Windows
Analysis Report
https://www.coatsgolds.com/871rc5m/21748tpd?sub1=177772&sub2=14437210-6546&sub3=8676
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6340 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// www.coatsg olds.com/8 71rc5m/217 48tpd?sub1 =177772&su b2=1443721 0-6546&sub 3=8676 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6496 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2024 --fi eld-trial- handle=189 6,i,180302 0011266056 5471,16170 9462605779 05929,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.250.31.84 | true | false | high | |
www.coatsgolds.com | 45.41.205.104 | true | false | unknown | |
www.google.com | 172.253.122.99 | true | false | high | |
clients.l.google.com | 142.251.16.101 | true | false | high | |
clients1.google.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true | unknown | ||
false | high | ||
false |
| unknown | |
false | high | ||
false |
| unknown | |
false | high | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.16.101 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
172.253.122.99 | www.google.com | United States | 15169 | GOOGLEUS | false | |
45.41.205.104 | www.coatsgolds.com | Reserved | 22400 | WEB2OBJECTSUS | false | |
142.250.31.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
172.253.122.100 | unknown | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1346381 |
Start date and time: | 2023-11-22 12:52:00 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 18s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://www.coatsgolds.com/871rc5m/21748tpd?sub1=177772&sub2=14437210-6546&sub3=8676 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@14/9@10/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 142.251.163.94, 34.104.35.123, 192.229.211.108, 172.253.115.94
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.987540311478969 |
Encrypted: | false |
SSDEEP: | 48:8EddTFBGH5idAKZdA1FehwiZUklqehTy+3:8SHAgy |
MD5: | 760346EBFB51DBC21420D2538E4A7CEE |
SHA1: | 9330F46D0422EF975B23AAA3FD3BA4A43D062ED4 |
SHA-256: | AFCF7A25B3B8EC85CEA9E0E796086376399C63444BA77A655EC2B46D12046982 |
SHA-512: | BA7697CFA4E57664BBDD30848337E42BDD9399983C8BFD6DB3D9F63BF49A79F7CC4B413F5B1186E7BBFF3C98D08A8E5D234A9E867A70C315DBF354D986810558 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.005164584443692 |
Encrypted: | false |
SSDEEP: | 48:8/ddTFBGH5idAKZdA1seh/iZUkAQkqehQy+2:8HHW9Q5y |
MD5: | 6718ED11E7DBDDE441DAA5F1832D3B5C |
SHA1: | 428352DA12952A4AB933F5D6A18672860C163C4D |
SHA-256: | 23A81C324D50B942490EF6D26D713A3B80476EAEC7BC00CC58EDA809C49EDD17 |
SHA-512: | 0C223314C1C6D7D20D684FAA53F5B56E49E8E9307399D61508FBAE894C7B6DA30EB07DB3486B9A11E19584F5676B9F61AAF68F84C53B80A618DBC2EC611DF1EF |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.009960087141545 |
Encrypted: | false |
SSDEEP: | 48:8WddTFBAH5idAKZdA14meh7sFiZUkmgqeh7suy+BX:8UHgnsy |
MD5: | 8BD214C1116B993EE88104A8A4C59734 |
SHA1: | 406A6143BAD1B69185C1C9684591556362FD99C3 |
SHA-256: | 93287E77ADE16FF450EEB69234F4B782D4B292774C45F4BEB9A38CADF7CB1B27 |
SHA-512: | E9B4566FA71E52498F0ED1CECD7630C7FFB2594E0274B5B2C2C0C5F70648B6630B01D834D74964B0141956AE6BC3EF3008CF1C5750446CA552C57CF82A4E70CD |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.001359056895579 |
Encrypted: | false |
SSDEEP: | 48:8wddTFBGH5idAKZdA1TehDiZUkwqehUy+R:8uHN2y |
MD5: | A5F45F1FEE6469906E69306CA429450C |
SHA1: | E8B5C6C445DE8E452A4D6A3F58506EB60962C652 |
SHA-256: | ADB6BA22C94D772907A1AA417EBB5753AB24ADBC0F859F618BB24C4A313242C7 |
SHA-512: | 9F00BC071143DDEC9176A4C54EB444BA88F9A1C400F653D10EE7E5973D029C7C875942982F23ED69218E060676C8D47E824ED02F73E01B88D3E5B48CAD0D5BE4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9888390448942217 |
Encrypted: | false |
SSDEEP: | 48:8mddTFBGH5idAKZdA1dehBiZUk1W1qehqy+C:8EHt9Ky |
MD5: | F0154916DA027D451182E76B69453995 |
SHA1: | 6D2E91E2A2261D05ADDE245FE5B62C18251550F6 |
SHA-256: | 85EB1F58424D78C23D4CB1DD4F5113CDEF4D3A96DEF2F87820A3D09C6EB73F88 |
SHA-512: | 39613FF03877822FEA626C5B629FCC2E7E5311B790032D5D0617AB17970A8182563230320FE288F000E83BDAB8F33885DB76BD02539DF350DD1124A5E0397CDD |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.000711231211141 |
Encrypted: | false |
SSDEEP: | 48:8bddTFBGH5idAKZdA1duTeehOuTbbiZUk5OjqehOuTbsy+yT+:8THVTfTbxWOvTbsy7T |
MD5: | FE77675093DA84E93BB047B757113405 |
SHA1: | AE5077FC6A9A9A2382963912A0A6AC61632C9905 |
SHA-256: | 0B6E7C563F57B3F991BD4A54645F6E56519D50F09CF63ED1581B0B82B27734E9 |
SHA-512: | 3B73454E3E39F5355F8EDA7871953EB1E9187160AE16753899D7EFB4F6319386BB0D0A31B4EADBC1D1AD9AA0E363EF4A1FF9E8A5B04BE1C2A6309CD6059151D7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 237 |
Entropy (8bit): | 4.800429681621492 |
Encrypted: | false |
SSDEEP: | 6:Vw2OLbWZisyK4NnBHsL2YriFGHLTwGRVj9wGdUwWeXFEL13:u2SWMsyKonBHslriFuPwuj9w4UwzC3 |
MD5: | 32B8C4E739FBA93ED442CB3382D5D2BF |
SHA1: | B133DA95787FEE011682BA799F568AFAE0B8D2D5 |
SHA-256: | D82499DB4DE81CA02F529B00DDEC3C2B9596AFB0AD1C78B1A0666DA9287572F4 |
SHA-512: | AAEAFB2E97389E81E4765B90EAC152CEACEB56313C8FFD89D701ACD1BB567670F87070E44FB1A0D13A5A8F66E8DB67CC96EE59E53B363BFF8C4422ECB269870D |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=https%3A%2F%2Fwww.coatsgolds.com&oit=3&cp=26&pgcl=4&gs_rn=42&psi=oeT4fW2ixss-Ryo4&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1093 |
Entropy (8bit): | 4.64990449533814 |
Encrypted: | false |
SSDEEP: | 24:hYzp8bh5O+CUJsf01jJfVTZMCScfK5kdflM:8HUJThJE375kdflM |
MD5: | 06C162752EB53F3F96CF521841403E83 |
SHA1: | AEDB7942897DF887DD782679853AF317743B230D |
SHA-256: | B5E774A2B98F0517DB8C2938B05D51249897D4B853C39F62A5DAA5E2F61CDDFC |
SHA-512: | F900145138F5E6349A7268E9FEC21D6DD583DFAF8F2F38CFDF74942F2EF540839FC326F9181F2875561286822C10EC983E86D63A8C18CA910BBCC4FFCA81778F |
Malicious: | false |
Reputation: | low |
URL: | https://www.coatsgolds.com/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 548 |
Entropy (8bit): | 4.688532577858027 |
Encrypted: | false |
SSDEEP: | 12:TjeRHVIdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH68DTPTPTPTPTPTc |
MD5: | 370E16C3B7DBA286CFF055F93B9A94D8 |
SHA1: | 65F3537C3C798F7DA146C55AEF536F7B5D0CB943 |
SHA-256: | D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090 |
SHA-512: | 75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966 |
Malicious: | false |
Reputation: | low |
URL: | https://www.coatsgolds.com/favicon.ico |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 22, 2023 12:52:27.050872087 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:27.050968885 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:30.313982964 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.314075947 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.314157009 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.315006018 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.315049887 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.315113068 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.315745115 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.315769911 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.315834999 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.316056013 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.316071987 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.316286087 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.316323042 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.316687107 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.316710949 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.316776037 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.317049026 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.317079067 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.317280054 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.317295074 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.561389923 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.561682940 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.561708927 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.563146114 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.563227892 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.563440084 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.563848019 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.563864946 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.564243078 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.564275026 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.564306974 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.564348936 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.564728975 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.564739943 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.564933062 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.564992905 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.565834045 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.565902948 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.565998077 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.566010952 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.609688997 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.609690905 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.689786911 CET | 49673 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:30.689954996 CET | 49674 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:30.726272106 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.726294041 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.726603985 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.726625919 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.726742983 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.726800919 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.727658987 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.727783918 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.727840900 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.727932930 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.728797913 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.728858948 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.729053974 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.729121923 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.729299068 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.729305983 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.766098022 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.766227007 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.766283989 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.767079115 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Nov 22, 2023 12:52:30.767100096 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Nov 22, 2023 12:52:30.769680977 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.770253897 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.770266056 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.786114931 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.786245108 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.798000097 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.802227020 CET | 49722 | 443 | 192.168.2.16 | 142.250.31.84 |
Nov 22, 2023 12:52:30.802248955 CET | 443 | 49722 | 142.250.31.84 | 192.168.2.16 |
Nov 22, 2023 12:52:30.817686081 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.915590048 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.915633917 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:30.915678978 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.919070005 CET | 49720 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:30.919080019 CET | 443 | 49720 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:31.070715904 CET | 49672 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:34.657639027 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:34.657737017 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:34.657825947 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:34.658175945 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:34.658214092 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:34.847949028 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:34.848484993 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:34.848536015 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:34.849411011 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:34.849493027 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:34.851011992 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:34.851075888 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:34.896792889 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:34.896816015 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:34.944732904 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:40.711363077 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:40.711436033 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:40.711555958 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:41.396096945 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:41.396183014 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:41.396334887 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:41.402606964 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:41.402645111 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:41.732779026 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:41.886864901 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:41.887799025 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:41.887856960 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:41.887902021 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:41.887931108 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:41.887969971 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:41.888021946 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:41.888052940 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:41.888108969 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:41.898192883 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:41.898320913 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:41.901215076 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:41.901233912 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:41.901485920 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:41.946758986 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.008446932 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.053261042 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.233094931 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.331850052 CET | 49719 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:52:42.331942081 CET | 443 | 49719 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370631933 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370656013 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370661974 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370676041 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370712042 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370754004 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.370805979 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370847940 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370866060 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.370886087 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.370887041 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.370919943 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.385700941 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.393583059 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.393613100 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.393644094 CET | 49725 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:52:42.393656969 CET | 443 | 49725 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:52:42.394123077 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.394185066 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.396044970 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.396110058 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.396725893 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.396807909 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.549722910 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.549793005 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.549840927 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.549864054 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.549894094 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.552402020 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.593702078 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.593760967 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:42.593791962 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 12:52:42.593844891 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 12:52:44.885706902 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:44.885796070 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:52:44.885915041 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:46.340450048 CET | 49724 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:52:46.340485096 CET | 443 | 49724 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:17.143110991 CET | 49712 | 80 | 192.168.2.16 | 72.21.81.240 |
Nov 22, 2023 12:53:17.234543085 CET | 80 | 49712 | 72.21.81.240 | 192.168.2.16 |
Nov 22, 2023 12:53:17.234695911 CET | 49712 | 80 | 192.168.2.16 | 72.21.81.240 |
Nov 22, 2023 12:53:18.870141983 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:18.870187998 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:18.870418072 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:18.871247053 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:18.871264935 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.372747898 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.372997999 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.377043962 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.377054930 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.377475977 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.379226923 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.421286106 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.844831944 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.844939947 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.844983101 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.845159054 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.845159054 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.845179081 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.845189095 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.845262051 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.845269918 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.845318079 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.845321894 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.845374107 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.849297047 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.849312067 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:19.849342108 CET | 49727 | 443 | 192.168.2.16 | 20.114.59.183 |
Nov 22, 2023 12:53:19.849347115 CET | 443 | 49727 | 20.114.59.183 | 192.168.2.16 |
Nov 22, 2023 12:53:34.587301970 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:34.587349892 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:34.587609053 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:34.588205099 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:34.588217974 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:34.800910950 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:34.801314116 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:34.801332951 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:34.801815033 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:34.802304983 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:34.802382946 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:34.855974913 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:38.825500965 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:38.869260073 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:38.961119890 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:38.964237928 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:38.964344978 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:38.965521097 CET | 49729 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:53:38.965538025 CET | 443 | 49729 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:53:39.569520950 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.569561005 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.569672108 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.569785118 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.569814920 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.569895029 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.570691109 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.570703030 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.571177006 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.571193933 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.800199986 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.804629087 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.809556961 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.809580088 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.809657097 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.809669018 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.810009956 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.810729980 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.811244011 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.811314106 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.811486959 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.811614990 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:39.811664104 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.853262901 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:39.863899946 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:40.121768951 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:40.121841908 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:40.121999979 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:40.153587103 CET | 49731 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:40.153604984 CET | 443 | 49731 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:40.211971045 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:40.253266096 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:40.382896900 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:40.383002043 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:40.383119106 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:40.383753061 CET | 49730 | 443 | 192.168.2.16 | 45.41.205.104 |
Nov 22, 2023 12:53:40.383768082 CET | 443 | 49730 | 45.41.205.104 | 192.168.2.16 |
Nov 22, 2023 12:53:59.662760019 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.662785053 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.662866116 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.663501024 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.663511992 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.868190050 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.868724108 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.868745089 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.870304108 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.870464087 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.870913029 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.871001005 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.873461008 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.873516083 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.873699903 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:53:59.873707056 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:53:59.921044111 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:54:00.071038961 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:54:00.071969032 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:54:00.072175026 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:54:00.072230101 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.100 |
Nov 22, 2023 12:54:00.072244883 CET | 443 | 49733 | 172.253.122.100 | 192.168.2.16 |
Nov 22, 2023 12:54:09.377460003 CET | 49714 | 443 | 192.168.2.16 | 23.223.36.114 |
Nov 22, 2023 12:54:09.468969107 CET | 443 | 49714 | 23.223.36.114 | 192.168.2.16 |
Nov 22, 2023 12:54:09.468992949 CET | 443 | 49714 | 23.223.36.114 | 192.168.2.16 |
Nov 22, 2023 12:54:09.469072104 CET | 49714 | 443 | 192.168.2.16 | 23.223.36.114 |
Nov 22, 2023 12:54:09.469136000 CET | 49714 | 443 | 192.168.2.16 | 23.223.36.114 |
Nov 22, 2023 12:54:10.096400976 CET | 49716 | 443 | 192.168.2.16 | 23.223.36.114 |
Nov 22, 2023 12:54:10.189685106 CET | 443 | 49716 | 23.223.36.114 | 192.168.2.16 |
Nov 22, 2023 12:54:10.189706087 CET | 443 | 49716 | 23.223.36.114 | 192.168.2.16 |
Nov 22, 2023 12:54:10.189852953 CET | 49716 | 443 | 192.168.2.16 | 23.223.36.114 |
Nov 22, 2023 12:54:10.189891100 CET | 49716 | 443 | 192.168.2.16 | 23.223.36.114 |
Nov 22, 2023 12:54:34.651519060 CET | 49734 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:54:34.651567936 CET | 443 | 49734 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:54:34.651670933 CET | 49734 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:54:34.652033091 CET | 49734 | 443 | 192.168.2.16 | 172.253.122.99 |
Nov 22, 2023 12:54:34.652048111 CET | 443 | 49734 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:54:34.839379072 CET | 443 | 49734 | 172.253.122.99 | 192.168.2.16 |
Nov 22, 2023 12:54:34.889940977 CET | 49734 | 443 | 192.168.2.16 | 172.253.122.99 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 22, 2023 12:52:30.163250923 CET | 56725 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:30.163569927 CET | 54285 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:30.172565937 CET | 64225 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:30.172926903 CET | 62988 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:30.173463106 CET | 63963 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:30.173804998 CET | 56317 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:30.300273895 CET | 53 | 56611 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:30.306849003 CET | 53 | 54285 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:30.309457064 CET | 53 | 56725 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:30.312424898 CET | 53 | 64225 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:30.312912941 CET | 53 | 63963 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:30.313676119 CET | 53 | 56317 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:30.315118074 CET | 53 | 62988 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:30.957029104 CET | 53 | 64787 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:34.530663967 CET | 64169 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:34.530834913 CET | 61965 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:52:34.651403904 CET | 53 | 64169 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:34.652028084 CET | 53 | 61965 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:52:43.021344900 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Nov 22, 2023 12:52:47.931502104 CET | 53 | 60731 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:53:06.779838085 CET | 53 | 52964 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:53:29.363640070 CET | 53 | 59741 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:53:29.860517979 CET | 53 | 56972 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:53:57.425666094 CET | 53 | 63696 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:53:59.540339947 CET | 51914 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:53:59.540868044 CET | 65353 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 12:53:59.661550999 CET | 53 | 51914 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 12:53:59.662059069 CET | 53 | 65353 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 22, 2023 12:52:30.163250923 CET | 192.168.2.16 | 1.1.1.1 | 0xf102 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 12:52:30.163569927 CET | 192.168.2.16 | 1.1.1.1 | 0xee7e | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 12:52:30.172565937 CET | 192.168.2.16 | 1.1.1.1 | 0xaea0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 12:52:30.172926903 CET | 192.168.2.16 | 1.1.1.1 | 0x6653 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 12:52:30.173463106 CET | 192.168.2.16 | 1.1.1.1 | 0xce6e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 12:52:30.173804998 CET | 192.168.2.16 | 1.1.1.1 | 0xf729 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 12:52:34.530663967 CET | 192.168.2.16 | 1.1.1.1 | 0xd2fd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 12:52:34.530834913 CET | 192.168.2.16 | 1.1.1.1 | 0x6e33 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 12:53:59.540339947 CET | 192.168.2.16 | 1.1.1.1 | 0xd832 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 12:53:59.540868044 CET | 192.168.2.16 | 1.1.1.1 | 0x86f4 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 22, 2023 12:52:30.309457064 CET | 1.1.1.1 | 192.168.2.16 | 0xf102 | No error (0) | 45.41.205.104 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312424898 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312424898 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | 142.251.16.101 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312424898 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | 142.251.16.102 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312424898 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | 142.251.16.100 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312424898 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | 142.251.16.139 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312424898 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | 142.251.16.138 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312424898 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | 142.251.16.113 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.312912941 CET | 1.1.1.1 | 192.168.2.16 | 0xce6e | No error (0) | 142.250.31.84 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:30.315118074 CET | 1.1.1.1 | 192.168.2.16 | 0x6653 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:34.651403904 CET | 1.1.1.1 | 192.168.2.16 | 0xd2fd | No error (0) | 172.253.122.99 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:34.651403904 CET | 1.1.1.1 | 192.168.2.16 | 0xd2fd | No error (0) | 172.253.122.147 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:34.651403904 CET | 1.1.1.1 | 192.168.2.16 | 0xd2fd | No error (0) | 172.253.122.104 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:34.651403904 CET | 1.1.1.1 | 192.168.2.16 | 0xd2fd | No error (0) | 172.253.122.103 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:34.651403904 CET | 1.1.1.1 | 192.168.2.16 | 0xd2fd | No error (0) | 172.253.122.106 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:34.651403904 CET | 1.1.1.1 | 192.168.2.16 | 0xd2fd | No error (0) | 172.253.122.105 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:52:34.652028084 CET | 1.1.1.1 | 192.168.2.16 | 0x6e33 | No error (0) | 65 | IN (0x0001) | false | |||
Nov 22, 2023 12:53:59.661550999 CET | 1.1.1.1 | 192.168.2.16 | 0xd832 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 22, 2023 12:53:59.661550999 CET | 1.1.1.1 | 192.168.2.16 | 0xd832 | No error (0) | 172.253.122.100 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:53:59.661550999 CET | 1.1.1.1 | 192.168.2.16 | 0xd832 | No error (0) | 172.253.122.101 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:53:59.661550999 CET | 1.1.1.1 | 192.168.2.16 | 0xd832 | No error (0) | 172.253.122.113 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:53:59.661550999 CET | 1.1.1.1 | 192.168.2.16 | 0xd832 | No error (0) | 172.253.122.139 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:53:59.661550999 CET | 1.1.1.1 | 192.168.2.16 | 0xd832 | No error (0) | 172.253.122.102 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:53:59.661550999 CET | 1.1.1.1 | 192.168.2.16 | 0xd832 | No error (0) | 172.253.122.138 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 12:53:59.662059069 CET | 1.1.1.1 | 192.168.2.16 | 0x86f4 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false |
|
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Nov 22, 2023 12:52:41.887969971 CET | 23.1.237.25 | 443 | 192.168.2.16 | 49703 | CN=r.bing.com, O=Microsoft Corporation, L=Redmond, ST=WA, C=US CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Oct 18 22:32:40 CEST 2023 Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 Fri Jun 28 01:59:59 CEST 2024 | 771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-16-23-65281,29-23-24,0 | 28a2c9bd18a11de089ef85a160da29e4 |
CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49722 | 142.250.31.84 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:52:30 UTC | 680 | OUT | |
2023-11-22 11:52:30 UTC | 1 | OUT | |
2023-11-22 11:52:30 UTC | 1627 | IN | |
2023-11-22 11:52:30 UTC | 23 | IN | |
2023-11-22 11:52:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49721 | 142.251.16.101 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:52:30 UTC | 752 | OUT | |
2023-11-22 11:52:30 UTC | 732 | IN | |
2023-11-22 11:52:30 UTC | 520 | IN | |
2023-11-22 11:52:30 UTC | 200 | IN | |
2023-11-22 11:52:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49720 | 45.41.205.104 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:52:30 UTC | 718 | OUT | |
2023-11-22 11:52:30 UTC | 225 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49719 | 45.41.205.104 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:52:40 UTC | 102 | IN | |
2023-11-22 11:52:40 UTC | 110 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49725 | 20.114.59.183 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:52:42 UTC | 306 | OUT | |
2023-11-22 11:52:42 UTC | 560 | IN | |
2023-11-22 11:52:42 UTC | 15824 | IN | |
2023-11-22 11:52:42 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49727 | 20.114.59.183 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:53:19 UTC | 306 | OUT | |
2023-11-22 11:53:19 UTC | 560 | IN | |
2023-11-22 11:53:19 UTC | 15824 | IN | |
2023-11-22 11:53:19 UTC | 9633 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49729 | 172.253.122.99 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:53:38 UTC | 868 | OUT | |
2023-11-22 11:53:38 UTC | 1880 | IN | |
2023-11-22 11:53:38 UTC | 243 | IN | |
2023-11-22 11:53:38 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49731 | 45.41.205.104 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:53:39 UTC | 661 | OUT | |
2023-11-22 11:53:40 UTC | 279 | IN | |
2023-11-22 11:53:40 UTC | 1093 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49730 | 45.41.205.104 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:53:40 UTC | 651 | OUT | |
2023-11-22 11:53:40 UTC | 143 | IN | |
2023-11-22 11:53:40 UTC | 548 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.16 | 49733 | 172.253.122.100 | 443 | 6496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 11:53:59 UTC | 453 | OUT | |
2023-11-22 11:54:00 UTC | 817 | IN | |
2023-11-22 11:54:00 UTC | 240 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 12:52:28 |
Start date: | 22/11/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 12:52:28 |
Start date: | 22/11/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |