Windows
Analysis Report
https://filmsinvest.com/material/?interprete=UTJGeWJXVnNidz09LFltVnlaMlYyYVdkcFlTNWpiMjA9LFkyRnliV1ZzYnk1allXNWhiR1Z6
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 4192 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2020 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2496 --fi eld-trial- handle=237 2,i,544371 8397366921 845,150030 3442913662 7769,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6396 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://filmsi nvest.com/ material/? interprete =UTJGeWJXV nNidz09LFl tVnlaMlYyY VdkcFlTNWp iMjA9LFkyR nliV1ZzYnk 1allXNWhiR 1Z6 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.251.163.84 | true | false | high | |
www.google.com | 172.253.115.103 | true | false | high | |
clients.l.google.com | 172.253.122.102 | true | false | high | |
filmsinvest.com | 164.160.91.31 | true | false | unknown | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
true | unknown | ||
false | unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
164.160.91.31 | filmsinvest.com | South Africa | 328037 | ElitehostZA | false | |
172.253.63.104 | unknown | United States | 15169 | GOOGLEUS | false | |
172.253.122.102 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.253.115.103 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.251.163.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
192.168.2.22 |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1348450 |
Start date and time: | 2023-11-27 11:50:30 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://filmsinvest.com/material/?interprete=UTJGeWJXVnNidz09LFltVnlaMlYyYVdkcFlTNWpiMjA9LFkyRnliV1ZzYnk1allXNWhiR1Z6 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@16/3@10/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.253.63.94, 34.104.35.123, 172.253.62.105, 172.253.62.106, 172.253.62.147, 172.253.62.99, 172.253.62.103, 172.253.62.104, 142.251.16.103, 142.251.16.105, 142.251.16.106, 142.251.16.147, 142.251.16.99, 142.251.16.104, 72.21.81.240, 192.229.211.108, 142.251.167.94
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, t2.gstatic.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 300 |
Entropy (8bit): | 6.6896392083127 |
Encrypted: | false |
SSDEEP: | 6:6v/lhPfWukt1pgql3lbQa5vr/AYlzWPeoPY/EeGUTfTAzxE32y05j+2MTNup:6v/7zKrlBQMvr/AIyPXZeGQfkzxE3G9j |
MD5: | FB3BD727D0306D3DAF574FEC092FC8CE |
SHA1: | 6E17C22D707FA33EEB09E9FE3F9CEEBF31792414 |
SHA-256: | A91AAE813A8781E642F25B37185430000ED98D5128C1FC574C36BC1BE91A4DB7 |
SHA-512: | 7D923FB3A199FB0565CB8D6DD0B8650ECE5F4690D8C0E102659C2D7F022D2EFE765379B3E11150AD79E2F4F475662A754FD40ED09DA88B95A11029668EBFE23F |
Malicious: | false |
Reputation: | low |
URL: | "https://t2.gstatic.com/faviconV2?client=SOCIAL&type=FAVICON&fallback_opts=TYPE,SIZE,URL&url=http://bergevigia.com&size=16" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1597 |
Entropy (8bit): | 4.876441134342879 |
Encrypted: | false |
SSDEEP: | 24:NYN1aEjcYgNmMvy4XsQHd352JW7DrA8zDzXR0LNt+LlcXiz6wk:NYWEsmMq3+tZFDlcA2STk |
MD5: | CEBECF74481D38B2E4E1C3F143B11D09 |
SHA1: | 430B620BEABC008913C3147E5503B91931AA710F |
SHA-256: | 830500154B77DE7E92B4F9DE543EAAED06FDB9E247B56AD168AE68706BB11F27 |
SHA-512: | 68D603A6F9D2CF52093206CA2BB12EB40A3706D2FCA816854394F958571A2C05160B5DED3F9BD3544F534F4022E4C9988941E8717BBD0FAEED0ACF9F1C79967E |
Malicious: | false |
Reputation: | low |
URL: | https://filmsinvest.com/material/?interprete=UTJGeWJXVnNidz09LFltVnlaMlYyYVdkcFlTNWpiMjA9LFkyRnliV1ZzYnk1allXNWhiR1Z6 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 6.6896392083127 |
Encrypted: | false |
SSDEEP: | 6:6v/lhPfWukt1pgql3lbQa5vr/AYlzWPeoPY/EeGUTfTAzxE32y05j+2MTNup:6v/7zKrlBQMvr/AIyPXZeGQfkzxE3G9j |
MD5: | FB3BD727D0306D3DAF574FEC092FC8CE |
SHA1: | 6E17C22D707FA33EEB09E9FE3F9CEEBF31792414 |
SHA-256: | A91AAE813A8781E642F25B37185430000ED98D5128C1FC574C36BC1BE91A4DB7 |
SHA-512: | 7D923FB3A199FB0565CB8D6DD0B8650ECE5F4690D8C0E102659C2D7F022D2EFE765379B3E11150AD79E2F4F475662A754FD40ED09DA88B95A11029668EBFE23F |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 27, 2023 11:51:15.622234106 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Nov 27, 2023 11:51:24.426127911 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.426171064 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.426242113 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.426557064 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.426562071 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.428179026 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.428186893 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.428229094 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.430169106 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.430174112 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.633806944 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.634216070 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.634249926 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.650973082 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.651109934 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.652096033 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.652168989 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.652215958 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.653956890 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.653973103 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.655689955 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.655766010 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.656183958 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.656296968 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.657104015 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.657116890 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.657233000 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.657370090 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.657376051 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.657510996 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.714405060 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.776985884 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.777019024 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.841564894 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.845360041 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.845424891 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.854417086 CET | 49730 | 443 | 192.168.2.4 | 172.253.122.102 |
Nov 27, 2023 11:51:24.854445934 CET | 443 | 49730 | 172.253.122.102 | 192.168.2.4 |
Nov 27, 2023 11:51:24.857261896 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.857327938 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.857342958 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.857398987 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:24.857444048 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.861440897 CET | 49731 | 443 | 192.168.2.4 | 142.251.163.84 |
Nov 27, 2023 11:51:24.861464977 CET | 443 | 49731 | 142.251.163.84 | 192.168.2.4 |
Nov 27, 2023 11:51:25.231764078 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Nov 27, 2023 11:51:26.828593969 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:26.828634977 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:26.828691006 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:26.829253912 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:26.829267025 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:26.858263969 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:26.858292103 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:26.858350992 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:26.858795881 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:26.858807087 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:26.859996080 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:26.860019922 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:26.860069990 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:26.860362053 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:26.860369921 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.028408051 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:27.028934002 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:27.028978109 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:27.030131102 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:27.030242920 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:27.033255100 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:27.033412933 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:27.077339888 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:27.077359915 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:27.121757030 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:27.851573944 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.852045059 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.852082014 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.853607893 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.853702068 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.855227947 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.855693102 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.855698109 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.856014967 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.862633944 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.862968922 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.862993002 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.864067078 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.864176989 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.865446091 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.869404078 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.901736975 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.901782036 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.910831928 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.910871029 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:27.949852943 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:27.965512991 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:29.035797119 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.035831928 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.035895109 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.039263010 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.039278030 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.235670090 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.235785007 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.241205931 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.241211891 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.241447926 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.293435097 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.347507000 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.393263102 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.442100048 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.442183018 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.442256927 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.442400932 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.442445040 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.442475080 CET | 49739 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.442492008 CET | 443 | 49739 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.455889940 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:29.455950022 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:29.455997944 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:29.456015110 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:29.456024885 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:29.456060886 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:29.462265015 CET | 49738 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:29.462275028 CET | 443 | 49738 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:29.543760061 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.543797016 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.543857098 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.544400930 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.544410944 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.661339998 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.661374092 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:29.661441088 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.662662983 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.662677050 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:29.736537933 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.736634016 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.738764048 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.738778114 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.739017010 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.741476059 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.789258003 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.854933023 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:29.855271101 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.855304956 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:29.856338978 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:29.856419086 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.856806993 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.856872082 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:29.856945992 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.856956005 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:29.904917955 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:29.922378063 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.922456980 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.922538996 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.924323082 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.924336910 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:29.924348116 CET | 49740 | 443 | 192.168.2.4 | 23.56.8.114 |
Nov 27, 2023 11:51:29.924352884 CET | 443 | 49740 | 23.56.8.114 | 192.168.2.4 |
Nov 27, 2023 11:51:30.048595905 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:30.048691034 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:30.048871994 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:30.049113035 CET | 49741 | 443 | 192.168.2.4 | 172.253.63.104 |
Nov 27, 2023 11:51:30.049122095 CET | 443 | 49741 | 172.253.63.104 | 192.168.2.4 |
Nov 27, 2023 11:51:37.051259041 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:37.051383972 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:37.051457882 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:38.247395039 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:38.247432947 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:38.247514009 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:38.249524117 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:38.249536991 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:38.654669046 CET | 49736 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:51:38.654695034 CET | 443 | 49736 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:51:38.659110069 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:38.659195900 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:38.664268970 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:38.664277077 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:38.664577007 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:38.714260101 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:39.168500900 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:39.213263988 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.430974960 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.430998087 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.431004047 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.431018114 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.431055069 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.431181908 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:39.431199074 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.431229115 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.431276083 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:39.431308031 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:39.454078913 CET | 49745 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:51:39.454093933 CET | 443 | 49745 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:51:39.730791092 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:39.730901957 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:51:39.730967999 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:40.662229061 CET | 49737 | 443 | 192.168.2.4 | 164.160.91.31 |
Nov 27, 2023 11:51:40.662281036 CET | 443 | 49737 | 164.160.91.31 | 192.168.2.4 |
Nov 27, 2023 11:52:15.836616039 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:15.836673021 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:15.836757898 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:15.837434053 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:15.837467909 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.239885092 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.240047932 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.246726036 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.246740103 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.246999025 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.269371986 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.317260981 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.632867098 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.632903099 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.632966042 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.633059025 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.633104086 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.633203030 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.633203030 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.633209944 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.633270979 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.644422054 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.644464970 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:16.644520998 CET | 49750 | 443 | 192.168.2.4 | 52.165.165.26 |
Nov 27, 2023 11:52:16.644527912 CET | 443 | 49750 | 52.165.165.26 | 192.168.2.4 |
Nov 27, 2023 11:52:26.752372980 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:26.752414942 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:26.752485991 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:26.752842903 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:26.752856016 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:26.946953058 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:26.947498083 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:26.947525978 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:26.947812080 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:26.948561907 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:26.948616982 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:26.995982885 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:32.512665033 CET | 49723 | 80 | 192.168.2.4 | 23.199.71.185 |
Nov 27, 2023 11:52:32.606195927 CET | 80 | 49723 | 23.199.71.185 | 192.168.2.4 |
Nov 27, 2023 11:52:32.606260061 CET | 49723 | 80 | 192.168.2.4 | 23.199.71.185 |
Nov 27, 2023 11:52:36.956504107 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:36.956588984 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Nov 27, 2023 11:52:36.956653118 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:38.654903889 CET | 49752 | 443 | 192.168.2.4 | 172.253.115.103 |
Nov 27, 2023 11:52:38.654958010 CET | 443 | 49752 | 172.253.115.103 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 27, 2023 11:51:24.151624918 CET | 53 | 54998 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:24.299357891 CET | 49299 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:24.299670935 CET | 60205 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:24.300255060 CET | 53834 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:24.300533056 CET | 62274 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:24.424576998 CET | 53 | 49299 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:24.424778938 CET | 53 | 60205 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:24.425062895 CET | 53 | 53834 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:24.427171946 CET | 53 | 62274 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:25.048877001 CET | 53 | 50769 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:26.462703943 CET | 59864 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:26.462855101 CET | 63023 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:26.702610016 CET | 65085 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:26.703016996 CET | 64794 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:26.792634010 CET | 53 | 59864 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:26.826487064 CET | 53 | 64794 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:26.827343941 CET | 53 | 65085 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:26.933931112 CET | 53 | 63023 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:29.534775972 CET | 54363 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:29.535238981 CET | 52403 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 27, 2023 11:51:29.659835100 CET | 53 | 54363 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:29.660418034 CET | 53 | 52403 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:30.413924932 CET | 53 | 59079 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:31.036060095 CET | 53 | 60787 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:42.027286053 CET | 53 | 57486 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:51:44.096069098 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Nov 27, 2023 11:52:00.838851929 CET | 53 | 62411 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:52:23.325232983 CET | 53 | 65231 | 1.1.1.1 | 192.168.2.4 |
Nov 27, 2023 11:52:23.973104954 CET | 53 | 56773 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Nov 27, 2023 11:51:26.934068918 CET | 192.168.2.4 | 1.1.1.1 | c22e | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 27, 2023 11:51:24.299357891 CET | 192.168.2.4 | 1.1.1.1 | 0xdd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2023 11:51:24.299670935 CET | 192.168.2.4 | 1.1.1.1 | 0x67d0 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 27, 2023 11:51:24.300255060 CET | 192.168.2.4 | 1.1.1.1 | 0x6b46 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2023 11:51:24.300533056 CET | 192.168.2.4 | 1.1.1.1 | 0xf2cd | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 27, 2023 11:51:26.462703943 CET | 192.168.2.4 | 1.1.1.1 | 0x13d3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2023 11:51:26.462855101 CET | 192.168.2.4 | 1.1.1.1 | 0x20d9 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 27, 2023 11:51:26.702610016 CET | 192.168.2.4 | 1.1.1.1 | 0x6a0a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2023 11:51:26.703016996 CET | 192.168.2.4 | 1.1.1.1 | 0x1eb | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 27, 2023 11:51:29.534775972 CET | 192.168.2.4 | 1.1.1.1 | 0xcd0d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 27, 2023 11:51:29.535238981 CET | 192.168.2.4 | 1.1.1.1 | 0x357a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 27, 2023 11:51:24.424576998 CET | 1.1.1.1 | 192.168.2.4 | 0xdd3 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.424576998 CET | 1.1.1.1 | 192.168.2.4 | 0xdd3 | No error (0) | 172.253.122.102 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.424576998 CET | 1.1.1.1 | 192.168.2.4 | 0xdd3 | No error (0) | 172.253.122.138 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.424576998 CET | 1.1.1.1 | 192.168.2.4 | 0xdd3 | No error (0) | 172.253.122.100 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.424576998 CET | 1.1.1.1 | 192.168.2.4 | 0xdd3 | No error (0) | 172.253.122.139 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.424576998 CET | 1.1.1.1 | 192.168.2.4 | 0xdd3 | No error (0) | 172.253.122.101 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.424576998 CET | 1.1.1.1 | 192.168.2.4 | 0xdd3 | No error (0) | 172.253.122.113 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.424778938 CET | 1.1.1.1 | 192.168.2.4 | 0x67d0 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:24.425062895 CET | 1.1.1.1 | 192.168.2.4 | 0x6b46 | No error (0) | 142.251.163.84 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:26.792634010 CET | 1.1.1.1 | 192.168.2.4 | 0x13d3 | No error (0) | 164.160.91.31 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:26.826487064 CET | 1.1.1.1 | 192.168.2.4 | 0x1eb | No error (0) | 65 | IN (0x0001) | false | |||
Nov 27, 2023 11:51:26.827343941 CET | 1.1.1.1 | 192.168.2.4 | 0x6a0a | No error (0) | 172.253.115.103 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:26.827343941 CET | 1.1.1.1 | 192.168.2.4 | 0x6a0a | No error (0) | 172.253.115.147 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:26.827343941 CET | 1.1.1.1 | 192.168.2.4 | 0x6a0a | No error (0) | 172.253.115.105 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:26.827343941 CET | 1.1.1.1 | 192.168.2.4 | 0x6a0a | No error (0) | 172.253.115.104 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:26.827343941 CET | 1.1.1.1 | 192.168.2.4 | 0x6a0a | No error (0) | 172.253.115.99 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:26.827343941 CET | 1.1.1.1 | 192.168.2.4 | 0x6a0a | No error (0) | 172.253.115.106 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:29.659835100 CET | 1.1.1.1 | 192.168.2.4 | 0xcd0d | No error (0) | 172.253.63.104 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:29.659835100 CET | 1.1.1.1 | 192.168.2.4 | 0xcd0d | No error (0) | 172.253.63.105 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:29.659835100 CET | 1.1.1.1 | 192.168.2.4 | 0xcd0d | No error (0) | 172.253.63.103 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:29.659835100 CET | 1.1.1.1 | 192.168.2.4 | 0xcd0d | No error (0) | 172.253.63.106 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:29.659835100 CET | 1.1.1.1 | 192.168.2.4 | 0xcd0d | No error (0) | 172.253.63.147 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:29.659835100 CET | 1.1.1.1 | 192.168.2.4 | 0xcd0d | No error (0) | 172.253.63.99 | A (IP address) | IN (0x0001) | false | ||
Nov 27, 2023 11:51:29.660418034 CET | 1.1.1.1 | 192.168.2.4 | 0x357a | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49731 | 142.251.163.84 | 443 | 2020 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:51:24 UTC | 680 | OUT | |
2023-11-27 10:51:24 UTC | 1 | OUT | |
2023-11-27 10:51:24 UTC | 1627 | IN | |
2023-11-27 10:51:24 UTC | 23 | IN | |
2023-11-27 10:51:24 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49730 | 172.253.122.102 | 443 | 2020 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:51:24 UTC | 752 | OUT | |
2023-11-27 10:51:24 UTC | 732 | IN | |
2023-11-27 10:51:24 UTC | 520 | IN | |
2023-11-27 10:51:24 UTC | 200 | IN | |
2023-11-27 10:51:24 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49738 | 164.160.91.31 | 443 | 2020 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:51:27 UTC | 751 | OUT | |
2023-11-27 10:51:29 UTC | 360 | IN | |
2023-11-27 10:51:29 UTC | 1597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49739 | 23.56.8.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:51:29 UTC | 161 | OUT | |
2023-11-27 10:51:29 UTC | 436 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49740 | 23.56.8.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:51:29 UTC | 239 | OUT | |
2023-11-27 10:51:29 UTC | 531 | IN | |
2023-11-27 10:51:29 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49741 | 172.253.63.104 | 443 | 2020 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:51:29 UTC | 892 | OUT | |
2023-11-27 10:51:30 UTC | 486 | IN | |
2023-11-27 10:51:30 UTC | 334 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49745 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:51:39 UTC | 306 | OUT | |
2023-11-27 10:51:39 UTC | 560 | IN | |
2023-11-27 10:51:39 UTC | 15824 | IN | |
2023-11-27 10:51:39 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49750 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-11-27 10:52:16 UTC | 306 | OUT | |
2023-11-27 10:52:16 UTC | 560 | IN | |
2023-11-27 10:52:16 UTC | 15824 | IN | |
2023-11-27 10:52:16 UTC | 9633 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 11:51:19 |
Start date: | 27/11/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 11:51:22 |
Start date: | 27/11/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 11:51:25 |
Start date: | 27/11/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |