Windows
Analysis Report
https://cadtutorial.org
Overview
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 3088 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// cadtutoria l.org/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6524 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2084 --fi eld-trial- handle=204 4,i,799234 7479787974 455,184463 1474209485 1320,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
1% | Virustotal | Browse | ||
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering | ||
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
1% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
1% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.251.111.84 | true | false | high | |
cadtutorial.org | 103.211.239.20 | true | false |
| unknown |
www.google.com | 172.253.122.104 | true | false | high | |
clients.l.google.com | 142.251.16.102 | true | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | high | ||
false |
| unknown | |
false |
| unknown | |
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.253.122.104 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.111.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
142.251.16.102 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
103.211.239.20 | cadtutorial.org | Malaysia | 45144 | NETONBOARD-MYNetOnboardSdnBhd-QualityReliableCloud | false |
IP |
---|
192.168.2.30 |
192.168.2.102 |
192.168.2.16 |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1346425 |
Start date and time: | 2023-11-22 15:03:06 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 29s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://cadtutorial.org |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@13/7@10/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 172.253.62.94, 34.104.35.123, 192.229.211.108, 172.253.63.94
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.974111864195241 |
Encrypted: | false |
SSDEEP: | 48:8Td0T40BH+idAKZdA1FehwiZUklqehHy+3:8e3Koy |
MD5: | C3002ABC10B35AAFFB7A74E6A96A334A |
SHA1: | 744F334639F05CC88041983DA4C79ED98965A5BC |
SHA-256: | B4D15323AFED267200F9A4D82BAB96F7FE1305A1EA4A71C36E0BE0962E7DA602 |
SHA-512: | 394B4F62E5479D1937DD7283D7CC4F71FBE7CCF388B056841545C8BD56359FD0985FDEFB515B5280EF0D0E7C7371DD0C93DCD175AF765A342A9C24C5925700F7 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9903090400810166 |
Encrypted: | false |
SSDEEP: | 48:89d0T40BH+idAKZdA1seh/iZUkAQkqehYy+2:8k3k9QBy |
MD5: | 856E178FA56ADA71591CD168C5CB03AA |
SHA1: | BDCA426EE663D7FB6C853BBC31627E32465812D4 |
SHA-256: | 81BA73D3D08154BED04BFAFA73742A4E554E6BB1D7F576349A90206E085D4F4D |
SHA-512: | C23BDEE59A50B19A89FCD053A514FEE777A6271D96D26D1381CC1AC4DA621D8151AC5B55D86324913135A0C120BA2BBD207713752383E00908129CDD21FEA413 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 3.9989363582772435 |
Encrypted: | false |
SSDEEP: | 48:8xd0T40AH+idAKZdA14meh7sFiZUkmgqeh7sqy+BX:8Y3Pn0y |
MD5: | AAFDF6964A07617FECAFE16C9771D70F |
SHA1: | 34DE1701DFDAC6726EC33F61D935DAB7ECF16323 |
SHA-256: | F426D12A66085D3DD6880D81386ECBDD7ADF1ACAA9953306A16B463C356E276B |
SHA-512: | 3D1ECC03E28D7130F3A4AC79CC5D0C4667984A04412B388F5BEA8E2B3A786EEFFD5C0C532A14E47C11D173F8E801432EB899D282F2EDCE13C047485A29DFF501 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.989425005877286 |
Encrypted: | false |
SSDEEP: | 48:8Kd0T40BH+idAKZdA1TehDiZUkwqeh8y+R:8d3/yy |
MD5: | FB5DE28BE92EEAFB1D6BDB1A5EA31BFA |
SHA1: | B21D90CB1D95A3CDC98C1325A40D22408B3BABC5 |
SHA-256: | 14D989057B6F16B9A3CE2ED43BF7C4A93A728D6C880B83903BC48DB47DCD2002 |
SHA-512: | 7D9ED7F9227E8E09D7DAEDC50E24C2F6E431E28AF6C8860D548E9BCF4A25814786BC179B9612957B9CFEC226E89DFD8F36EFC8BC7BAAF6E642098EEB4C0AEF56 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.979448768401295 |
Encrypted: | false |
SSDEEP: | 48:8ed0T40BH+idAKZdA1dehBiZUk1W1qehWy+C:8R3f92y |
MD5: | EB42FD0DE459298F508EEAF3A0861FB4 |
SHA1: | DA6709B78DF09041F206F85CE3ABF58D7D95B3E3 |
SHA-256: | E2A2EE75BC1CAD62494A20C2C490705B59F75170FD7F43C21102335BE1C57BA6 |
SHA-512: | C997D31ED32A47F3C968D398412E343D0EE4281240BCDA6304E97D8BF7486D00360D4C3B5A959C98F3BC15EE087195EBFC0A22CC72469C7A216F644B5CDC8497 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.985084174939121 |
Encrypted: | false |
SSDEEP: | 48:8td0T40BH+idAKZdA1duTeehOuTbbiZUk5OjqehOuTb0y+yT+:8U3jTfTbxWOvTb0y7T |
MD5: | 927B15B9241E9CB626F7F055F2FBA17C |
SHA1: | CD6B66E2DFE3ACC11C79B62E5E142D542A4F55FB |
SHA-256: | 206A3E593B2A095925C84A8C2B933AEA31E6A8E04A2814CE7FCFA6FC729153C2 |
SHA-512: | 11588F2C7036BCD63A2C58E94DBF54B39035F7F9F924F332B1343F14904C9A6A7B57F86D6B6448F6AA7A6B43F344C410BFB91BDC8689C5EAB345AFAE68FD831C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 800 |
Entropy (8bit): | 5.132169357978193 |
Encrypted: | false |
SSDEEP: | 24:bLJTNz7ZppR9mBHslgT9lCuABuoB7HHHHHHHYqmffffffo:bLfZp9mKlgZ01BuSEqmffffffo |
MD5: | DC03E25F2E2C6AAA296EF85E9B639958 |
SHA1: | E25EA34BD945E6DAD7488C15D9050C05F03A0AFA |
SHA-256: | B286D64D3277192943AFD33623512E069AD911B5CF267904D4A74BBFAB51B44A |
SHA-512: | 4523F2D005F7314BCEAE35262BDFCD9C074048BFBB5E9FDD8503D01C3350746AE92C840B3BCCF440AA7369FC6B70ABFE66936AD946382CEC57B81BBDEBA0BC49 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 22, 2023 15:03:33.007211924 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:33.007390022 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:36.727921009 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:36.728013992 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:36.728113890 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:36.728702068 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:36.728730917 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:36.729270935 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:36.729314089 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:36.729377031 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:36.729655981 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:36.729682922 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:36.799014091 CET | 49674 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:36.799043894 CET | 49673 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:37.107753992 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.108431101 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.108454943 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.108798027 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.108860016 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.109499931 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.109546900 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.111960888 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.112009048 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.112143040 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.112148046 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.113234043 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.113414049 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.113440990 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.114485979 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.114559889 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.115876913 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.116144896 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.116154909 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.117218971 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.163002014 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.163002014 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.163038969 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.195076942 CET | 49672 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:37.210999966 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.243232965 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:37.243279934 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:37.243391037 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:37.245194912 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:37.245235920 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:37.245296955 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:37.246706963 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:37.246718884 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:37.247384071 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:37.247407913 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:37.513328075 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.513457060 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.513516903 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.514076948 CET | 49720 | 443 | 192.168.2.16 | 142.251.16.102 |
Nov 22, 2023 15:03:37.514090061 CET | 443 | 49720 | 142.251.16.102 | 192.168.2.16 |
Nov 22, 2023 15:03:37.532982111 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.533118963 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:37.533194065 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.534117937 CET | 49721 | 443 | 192.168.2.16 | 142.251.111.84 |
Nov 22, 2023 15:03:37.534140110 CET | 443 | 49721 | 142.251.111.84 | 192.168.2.16 |
Nov 22, 2023 15:03:39.288027048 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.288319111 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.288333893 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.289520025 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.289589882 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.290653944 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.290736914 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.290920973 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.290926933 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.315242052 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.315634012 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.315658092 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.316674948 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.316735983 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.317049980 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.317096949 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.342001915 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.358006001 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:39.358021975 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:39.406006098 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:40.373608112 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:40.376224995 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:40.376317024 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:40.377886057 CET | 49722 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:40.377902985 CET | 443 | 49722 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:40.418255091 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:40.461262941 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:40.993813992 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:40.995920897 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:40.996062040 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:40.996254921 CET | 49723 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:40.996275902 CET | 443 | 49723 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:41.087728977 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.087759972 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:41.087830067 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.088272095 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.088279009 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:41.471709013 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:41.472136021 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.472148895 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:41.473210096 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:41.473289967 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.474497080 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.474561930 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:41.525012016 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.525022030 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:41.573019028 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:41.877604961 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:41.877700090 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:41.877827883 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:41.878061056 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:41.878073931 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:42.699445963 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:42.699867010 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:42.699901104 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:42.700994968 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:42.701093912 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:42.701425076 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:42.701479912 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:42.701591969 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:42.701607943 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:42.756036043 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:43.563395977 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:43.566478014 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:43.566577911 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:43.566695929 CET | 49726 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:43.566711903 CET | 443 | 49726 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:47.560834885 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:47.560863972 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:47.560976028 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:47.567461014 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:47.567475080 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:47.823543072 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:47.823582888 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:47.823668957 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:47.823899984 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:47.823925972 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:47.823982000 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:47.824502945 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:47.824515104 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:47.824704885 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:47.824727058 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:47.868707895 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:48.089864969 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:48.091362000 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:48.091378927 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:48.091386080 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:48.091397047 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:48.091480970 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:48.091531038 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:48.150752068 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.150891066 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.155096054 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.155137062 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.157644987 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.201060057 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.272795916 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.317251921 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.760287046 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:48.817838907 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.817872047 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.817878962 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.817894936 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.817934036 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.817994118 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.818006992 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.818047047 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:48.818089962 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.818121910 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.838454962 CET | 49727 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:03:48.838469982 CET | 443 | 49727 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:03:49.005822897 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:49.006536961 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:49.006609917 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:49.763484001 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.764317036 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:49.764344931 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.764695883 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.765100956 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:49.765161037 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.765372992 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:49.809288025 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.823153973 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.823534012 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:49.823560953 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.823930979 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.824224949 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:49.824309111 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:49.879103899 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:50.748790979 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:50.753158092 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:50.753257990 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:50.753401041 CET | 49729 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:50.753442049 CET | 443 | 49729 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:50.784164906 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:50.829257011 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:51.331302881 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:51.334630966 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:51.334748983 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:51.334871054 CET | 49728 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:51.334881067 CET | 443 | 49728 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:51.337764978 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:51.337799072 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:51.337882042 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:51.338207006 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:51.338215113 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:51.520692110 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:51.520834923 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:51.520896912 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:52.331118107 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:52.331501007 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:52.331517935 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:52.331865072 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:52.332180977 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:52.332246065 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:52.332324982 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:52.373317003 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:52.689831972 CET | 49725 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:52.689853907 CET | 443 | 49725 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:53.816596031 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:53.816704035 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:53.816756964 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:53.817617893 CET | 49731 | 443 | 192.168.2.16 | 103.211.239.20 |
Nov 22, 2023 15:03:53.817636013 CET | 443 | 49731 | 103.211.239.20 | 192.168.2.16 |
Nov 22, 2023 15:03:56.075490952 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.075562954 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.075666904 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.075984001 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.076008081 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.455027103 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.455480099 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.455504894 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.456068993 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.456749916 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.456844091 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.456948996 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.501252890 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.850888014 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.850939989 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.850971937 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.851053953 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.851063013 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.851074934 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.851099014 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.862322092 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.862344027 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.862402916 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.862423897 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.862473011 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.870450020 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.870539904 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.870628119 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.870628119 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:56.870651007 CET | 443 | 49732 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:03:56.870732069 CET | 49732 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:03:58.979262114 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:58.979279041 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:58.979290009 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Nov 22, 2023 15:03:58.979362011 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:03:58.979401112 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Nov 22, 2023 15:04:18.391581059 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:18.391637087 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:18.391899109 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:18.392144918 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:18.392158985 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:18.804347038 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:18.804928064 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:18.804968119 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:18.805330992 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:18.805752993 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:18.805814028 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:18.805983067 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:18.849250078 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:19.197979927 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:19.198107004 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:19.198182106 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:19.198208094 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:19.201894999 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:19.201972008 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:19.202120066 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:19.202150106 CET | 443 | 49733 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:25.215572119 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:25.215617895 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:25.215703964 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:25.216865063 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:25.216876984 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:25.602730989 CET | 49713 | 80 | 192.168.2.16 | 72.21.81.240 |
Nov 22, 2023 15:04:25.803141117 CET | 80 | 49713 | 72.21.81.240 | 192.168.2.16 |
Nov 22, 2023 15:04:25.803284883 CET | 49713 | 80 | 192.168.2.16 | 72.21.81.240 |
Nov 22, 2023 15:04:25.939488888 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:25.939661980 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:25.944327116 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:25.944346905 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:25.944674015 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:25.947122097 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:25.989269018 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:26.632647991 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:26.632677078 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:26.632726908 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:26.632822037 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:26.632874012 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:26.632917881 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:26.632944107 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:26.632977962 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:26.638132095 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:26.638180017 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:26.638242960 CET | 49734 | 443 | 192.168.2.16 | 52.165.165.26 |
Nov 22, 2023 15:04:26.638258934 CET | 443 | 49734 | 52.165.165.26 | 192.168.2.16 |
Nov 22, 2023 15:04:40.911289930 CET | 49736 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:40.911330938 CET | 443 | 49736 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:40.911442995 CET | 49736 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:40.911747932 CET | 49736 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:40.911758900 CET | 443 | 49736 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:41.324038029 CET | 443 | 49736 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:41.324337006 CET | 49736 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:41.324368000 CET | 443 | 49736 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:41.339235067 CET | 443 | 49736 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:41.339586020 CET | 49736 | 443 | 192.168.2.16 | 172.253.122.104 |
Nov 22, 2023 15:04:41.339658022 CET | 443 | 49736 | 172.253.122.104 | 192.168.2.16 |
Nov 22, 2023 15:04:41.390132904 CET | 49736 | 443 | 192.168.2.16 | 172.253.122.104 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 22, 2023 15:03:36.405356884 CET | 62129 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:36.405668974 CET | 50629 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:36.494240999 CET | 57106 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:36.494563103 CET | 63450 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:36.495059967 CET | 55869 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:36.495538950 CET | 55220 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:36.648715973 CET | 53 | 61058 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:36.726526976 CET | 53 | 55869 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:36.726700068 CET | 53 | 63450 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:36.726718903 CET | 53 | 57106 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:36.727989912 CET | 53 | 55220 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:37.178464890 CET | 53 | 62129 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:37.799820900 CET | 53 | 55210 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:38.038211107 CET | 53 | 50629 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:40.858125925 CET | 61012 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:40.858297110 CET | 60236 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:41.004173040 CET | 53117 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:41.004515886 CET | 50047 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 22, 2023 15:03:41.085690975 CET | 53 | 60236 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:41.086111069 CET | 53 | 61012 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:41.346002102 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Nov 22, 2023 15:03:41.822758913 CET | 53 | 53117 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:42.430902958 CET | 53 | 50047 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:03:54.758061886 CET | 53 | 61243 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:04:13.666443110 CET | 53 | 49855 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:04:36.320276022 CET | 53 | 62963 | 1.1.1.1 | 192.168.2.16 |
Nov 22, 2023 15:04:36.349359989 CET | 53 | 59739 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Nov 22, 2023 15:03:38.038317919 CET | 192.168.2.16 | 1.1.1.1 | c234 | (Port unreachable) | Destination Unreachable |
Nov 22, 2023 15:03:42.431026936 CET | 192.168.2.16 | 1.1.1.1 | c234 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 22, 2023 15:03:36.405356884 CET | 192.168.2.16 | 1.1.1.1 | 0x3f77 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 15:03:36.405668974 CET | 192.168.2.16 | 1.1.1.1 | 0xd31c | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 15:03:36.494240999 CET | 192.168.2.16 | 1.1.1.1 | 0xd6ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 15:03:36.494563103 CET | 192.168.2.16 | 1.1.1.1 | 0xfd48 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 15:03:36.495059967 CET | 192.168.2.16 | 1.1.1.1 | 0x96d4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 15:03:36.495538950 CET | 192.168.2.16 | 1.1.1.1 | 0x129a | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 15:03:40.858125925 CET | 192.168.2.16 | 1.1.1.1 | 0xb96c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 15:03:40.858297110 CET | 192.168.2.16 | 1.1.1.1 | 0x7f58 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 22, 2023 15:03:41.004173040 CET | 192.168.2.16 | 1.1.1.1 | 0x5efa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 22, 2023 15:03:41.004515886 CET | 192.168.2.16 | 1.1.1.1 | 0x7dcd | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 22, 2023 15:03:36.726526976 CET | 1.1.1.1 | 192.168.2.16 | 0x96d4 | No error (0) | 142.251.111.84 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726700068 CET | 1.1.1.1 | 192.168.2.16 | 0xfd48 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726718903 CET | 1.1.1.1 | 192.168.2.16 | 0xd6ae | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726718903 CET | 1.1.1.1 | 192.168.2.16 | 0xd6ae | No error (0) | 142.251.16.102 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726718903 CET | 1.1.1.1 | 192.168.2.16 | 0xd6ae | No error (0) | 142.251.16.100 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726718903 CET | 1.1.1.1 | 192.168.2.16 | 0xd6ae | No error (0) | 142.251.16.138 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726718903 CET | 1.1.1.1 | 192.168.2.16 | 0xd6ae | No error (0) | 142.251.16.113 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726718903 CET | 1.1.1.1 | 192.168.2.16 | 0xd6ae | No error (0) | 142.251.16.139 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:36.726718903 CET | 1.1.1.1 | 192.168.2.16 | 0xd6ae | No error (0) | 142.251.16.101 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:37.178464890 CET | 1.1.1.1 | 192.168.2.16 | 0x3f77 | No error (0) | 103.211.239.20 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:41.085690975 CET | 1.1.1.1 | 192.168.2.16 | 0x7f58 | No error (0) | 65 | IN (0x0001) | false | |||
Nov 22, 2023 15:03:41.086111069 CET | 1.1.1.1 | 192.168.2.16 | 0xb96c | No error (0) | 172.253.122.104 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:41.086111069 CET | 1.1.1.1 | 192.168.2.16 | 0xb96c | No error (0) | 172.253.122.99 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:41.086111069 CET | 1.1.1.1 | 192.168.2.16 | 0xb96c | No error (0) | 172.253.122.147 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:41.086111069 CET | 1.1.1.1 | 192.168.2.16 | 0xb96c | No error (0) | 172.253.122.106 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:41.086111069 CET | 1.1.1.1 | 192.168.2.16 | 0xb96c | No error (0) | 172.253.122.103 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:41.086111069 CET | 1.1.1.1 | 192.168.2.16 | 0xb96c | No error (0) | 172.253.122.105 | A (IP address) | IN (0x0001) | false | ||
Nov 22, 2023 15:03:41.822758913 CET | 1.1.1.1 | 192.168.2.16 | 0x5efa | No error (0) | 103.211.239.20 | A (IP address) | IN (0x0001) | false |
|
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Nov 22, 2023 15:03:48.091386080 CET | 23.1.237.25 | 443 | 192.168.2.16 | 49703 | CN=r.bing.com, O=Microsoft Corporation, L=Redmond, ST=WA, C=US CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Oct 18 22:32:40 CEST 2023 Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 Fri Jun 28 01:59:59 CEST 2024 | 771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-16-23-65281,29-23-24,0 | 28a2c9bd18a11de089ef85a160da29e4 |
CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49720 | 142.251.16.102 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:37 UTC | 752 | OUT | |
2023-11-22 14:03:37 UTC | 732 | IN | |
2023-11-22 14:03:37 UTC | 520 | IN | |
2023-11-22 14:03:37 UTC | 200 | IN | |
2023-11-22 14:03:37 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49721 | 142.251.111.84 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:37 UTC | 680 | OUT | |
2023-11-22 14:03:37 UTC | 1 | OUT | |
2023-11-22 14:03:37 UTC | 1627 | IN | |
2023-11-22 14:03:37 UTC | 23 | IN | |
2023-11-22 14:03:37 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49722 | 103.211.239.20 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:39 UTC | 658 | OUT | |
2023-11-22 14:03:40 UTC | 159 | IN | |
2023-11-22 14:03:40 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49723 | 103.211.239.20 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:40 UTC | 586 | OUT | |
2023-11-22 14:03:40 UTC | 159 | IN | |
2023-11-22 14:03:40 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49726 | 103.211.239.20 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:42 UTC | 350 | OUT | |
2023-11-22 14:03:43 UTC | 159 | IN | |
2023-11-22 14:03:43 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49727 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:48 UTC | 306 | OUT | |
2023-11-22 14:03:48 UTC | 560 | IN | |
2023-11-22 14:03:48 UTC | 15824 | IN | |
2023-11-22 14:03:48 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49729 | 103.211.239.20 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:49 UTC | 684 | OUT | |
2023-11-22 14:03:50 UTC | 159 | IN | |
2023-11-22 14:03:50 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49728 | 103.211.239.20 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:50 UTC | 586 | OUT | |
2023-11-22 14:03:51 UTC | 159 | IN | |
2023-11-22 14:03:51 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49731 | 103.211.239.20 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:52 UTC | 350 | OUT | |
2023-11-22 14:03:53 UTC | 159 | IN | |
2023-11-22 14:03:53 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.16 | 49732 | 172.253.122.104 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:03:56 UTC | 802 | OUT | |
2023-11-22 14:03:56 UTC | 1880 | IN | |
2023-11-22 14:03:56 UTC | 1880 | IN | |
2023-11-22 14:03:56 UTC | 481 | IN | |
2023-11-22 14:03:56 UTC | 90 | IN | |
2023-11-22 14:03:56 UTC | 1252 | IN | |
2023-11-22 14:03:56 UTC | 1252 | IN | |
2023-11-22 14:03:56 UTC | 1252 | IN | |
2023-11-22 14:03:56 UTC | 595 | IN | |
2023-11-22 14:03:56 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.16 | 49733 | 172.253.122.104 | 443 | 6524 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:04:18 UTC | 802 | OUT | |
2023-11-22 14:04:19 UTC | 1880 | IN | |
2023-11-22 14:04:19 UTC | 807 | IN | |
2023-11-22 14:04:19 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.16 | 49734 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-22 14:04:25 UTC | 306 | OUT | |
2023-11-22 14:04:26 UTC | 560 | IN | |
2023-11-22 14:04:26 UTC | 15824 | IN | |
2023-11-22 14:04:26 UTC | 9633 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 15:03:34 |
Start date: | 22/11/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 15:03:34 |
Start date: | 22/11/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |