Windows
Analysis Report
http://x1.c.lencr.org
Overview
Detection
Score: | 20 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 3492 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 3236 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2108 --fi eld-trial- handle=194 8,i,173101 3787910947 869,116878 5939711100 7845,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) rundll32.exe (PID: 7104 cmdline:
"C:\Window s\system32 \rundll32. exe" crypt ext.dll,Cr yptExtOpen CRL C:\Use rs\user\Do wnloads\do wnload.crl MD5: EF3179D498793BF4234F708D3BE28633)
chrome.exe (PID: 6488 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http ://x1.c.le ncr.org MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
- • Hooking and other Techniques for Hiding and Protection
Click to jump to signature section
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Software Vulnerabilities |
---|
Source: | Child: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window detected: |
Source: | Process information set: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 1 Exploitation for Client Execution | Path Interception | 1 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Rundll32 | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 1 Ingress Tool Transfer | SIM Card Swap | Carrier Billing Fraud |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 172.253.62.84 | true | false | high | |
www.google.com | 172.253.115.105 | true | false | high | |
clients.l.google.com | 172.253.63.100 | true | false | high | |
clients2.google.com | unknown | unknown | false | high | |
x1.c.lencr.org | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.253.115.105 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.253.62.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
172.253.63.100 | clients.l.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.8 |
192.168.2.7 |
192.168.2.9 |
192.168.2.4 |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1330823 |
Start date and time: | 2023-10-23 22:05:05 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://x1.c.lencr.org |
Analysis system description: | Windows 10 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus20.expl.win@19/3@8/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, B ackgroundTransferHost.exe, WMI ADAP.exe, SIHClient.exe, backg roundTaskHost.exe, conhost.exe , svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.16.94, 34. 104.35.123, 104.108.107.41, 19 2.229.211.108 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, e8652.dscx.akamaiedge.net, ocsp.digicert.com, edgedl.me. gvt1.com, slscr.update.microso ft.com, update.googleapis.com, clientservices.googleapis.com , fe3cr.delivery.mp.microsoft. com, crl.root-x1.letsencrypt.o rg.edgekey.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtProtectVirtualMemory calls found. - VT rate limit hit for: http:/
/x1.c.lencr.org
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 717 |
Entropy (8bit): | 7.5050705422409765 |
Encrypted: | false |
SSDEEP: | 12:mmSc27TqU0YW/FQgCYTpZf0ZqAZvQqdVleICckto0G+4jR6qmgOGErkoLHj:YXfimgCYTpZfKtZvQuCcktoJ3OGe3rj |
MD5: | 60FE01DF86BE2E5331B0CDBE86165686 |
SHA1: | 2A79F9713C3F192862FF80508062E64E8E0B29BD |
SHA-256: | C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8 |
SHA-512: | EF9F9A4DEDCBFE339F4F3D07FB614645596C6F2B15608BDCCDAD492578B735F7CB075BDAA07178C764582EE345857EC4665F90342694E6A60786BB3D9B3A3D23 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 717 |
Entropy (8bit): | 7.5050705422409765 |
Encrypted: | false |
SSDEEP: | 12:mmSc27TqU0YW/FQgCYTpZf0ZqAZvQqdVleICckto0G+4jR6qmgOGErkoLHj:YXfimgCYTpZfKtZvQuCcktoJ3OGe3rj |
MD5: | 60FE01DF86BE2E5331B0CDBE86165686 |
SHA1: | 2A79F9713C3F192862FF80508062E64E8E0B29BD |
SHA-256: | C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8 |
SHA-512: | EF9F9A4DEDCBFE339F4F3D07FB614645596C6F2B15608BDCCDAD492578B735F7CB075BDAA07178C764582EE345857EC4665F90342694E6A60786BB3D9B3A3D23 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 738 |
Entropy (8bit): | 7.674122582943747 |
Encrypted: | false |
SSDEEP: | 12:XgM4BY+/H3+3SauRoQffkyFxPKJMguXgyqmM1qhNMerekIp4/eQmHG7yl1:XgMeY+/OFKoCjPKyUhmMANMetA3N31 |
MD5: | 1445914CF81596B8601950AF3317BBE4 |
SHA1: | CDB9E75488A6111B591873C14419B8836A48DBBF |
SHA-256: | 5A59FB3D743DD245EE7F0C8FEDF45BF7764EBBD20E32DC631232DC6AFABAA0E7 |
SHA-512: | 8C705E373403150D2F5332CCE3B5CC21FA20831CF685C8E4D5B9D3F10AD8BC59BB38EA940BE1F564B0D4B742BBDC4074D2EB60D5C230EBE951B5B42D074409FC |
Malicious: | false |
Reputation: | low |
URL: | http://x1.c.lencr.org/ |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 105
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 23, 2023 22:05:55.357923985 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Oct 23, 2023 22:06:05.390516996 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.390564919 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.390631914 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.391330004 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.391345024 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.391766071 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.391813040 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.391877890 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.392050028 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.392066002 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.638258934 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.638358116 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.638942957 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.638958931 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.639060020 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.639076948 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.639499903 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.639581919 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.640942097 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.640975952 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.641019106 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.641105890 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.642162085 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.642252922 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.642416000 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.642426014 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.642539024 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.642630100 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.642750978 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.685033083 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.686460018 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.747551918 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.747575998 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.834645033 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.835092068 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.835155964 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.835391998 CEST | 49737 | 443 | 192.168.2.4 | 172.253.63.100 |
Oct 23, 2023 22:06:05.835413933 CEST | 443 | 49737 | 172.253.63.100 | 192.168.2.4 |
Oct 23, 2023 22:06:05.859751940 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.859857082 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.859890938 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.859999895 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:05.860049963 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.860838890 CEST | 49738 | 443 | 192.168.2.4 | 172.253.62.84 |
Oct 23, 2023 22:06:05.860856056 CEST | 443 | 49738 | 172.253.62.84 | 192.168.2.4 |
Oct 23, 2023 22:06:09.345350027 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:09.345387936 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:09.345475912 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:09.345952988 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:09.345966101 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:09.559221983 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:09.571367979 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:09.571398020 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:09.573112965 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:09.573230982 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:09.575139046 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:09.575242043 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:09.622364044 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:09.622379065 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:09.669050932 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:10.150435925 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.150474072 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.150566101 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.161700010 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.161716938 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.514583111 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.514717102 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.543853998 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.543890953 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.544907093 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.607007980 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.625962973 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.666455030 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.833631039 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.833713055 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.833797932 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.833915949 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.833940029 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.833954096 CEST | 49747 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.833961964 CEST | 443 | 49747 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.894701958 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.894747972 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:10.894839048 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.895518064 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:10.895534039 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.224450111 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.224561930 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:11.229607105 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:11.229617119 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.229962111 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.231729031 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:11.278453112 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.544075012 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.544146061 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.544250011 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:11.547725916 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:11.547749996 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:11.547790051 CEST | 49748 | 443 | 192.168.2.4 | 23.52.160.85 |
Oct 23, 2023 22:06:11.547799110 CEST | 443 | 49748 | 23.52.160.85 | 192.168.2.4 |
Oct 23, 2023 22:06:19.309942007 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:19.310010910 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:19.310113907 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:19.313771009 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:19.313796997 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:19.555176020 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:19.555335999 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:19.555402040 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:19.879440069 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:19.879539013 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:19.882385969 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:19.882415056 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:19.882838011 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:19.934969902 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.025887966 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.066462040 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.412750959 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.412813902 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.412832975 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.412851095 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.412889004 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.412908077 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.412950039 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.413009882 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.413032055 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.413065910 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.413115978 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.413187981 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.413207054 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.413326025 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.413383961 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.439491034 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.439522028 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:20.439538956 CEST | 49749 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:20.439548016 CEST | 443 | 49749 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:21.485707045 CEST | 49746 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:06:21.485728025 CEST | 443 | 49746 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:06:50.314038992 CEST | 49732 | 443 | 192.168.2.4 | 204.79.197.200 |
Oct 23, 2023 22:06:57.005323887 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:57.005372047 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:57.005439043 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:57.007112026 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:57.007132053 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:57.565066099 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:57.565218925 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:57.567434072 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:57.567442894 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:57.567910910 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:57.570175886 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:57.610476017 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.099862099 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.099931002 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.099975109 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.100012064 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.100039959 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.100075006 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.100083113 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.100300074 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.100354910 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.100373030 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.100377083 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.100415945 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.100423098 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.100498915 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.100548029 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.105109930 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.105127096 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:06:58.105160952 CEST | 49751 | 443 | 192.168.2.4 | 40.68.123.157 |
Oct 23, 2023 22:06:58.105166912 CEST | 443 | 49751 | 40.68.123.157 | 192.168.2.4 |
Oct 23, 2023 22:07:06.966346979 CEST | 49723 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:06.966465950 CEST | 49724 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:06.966547012 CEST | 49731 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:06.966665030 CEST | 49735 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:07.059173107 CEST | 80 | 49723 | 72.21.81.240 | 192.168.2.4 |
Oct 23, 2023 22:07:07.059431076 CEST | 49723 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:07.059487104 CEST | 80 | 49724 | 72.21.81.240 | 192.168.2.4 |
Oct 23, 2023 22:07:07.059541941 CEST | 49724 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:07.059809923 CEST | 80 | 49735 | 72.21.81.240 | 192.168.2.4 |
Oct 23, 2023 22:07:07.059878111 CEST | 49735 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:07.060751915 CEST | 80 | 49731 | 72.21.81.240 | 192.168.2.4 |
Oct 23, 2023 22:07:07.060806990 CEST | 49731 | 80 | 192.168.2.4 | 72.21.81.240 |
Oct 23, 2023 22:07:09.311897039 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:09.311949968 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:09.312057018 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:09.312525034 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:09.312541008 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:09.536962032 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:09.537307024 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:09.537353039 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:09.538060904 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:09.538491011 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:09.538589954 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:09.577860117 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:19.526343107 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:19.526508093 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Oct 23, 2023 22:07:19.526576996 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:21.469604969 CEST | 49753 | 443 | 192.168.2.4 | 172.253.115.105 |
Oct 23, 2023 22:07:21.469639063 CEST | 443 | 49753 | 172.253.115.105 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 23, 2023 22:06:05.290811062 CEST | 56567 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:05.293432951 CEST | 55566 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:05.294219017 CEST | 52850 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:05.295670986 CEST | 56531 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:05.367764950 CEST | 53 | 58136 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:05.385281086 CEST | 53 | 56567 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:05.388209105 CEST | 53 | 52850 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:05.388842106 CEST | 53 | 55566 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:05.390383005 CEST | 53 | 56531 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:05.979923964 CEST | 53 | 65118 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:06.736990929 CEST | 56436 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:06.737298012 CEST | 51999 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:09.249569893 CEST | 56549 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:09.249825954 CEST | 52783 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 23, 2023 22:06:09.343574047 CEST | 53 | 56549 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:09.344050884 CEST | 53 | 52783 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:18.570867062 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Oct 23, 2023 22:06:23.094253063 CEST | 53 | 50773 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:06:42.227381945 CEST | 53 | 64246 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:07:04.763765097 CEST | 53 | 56384 | 1.1.1.1 | 192.168.2.4 |
Oct 23, 2023 22:07:04.959487915 CEST | 53 | 50225 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 23, 2023 22:06:05.290811062 CEST | 192.168.2.4 | 1.1.1.1 | 0xef5e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 23, 2023 22:06:05.293432951 CEST | 192.168.2.4 | 1.1.1.1 | 0x1bd5 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 23, 2023 22:06:05.294219017 CEST | 192.168.2.4 | 1.1.1.1 | 0xe9fb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 23, 2023 22:06:05.295670986 CEST | 192.168.2.4 | 1.1.1.1 | 0xdbe8 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 23, 2023 22:06:06.736990929 CEST | 192.168.2.4 | 1.1.1.1 | 0xea3f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 23, 2023 22:06:06.737298012 CEST | 192.168.2.4 | 1.1.1.1 | 0xada7 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 23, 2023 22:06:09.249569893 CEST | 192.168.2.4 | 1.1.1.1 | 0xde25 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 23, 2023 22:06:09.249825954 CEST | 192.168.2.4 | 1.1.1.1 | 0xe394 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 23, 2023 22:06:05.385281086 CEST | 1.1.1.1 | 192.168.2.4 | 0xef5e | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.385281086 CEST | 1.1.1.1 | 192.168.2.4 | 0xef5e | No error (0) | 172.253.63.100 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.385281086 CEST | 1.1.1.1 | 192.168.2.4 | 0xef5e | No error (0) | 172.253.63.101 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.385281086 CEST | 1.1.1.1 | 192.168.2.4 | 0xef5e | No error (0) | 172.253.63.113 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.385281086 CEST | 1.1.1.1 | 192.168.2.4 | 0xef5e | No error (0) | 172.253.63.102 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.385281086 CEST | 1.1.1.1 | 192.168.2.4 | 0xef5e | No error (0) | 172.253.63.138 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.385281086 CEST | 1.1.1.1 | 192.168.2.4 | 0xef5e | No error (0) | 172.253.63.139 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.388209105 CEST | 1.1.1.1 | 192.168.2.4 | 0xe9fb | No error (0) | 172.253.62.84 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:05.388842106 CEST | 1.1.1.1 | 192.168.2.4 | 0x1bd5 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:06.832247972 CEST | 1.1.1.1 | 192.168.2.4 | 0xea3f | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:06.841778040 CEST | 1.1.1.1 | 192.168.2.4 | 0xada7 | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:09.343574047 CEST | 1.1.1.1 | 192.168.2.4 | 0xde25 | No error (0) | 172.253.115.105 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:09.343574047 CEST | 1.1.1.1 | 192.168.2.4 | 0xde25 | No error (0) | 172.253.115.147 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:09.343574047 CEST | 1.1.1.1 | 192.168.2.4 | 0xde25 | No error (0) | 172.253.115.99 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:09.343574047 CEST | 1.1.1.1 | 192.168.2.4 | 0xde25 | No error (0) | 172.253.115.103 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:09.343574047 CEST | 1.1.1.1 | 192.168.2.4 | 0xde25 | No error (0) | 172.253.115.104 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:09.343574047 CEST | 1.1.1.1 | 192.168.2.4 | 0xde25 | No error (0) | 172.253.115.106 | A (IP address) | IN (0x0001) | false | ||
Oct 23, 2023 22:06:09.344050884 CEST | 1.1.1.1 | 192.168.2.4 | 0xe394 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.4 | 49737 | 172.253.63.100 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:05 UTC | 0 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.4 | 49738 | 172.253.62.84 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:05 UTC | 0 | OUT | |
2023-10-23 20:06:05 UTC | 1 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 172.253.63.100 | 443 | 192.168.2.4 | 49737 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:05 UTC | 1 | IN | |
2023-10-23 20:06:05 UTC | 2 | IN | |
2023-10-23 20:06:05 UTC | 2 | IN | |
2023-10-23 20:06:05 UTC | 2 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 172.253.62.84 | 443 | 192.168.2.4 | 49738 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:05 UTC | 2 | IN | |
2023-10-23 20:06:05 UTC | 4 | IN | |
2023-10-23 20:06:05 UTC | 4 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
4 | 192.168.2.4 | 49747 | 23.52.160.85 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:10 UTC | 4 | OUT | |
2023-10-23 20:06:10 UTC | 4 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
5 | 192.168.2.4 | 49748 | 23.52.160.85 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:11 UTC | 5 | OUT | |
2023-10-23 20:06:11 UTC | 5 | IN | |
2023-10-23 20:06:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
6 | 192.168.2.4 | 49749 | 40.68.123.157 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:20 UTC | 5 | OUT | |
2023-10-23 20:06:20 UTC | 6 | IN | |
2023-10-23 20:06:20 UTC | 6 | IN | |
2023-10-23 20:06:20 UTC | 22 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
7 | 192.168.2.4 | 49751 | 40.68.123.157 | 443 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-10-23 20:06:57 UTC | 30 | OUT | |
2023-10-23 20:06:58 UTC | 30 | IN | |
2023-10-23 20:06:58 UTC | 31 | IN | |
2023-10-23 20:06:58 UTC | 46 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 22:05:59 |
Start date: | 23/10/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 22:06:02 |
Start date: | 23/10/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 22:06:05 |
Start date: | 23/10/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 22:06:09 |
Start date: | 23/10/2023 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6a8a90000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |