Windows
Analysis Report
https://www.ojrq.net/
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 6524 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// www.ojrq.n et/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 3496 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2076 --fi eld-trial- handle=200 8,i,889776 9019717590 478,478885 5190301408 649,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.ojrq.net | 34.95.127.121 | true | false | high | |
accounts.google.com | 142.251.167.84 | true | false | high | |
www.google.com | 142.250.31.104 | true | false | high | |
clients.l.google.com | 142.251.16.101 | true | false | high | |
clients1.google.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
34.95.127.121 | www.ojrq.net | United States | 15169 | GOOGLEUS | false | |
142.251.167.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.31.104 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.253.122.138 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.16.101 | clients.l.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1352946 |
Start date and time: | 2023-12-04 08:58:21 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 22s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://www.ojrq.net/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@14/6@12/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, WMIADAP.exe, SIHCl ient.exe, conhost.exe - Excluded IPs from analysis (wh
itelisted): 172.253.122.94, 34 .104.35.123, 192.229.211.108, 142.251.16.94 - Excluded domains from analysis
(whitelisted): ocsp.digicert. com, edgedl.me.gvt1.com, slscr .update.microsoft.com, update. googleapis.com, clientservices .googleapis.com, fe3cr.deliver y.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.99343713545573 |
Encrypted: | false |
SSDEEP: | 48:8zd0T4sHHPWidAKZdA1FehwiZUklqehny+3:8iPMUy |
MD5: | 16420AC2BB1E9CB4942BC1E0B6081A4B |
SHA1: | 7EF3D389544BE60619348EC87A8B8BBF18E2A508 |
SHA-256: | 62FB7ED576911C7BCE41194BB53B92AAE73622301E8A62D8E0C860FB98ED607B |
SHA-512: | 7643E509AAD1132A0432FF11E9F12758C6360D70EAD22EBD7A72A0679F9137A2E1642E56993B64D04D236ADC4BE1F86A26F7FFD6F1ED444D702FE00DAC1BF9B8 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.007383360046751 |
Encrypted: | false |
SSDEEP: | 48:8Hd0T4sHHPWidAKZdA1seh/iZUkAQkqehEy+2:8OPi9QVy |
MD5: | 318797B7801D231CF52019409EF7E4ED |
SHA1: | 273A77DEFD7F7CDFD10E1E5BA796AB1DB53FA2BC |
SHA-256: | 37DCEF88AC26B956060604DD12B18A332DE35D5B285639275C446C4F90CDFE96 |
SHA-512: | CE22C41C6F64D1294896245BD733497D8106069BBCB81F715A39E7DA1156F8C3E2B139630EAEF242316CB176419C7E2A93E89EC4CF7100D1C0350C287EA2C459 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.01319157381348 |
Encrypted: | false |
SSDEEP: | 48:8Jd0T4sAHPWidAKZdA14meh7sFiZUkmgqeh7sqy+BX:84PDnwy |
MD5: | 8E5023A92454847ABC14EFDCF47A5E54 |
SHA1: | 05620EECAEEFCC895F06E30AD02D2B8C7933702D |
SHA-256: | 648BE4AE49F529124EAB63B23A3486590098A2F47CC2B4ACF7723E2E91DE7296 |
SHA-512: | 14A7317DCFD9783E6F0F2570FD625413DA7C7E5978BD62F0616C28FC900645E9658F0D5A33444BF70376B0314C67467E16E050477851CCDF3D4ACE22B0D343DC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.006704701982066 |
Encrypted: | false |
SSDEEP: | 48:8Ud0T4sHHPWidAKZdA1TehDiZUkwqehIy+R:8bP5iy |
MD5: | 310F53D3C646F0808E717758EBA0702D |
SHA1: | A02D4C1F4AAC057D2AD08C800E00C675E407B24E |
SHA-256: | 288F3417565DAFCA1C2D62930E7B83E62E121D9A628F19AED8CEFCD08732DF55 |
SHA-512: | 12E64A0CD48E373A2F6BAC384C4CEEF888F869825A8D228B9D362EB19B28B20E9AAE220B9C8998509A0264F3C6A8D2194B6B5C6B2BF588D5C4EFCEE86E650042 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.996144197180148 |
Encrypted: | false |
SSDEEP: | 48:8Pd0T4sHHPWidAKZdA1dehBiZUk1W1qehGy+C:8mPp9my |
MD5: | 7FED7C4509842BB44DD4CB7A40FA7CD8 |
SHA1: | BCA78F28E7EF6B97FC4E538AD5728EBB57DD1B1B |
SHA-256: | 519DC389F5DB085DDFBC49D069401CFE743D3040D132DE2888351886F54C8825 |
SHA-512: | 56B7841C1E84F8EC3242098DF7B0A1286BE4EBDD902276602AD43634FCA79B26930D36D7CF8E95F30962EA281FE56D3BA51F70EA9999678B2D5D9DC9757D8EF7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.005535221486846 |
Encrypted: | false |
SSDEEP: | 48:8kd0T4sHHPWidAKZdA1duTeehOuTbbiZUk5OjqehOuTbwy+yT+:8LPRTfTbxWOvTbwy7T |
MD5: | 8A7D0F4287F2618ED6552AFE96B6269D |
SHA1: | BA923A7A6ABBA7649782456DC9336233F7A3820E |
SHA-256: | 2C37DF7B65136891652D5501CB606162108F2C5481A0CA00D4144D451264B9F2 |
SHA-512: | 60646DAABF2F5CC18E9E429EAF620F18A03E4982D17DCEABE5A6D1A5EE337DF45B39A6675723AE5228B9E76B2D92C0A772EE080D566AC707980A216C865954B6 |
Malicious: | false |
Reputation: | low |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 149
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 4, 2023 08:58:47.472630978 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:58:47.472723007 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:58:49.861629963 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:49.861669064 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:49.861732006 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:49.862991095 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:49.863007069 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:49.931045055 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:49.931091070 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:49.931158066 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:49.931468010 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:49.931488037 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:49.932353973 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:49.932384014 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:49.932434082 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:49.932717085 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:49.932730913 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.129443884 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.132703066 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.132709980 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.135178089 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.135271072 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.138683081 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.138782024 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.139547110 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.139554024 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.169929981 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.170222998 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.170267105 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.170648098 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.170722961 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.171267033 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.171325922 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.172518015 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.173299074 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.173317909 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.173484087 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.173564911 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.173650980 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.173662901 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.174808025 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.174887896 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.175775051 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.175869942 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.176851034 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.176860094 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.194950104 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.224113941 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.224117041 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.312239885 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.313788891 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.313869953 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.315238953 CET | 49719 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.315258026 CET | 443 | 49719 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.336040020 CET | 49674 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:58:50.336080074 CET | 49673 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:58:50.381376982 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.381421089 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.381541014 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.381916046 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.381927013 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.385538101 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.385673046 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.385734081 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.386466026 CET | 49721 | 443 | 192.168.2.16 | 142.251.16.101 |
Dec 4, 2023 08:58:50.386498928 CET | 443 | 49721 | 142.251.16.101 | 192.168.2.16 |
Dec 4, 2023 08:58:50.396476984 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.396590948 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.396620035 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.396814108 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.396867990 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.397303104 CET | 49722 | 443 | 192.168.2.16 | 142.251.167.84 |
Dec 4, 2023 08:58:50.397322893 CET | 443 | 49722 | 142.251.167.84 | 192.168.2.16 |
Dec 4, 2023 08:58:50.597681046 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.598012924 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.598026991 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.598706007 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.598994017 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.599080086 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.599123955 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.645251989 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.654093027 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.718096018 CET | 49672 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:58:50.802823067 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.802958012 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.803018093 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.803026915 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.803236961 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.803287029 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.804362059 CET | 49723 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.804374933 CET | 443 | 49723 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.939346075 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.939418077 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:50.939515114 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.939809084 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:50.939831972 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.156728983 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.157044888 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.157077074 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.158576012 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.158655882 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.158904076 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.158984900 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.159029961 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.205260038 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.214063883 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.214128971 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.261003971 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.360887051 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.361030102 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.361104012 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.361125946 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.361390114 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:51.361582994 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.362111092 CET | 49725 | 443 | 192.168.2.16 | 34.95.127.121 |
Dec 4, 2023 08:58:51.362128019 CET | 443 | 49725 | 34.95.127.121 | 192.168.2.16 |
Dec 4, 2023 08:58:54.440407991 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:58:54.440438986 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:58:54.440521002 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:58:54.440890074 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:58:54.440902948 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:58:54.659605026 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:58:54.659921885 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:58:54.659959078 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:58:54.662192106 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:58:54.662384987 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:58:54.663429976 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:58:54.663532019 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:58:54.707160950 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:58:54.707179070 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:58:54.755110979 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:01.192650080 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:01.192698002 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:01.192779064 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:01.198411942 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:01.198441982 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:01.369517088 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:01.529107094 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:01.529943943 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:01.529985905 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:01.530040979 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:01.530041933 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:01.530075073 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:01.530078888 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:01.530097008 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:01.530131102 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:01.753360033 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:01.753467083 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:01.755275011 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:01.755302906 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:01.755732059 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:01.809045076 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:01.842833042 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:01.885263920 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:01.887267113 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.046808958 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.047141075 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.047226906 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.047991991 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.048459053 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.048758984 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.048804998 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.207456112 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.207540035 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.207556009 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.207670927 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.207672119 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.208061934 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.211997986 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.253305912 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.253340960 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Dec 4, 2023 08:59:02.253371000 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.253408909 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Dec 4, 2023 08:59:02.263413906 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263470888 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263489962 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263508081 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263546944 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263565063 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263652086 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.263652086 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.263652086 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.263652086 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.263725042 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263765097 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263792038 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.263799906 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263822079 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.263854980 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.263879061 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.263894081 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.264007092 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.264061928 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.280263901 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.280303001 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:02.280328989 CET | 49727 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:02.280344963 CET | 443 | 49727 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:04.653871059 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:04.653947115 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:04.654011011 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:06.069747925 CET | 49726 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:06.069797993 CET | 443 | 49726 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:37.118256092 CET | 49713 | 80 | 192.168.2.16 | 72.21.81.240 |
Dec 4, 2023 08:59:37.216332912 CET | 80 | 49713 | 72.21.81.240 | 192.168.2.16 |
Dec 4, 2023 08:59:37.216442108 CET | 49713 | 80 | 192.168.2.16 | 72.21.81.240 |
Dec 4, 2023 08:59:38.687227964 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:38.687309027 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:38.687479973 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:38.688855886 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:38.688891888 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.219835043 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.220185041 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:39.227225065 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:39.227256060 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.227714062 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.229486942 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:39.277260065 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.724406004 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.724436998 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.724459887 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.724572897 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:39.724632025 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.724663019 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.724766970 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:39.729548931 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:39.729582071 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:39.729609013 CET | 49729 | 443 | 192.168.2.16 | 40.127.169.103 |
Dec 4, 2023 08:59:39.729624033 CET | 443 | 49729 | 40.127.169.103 | 192.168.2.16 |
Dec 4, 2023 08:59:54.368629932 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:54.368670940 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:54.368946075 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:54.369931936 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:54.369946003 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:54.574460030 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:54.574820042 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:54.574837923 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:54.575295925 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:54.575762987 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 08:59:54.575844049 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 08:59:54.622029066 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 09:00:04.585612059 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 09:00:04.585684061 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 09:00:04.585742950 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 09:00:06.078360081 CET | 49731 | 443 | 192.168.2.16 | 142.250.31.104 |
Dec 4, 2023 09:00:06.078382015 CET | 443 | 49731 | 142.250.31.104 | 192.168.2.16 |
Dec 4, 2023 09:00:19.445983887 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.446067095 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.446156025 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.446547031 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.446582079 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.652393103 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.652733088 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.652759075 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.653306961 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.653402090 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.654329062 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.654392004 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.655467987 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.655549049 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.655669928 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.655683994 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.708059072 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.944782019 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.946028948 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:19.946192980 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.946378946 CET | 49733 | 443 | 192.168.2.16 | 172.253.122.138 |
Dec 4, 2023 09:00:19.946408987 CET | 443 | 49733 | 172.253.122.138 | 192.168.2.16 |
Dec 4, 2023 09:00:29.109397888 CET | 49715 | 443 | 192.168.2.16 | 23.221.242.90 |
Dec 4, 2023 09:00:29.208214998 CET | 443 | 49715 | 23.221.242.90 | 192.168.2.16 |
Dec 4, 2023 09:00:29.208254099 CET | 443 | 49715 | 23.221.242.90 | 192.168.2.16 |
Dec 4, 2023 09:00:29.208369017 CET | 49715 | 443 | 192.168.2.16 | 23.221.242.90 |
Dec 4, 2023 09:00:29.208448887 CET | 49715 | 443 | 192.168.2.16 | 23.221.242.90 |
Dec 4, 2023 09:00:29.684474945 CET | 49717 | 443 | 192.168.2.16 | 23.221.242.90 |
Dec 4, 2023 09:00:29.783098936 CET | 443 | 49717 | 23.221.242.90 | 192.168.2.16 |
Dec 4, 2023 09:00:29.783117056 CET | 443 | 49717 | 23.221.242.90 | 192.168.2.16 |
Dec 4, 2023 09:00:29.783169985 CET | 49717 | 443 | 192.168.2.16 | 23.221.242.90 |
Dec 4, 2023 09:00:29.783210039 CET | 49717 | 443 | 192.168.2.16 | 23.221.242.90 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 4, 2023 08:58:49.672606945 CET | 63701 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:49.672725916 CET | 62839 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:49.799314022 CET | 49706 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:49.800628901 CET | 64832 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:49.801189899 CET | 54396 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:49.801887989 CET | 53 | 60041 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:49.802472115 CET | 58341 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:49.803680897 CET | 53 | 63701 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:49.804807901 CET | 53 | 62839 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:49.929399014 CET | 53 | 49706 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:49.930562019 CET | 53 | 64832 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:49.931287050 CET | 53 | 58341 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:49.931854963 CET | 53 | 54396 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:50.571470976 CET | 53 | 52449 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:50.807645082 CET | 51146 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:50.807877064 CET | 60586 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:50.937079906 CET | 53 | 51146 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:50.938927889 CET | 53 | 60586 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:54.309078932 CET | 57749 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:54.309154987 CET | 53139 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 08:58:54.439102888 CET | 53 | 57749 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:54.439140081 CET | 53 | 53139 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:58:58.334877968 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Dec 4, 2023 08:59:07.652563095 CET | 53 | 55988 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:59:26.511598110 CET | 53 | 58443 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:59:48.829946995 CET | 53 | 50768 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 08:59:49.660464048 CET | 53 | 57091 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 09:00:17.298707008 CET | 53 | 52290 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 09:00:19.310580015 CET | 62668 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 09:00:19.311005116 CET | 64342 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 4, 2023 09:00:19.439583063 CET | 53 | 62668 | 1.1.1.1 | 192.168.2.16 |
Dec 4, 2023 09:00:19.445502043 CET | 53 | 64342 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 4, 2023 08:58:49.672606945 CET | 192.168.2.16 | 1.1.1.1 | 0x954d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 4, 2023 08:58:49.672725916 CET | 192.168.2.16 | 1.1.1.1 | 0x41af | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 4, 2023 08:58:49.799314022 CET | 192.168.2.16 | 1.1.1.1 | 0x911c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 4, 2023 08:58:49.800628901 CET | 192.168.2.16 | 1.1.1.1 | 0x93ad | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 4, 2023 08:58:49.801189899 CET | 192.168.2.16 | 1.1.1.1 | 0x442d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 4, 2023 08:58:49.802472115 CET | 192.168.2.16 | 1.1.1.1 | 0x66c0 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 4, 2023 08:58:50.807645082 CET | 192.168.2.16 | 1.1.1.1 | 0x7f0b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 4, 2023 08:58:50.807877064 CET | 192.168.2.16 | 1.1.1.1 | 0x2c66 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 4, 2023 08:58:54.309078932 CET | 192.168.2.16 | 1.1.1.1 | 0x76ad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 4, 2023 08:58:54.309154987 CET | 192.168.2.16 | 1.1.1.1 | 0xc24b | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 4, 2023 09:00:19.310580015 CET | 192.168.2.16 | 1.1.1.1 | 0xd926 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 4, 2023 09:00:19.311005116 CET | 192.168.2.16 | 1.1.1.1 | 0x372d | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 4, 2023 08:58:49.803680897 CET | 1.1.1.1 | 192.168.2.16 | 0x954d | No error (0) | 34.95.127.121 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.929399014 CET | 1.1.1.1 | 192.168.2.16 | 0x911c | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.929399014 CET | 1.1.1.1 | 192.168.2.16 | 0x911c | No error (0) | 142.251.16.101 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.929399014 CET | 1.1.1.1 | 192.168.2.16 | 0x911c | No error (0) | 142.251.16.138 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.929399014 CET | 1.1.1.1 | 192.168.2.16 | 0x911c | No error (0) | 142.251.16.113 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.929399014 CET | 1.1.1.1 | 192.168.2.16 | 0x911c | No error (0) | 142.251.16.139 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.929399014 CET | 1.1.1.1 | 192.168.2.16 | 0x911c | No error (0) | 142.251.16.102 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.929399014 CET | 1.1.1.1 | 192.168.2.16 | 0x911c | No error (0) | 142.251.16.100 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.930562019 CET | 1.1.1.1 | 192.168.2.16 | 0x93ad | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:49.931854963 CET | 1.1.1.1 | 192.168.2.16 | 0x442d | No error (0) | 142.251.167.84 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:50.937079906 CET | 1.1.1.1 | 192.168.2.16 | 0x7f0b | No error (0) | 34.95.127.121 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:54.439102888 CET | 1.1.1.1 | 192.168.2.16 | 0x76ad | No error (0) | 142.250.31.104 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:54.439102888 CET | 1.1.1.1 | 192.168.2.16 | 0x76ad | No error (0) | 142.250.31.103 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:54.439102888 CET | 1.1.1.1 | 192.168.2.16 | 0x76ad | No error (0) | 142.250.31.147 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:54.439102888 CET | 1.1.1.1 | 192.168.2.16 | 0x76ad | No error (0) | 142.250.31.106 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:54.439102888 CET | 1.1.1.1 | 192.168.2.16 | 0x76ad | No error (0) | 142.250.31.99 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:54.439102888 CET | 1.1.1.1 | 192.168.2.16 | 0x76ad | No error (0) | 142.250.31.105 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 08:58:54.439140081 CET | 1.1.1.1 | 192.168.2.16 | 0xc24b | No error (0) | 65 | IN (0x0001) | false | |||
Dec 4, 2023 09:00:19.439583063 CET | 1.1.1.1 | 192.168.2.16 | 0xd926 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 4, 2023 09:00:19.439583063 CET | 1.1.1.1 | 192.168.2.16 | 0xd926 | No error (0) | 172.253.122.138 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 09:00:19.439583063 CET | 1.1.1.1 | 192.168.2.16 | 0xd926 | No error (0) | 172.253.122.101 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 09:00:19.439583063 CET | 1.1.1.1 | 192.168.2.16 | 0xd926 | No error (0) | 172.253.122.113 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 09:00:19.439583063 CET | 1.1.1.1 | 192.168.2.16 | 0xd926 | No error (0) | 172.253.122.102 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 09:00:19.439583063 CET | 1.1.1.1 | 192.168.2.16 | 0xd926 | No error (0) | 172.253.122.139 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 09:00:19.439583063 CET | 1.1.1.1 | 192.168.2.16 | 0xd926 | No error (0) | 172.253.122.100 | A (IP address) | IN (0x0001) | false | ||
Dec 4, 2023 09:00:19.445502043 CET | 1.1.1.1 | 192.168.2.16 | 0x372d | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false |
|
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Dec 4, 2023 08:59:01.530040979 CET | 23.1.237.25 | 443 | 192.168.2.16 | 49703 | CN=r.bing.com, O=Microsoft Corporation, L=Redmond, ST=WA, C=US CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Oct 18 22:32:40 CEST 2023 Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 Fri Jun 28 01:59:59 CEST 2024 | 771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-16-23-65281,29-23-24,0 | 28a2c9bd18a11de089ef85a160da29e4 |
CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49719 | 34.95.127.121 | 443 | 3496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 07:58:50 UTC | 655 | OUT | |
2023-12-04 07:58:50 UTC | 463 | IN | |
2023-12-04 07:58:50 UTC | 248 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49721 | 142.251.16.101 | 443 | 3496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 07:58:50 UTC | 752 | OUT | |
2023-12-04 07:58:50 UTC | 732 | IN | |
2023-12-04 07:58:50 UTC | 520 | IN | |
2023-12-04 07:58:50 UTC | 200 | IN | |
2023-12-04 07:58:50 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49722 | 142.251.167.84 | 443 | 3496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 07:58:50 UTC | 680 | OUT | |
2023-12-04 07:58:50 UTC | 1 | OUT | |
2023-12-04 07:58:50 UTC | 1627 | IN | |
2023-12-04 07:58:50 UTC | 23 | IN | |
2023-12-04 07:58:50 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49723 | 34.95.127.121 | 443 | 3496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 07:58:50 UTC | 580 | OUT | |
2023-12-04 07:58:50 UTC | 512 | IN | |
2023-12-04 07:58:50 UTC | 740 | IN | |
2023-12-04 07:58:50 UTC | 1252 | IN | |
2023-12-04 07:58:50 UTC | 261 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49725 | 34.95.127.121 | 443 | 3496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 07:58:51 UTC | 347 | OUT | |
2023-12-04 07:58:51 UTC | 512 | IN | |
2023-12-04 07:58:51 UTC | 740 | IN | |
2023-12-04 07:58:51 UTC | 1252 | IN | |
2023-12-04 07:58:51 UTC | 261 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49727 | 40.127.169.103 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 07:59:01 UTC | 306 | OUT | |
2023-12-04 07:59:02 UTC | 560 | IN | |
2023-12-04 07:59:02 UTC | 15824 | IN | |
2023-12-04 07:59:02 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49729 | 40.127.169.103 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 07:59:39 UTC | 306 | OUT | |
2023-12-04 07:59:39 UTC | 560 | IN | |
2023-12-04 07:59:39 UTC | 15824 | IN | |
2023-12-04 07:59:39 UTC | 9633 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49733 | 172.253.122.138 | 443 | 3496 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-04 08:00:19 UTC | 449 | OUT | |
2023-12-04 08:00:19 UTC | 817 | IN | |
2023-12-04 08:00:19 UTC | 219 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:58:48 |
Start date: | 04/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 08:58:48 |
Start date: | 04/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |