | 0x3ee8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 19, 2023 17:57:27.165328979 CEST | 192.168.2.5 | 8.8.8.8 | 0x5806 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 19, 2023 17:57:23.033447981 CEST | 8.8.8.8 | 192.168.2.5 | 0x8b51 | No error (0) | 172.217.13.141 | A (IP address) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:23.035062075 CEST | 8.8.8.8 | 192.168.2.5 | 0xe02d | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:23.035062075 CEST | 8.8.8.8 | 192.168.2.5 | 0xe02d | No error (0) | 172.217.13.174 | A (IP address) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:23.036506891 CEST | 8.8.8.8 | 192.168.2.5 | 0x70cc | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:25.466939926 CEST | 8.8.8.8 | 192.168.2.5 | 0xfde2 | No error (0) | 167.89.115.121 | A (IP address) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:25.466939926 CEST | 8.8.8.8 | 192.168.2.5 | 0xfde2 | No error (0) | 167.89.123.122 | A (IP address) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:25.466939926 CEST | 8.8.8.8 | 192.168.2.5 | 0xfde2 | No error (0) | 167.89.115.54 | A (IP address) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:25.466939926 CEST | 8.8.8.8 | 192.168.2.5 | 0xfde2 | No error (0) | 167.89.123.16 | A (IP address) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:27.255800962 CEST | 8.8.8.8 | 192.168.2.5 | 0x3ee8 | No error (0) | 172.217.13.100 | A (IP address) | IN (0x0001) | false | ||
Sep 19, 2023 17:57:27.255887032 CEST | 8.8.8.8 | 192.168.2.5 | 0x5806 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.5 | 49728 | 172.217.13.174 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-09-19 15:57:23 UTC | 0 | OUT | |
2023-09-19 15:57:23 UTC | 1 | IN | |
2023-09-19 15:57:23 UTC | 2 | IN | |
2023-09-19 15:57:23 UTC | 2 | IN | |
2023-09-19 15:57:23 UTC | 3 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.5 | 49727 | 172.217.13.141 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-09-19 15:57:23 UTC | 0 | OUT | |
2023-09-19 15:57:23 UTC | 1 | OUT | |
2023-09-19 15:57:23 UTC | 3 | IN | |
2023-09-19 15:57:23 UTC | 4 | IN | |
2023-09-19 15:57:23 UTC | 4 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.5 | 49729 | 167.89.115.121 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-09-19 15:57:25 UTC | 4 | OUT | |
2023-09-19 15:57:25 UTC | 6 | IN | |
2023-09-19 15:57:25 UTC | 6 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.5 | 49730 | 167.89.115.121 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-09-19 15:57:26 UTC | 6 | OUT | |
2023-09-19 15:57:26 UTC | 8 | IN | |
2023-09-19 15:57:26 UTC | 8 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 17:57:21 |
Start date: | 19/09/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71d210000 |
File size: | 3'219'224 bytes |
MD5 hash: | 8D1C4713ACB7CC2AAAEE4477C58A80BA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 17:57:21 |
Start date: | 19/09/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71d210000 |
File size: | 3'219'224 bytes |
MD5 hash: | 8D1C4713ACB7CC2AAAEE4477C58A80BA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 17:57:24 |
Start date: | 19/09/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71d210000 |
File size: | 3'219'224 bytes |
MD5 hash: | 8D1C4713ACB7CC2AAAEE4477C58A80BA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |