Windows
Analysis Report
http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1352 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 6696 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2348 --fi eld-trial- handle=228 8,i,123301 0466196752 0940,68284 7274094739 711,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 1248 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http ://status. thawte.com //MFEwTzBN MEswSTAJBg UrDgMCGgUA BBRzhKfQYs AHQZZDzb8R tQ5PgsTjQQ QUpYz%2BMs zrDyzUGcYI uAAkiF3Dxb cCEAuHlVK1 KTZl0evTeF WOnVg%3D MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.250.64.141 | true | false | high | |
www.google.com | 142.250.217.228 | true | false | high | |
clients.l.google.com | 192.178.50.46 | true | false | high | |
clients2.google.com | unknown | unknown | false | high | |
status.thawte.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.64.141 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
192.178.50.46 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.217.228 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 38.0.0 Ammolite |
Analysis ID: | 1355439 |
Start date and time: | 2023-12-07 15:02:03 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | UNKNOWN |
Classification: | unknown1.win@17/9@8/5 |
EGA Information: | Failed |
HCA Information: |
|
- URL not reachable
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe, SIHClient.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 192.178.50.35, 34. 104.35.123, 23.56.6.73, 72.21. 81.240, 192.229.211.108 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, ocsp.digicert.com, edgedl. me.gvt1.com, slscr.update.micr osoft.com, update.googleapis.c om, ctldl.windowsupdate.com, c lientservices.googleapis.com, fe3cr.delivery.mp.microsoft.co m - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: http:/
/status.thawte.com//MFEwTzBNME swSTAJBgUrDgMCGgUABBRzhKfQYsAH QZZDzb8RtQ5PgsTjQQQUpYz%2BMszr DyzUGcYIuAAkiF3DxbcCEAuHlVK1KT Zl0evTeFWOnVg%3D
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 471 |
Entropy (8bit): | 7.2065006082985725 |
Encrypted: | false |
SSDEEP: | 6:J0MEidG5o7UH6H9xwEqkYdtEn/DmMxsdCLj2I+fYXrPPkhoWPwkFhgWw/13s1tGw:JOkG5lHYLqMmdK2IfzkCkFOP30BZ |
MD5: | E09531B89414706804DA63BADE235FF4 |
SHA1: | 48CBDD29895F66F4D348A9C9A1C7E9A25C3D1F09 |
SHA-256: | F53D82D21E02449FB279D235FE11F5682A30D0368F3F883434DD469C1E2D1377 |
SHA-512: | 65ED1D05872B98FB3FDBBAE28E1CB71D5ACF2EC79B92C7E3147F1E7D20C446BD15B15F7B06850E14CDE6B4CAB5500312A9E6E3D0BF139E31596D722B00997AEE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.972149567753829 |
Encrypted: | false |
SSDEEP: | 48:8bNdaST6ejEHu0idAKZdA19ehwiZUklqehHy+3:8eSOqcoy |
MD5: | 372E38A7771A95087C4DD1482BCAF738 |
SHA1: | 305E1A700622D5E59F3EDB3403889B373AE0813E |
SHA-256: | FF00689C5AB7B0E72C792AFD4D691CABFC51C5EFCB0A18DF0A2C01CB6C39AAD4 |
SHA-512: | B5D5DC890E4606CBF82D5C136C7CCAE84A55E75A5429CEF6B3F1CC17330C8AA182CC854DADAC759A35A1AE42C8EF0E843C4796BC14BB12BFF74D7DF69E979AA2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.988931836991867 |
Encrypted: | false |
SSDEEP: | 48:8mNdaST6ejEHu0idAKZdA1weh/iZUkAQkqehYy+2:8LSOqu9QBy |
MD5: | 06D19139703889E57381B3A2C8DD2C67 |
SHA1: | D072597207AEC772E8C4D9020498D6C90DCD1E70 |
SHA-256: | FD270550B3B6A90E169F74187622CAA460C51C3EDC56C12BB6E6B66FBF0120B5 |
SHA-512: | 71244C98BC772E56A578AF4CCA3CA5294909D314A5E3A4F186DCB3A2BD59121BFEA8F0626DE36F32914F77E5FCBFE4AB4B16B8AFF372983609BAB276502EC28D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.001093785032837 |
Encrypted: | false |
SSDEEP: | 48:8xkdaST6ejsHu0idAKZdA14tseh7sFiZUkmgqeh7sqy+BX:8xNSOq+n0y |
MD5: | 9B81BA8340D2402C456F5520C69316F9 |
SHA1: | B84550BCEECF121046EC619A2CAFD51C10D6158B |
SHA-256: | A1DFAEA1BD30B8220103F80ECB34A86B54AB1BC8C63F4E4ECD1B53D77EAB6140 |
SHA-512: | 853FB18264DCA3990C7D821B454E98B542B67D7F36FD0270DED8338D2206266BE1C0DA77A0637BABA05302D29A8A808CE7BB33116AC9F822B9C711793C8BB229 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.986952209134305 |
Encrypted: | false |
SSDEEP: | 48:8hNdaST6ejEHu0idAKZdA1vehDiZUkwqeh8y+R:8ESOq1yy |
MD5: | C457C407B78C41B3889A222F04EBE467 |
SHA1: | 4A83385D5F3FA599A838BEA05044F8C2F754726B |
SHA-256: | 37A0D70B750CFCB03C2CF9AE4E95B0909F074E12ED0BE00A07C8E282393A64D3 |
SHA-512: | B5207497B77B9F613EB29F5E737AF57A0D0AFD51159700516738CB630EEAA6C7837C8522C57C0E04386B75AF87E93736A10E4FB06A1FFF232D189B35ABDD1B0A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.978511677888848 |
Encrypted: | false |
SSDEEP: | 48:8amNdaST6ejEHu0idAKZdA1hehBiZUk1W1qehWy+C:8KSOql92y |
MD5: | 357F28BC245334E64C8E8FB585092911 |
SHA1: | 33DFFBCDF8DF3E1E9213755E0FA3BB297C5010BF |
SHA-256: | 456FE3AF4D7BB4639F8535D357862FDE89CC44FEDA2A12236A8A844BEEB9C81C |
SHA-512: | BEB88A3A8C1066DCC72B7A18977903833F5F8D736DB78CD72A48D756BB9E059E8B3420CCCA192D93F4C3CD1B8B87A9A498343BD93CDB154E253988C95017391D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9887634869831534 |
Encrypted: | false |
SSDEEP: | 48:8+NdaST6ejEHu0idAKZdA1duT+ehOuTbbiZUk5OjqehOuTb0y+yT+:8TSOq5T/TbxWOvTb0y7T |
MD5: | 900373A2C0816EBF8B3CE34F4B3A4DB5 |
SHA1: | 1A0994E68135F232657D5C7F191A6E63566A6DC7 |
SHA-256: | 79EBD9DBD080618E6A6051B36CF1FAE40DC20BDC3210EB28D039303A34285D69 |
SHA-512: | 03FAA7B14F90F3AED80C644A90AA25C35E0F21DB673C25A4027279E66CDDFC683A3700B4B6B04933427391B9D056A8B3487E914B0EB48756EDA26150EA786F28 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 471 |
Entropy (8bit): | 7.2065006082985725 |
Encrypted: | false |
SSDEEP: | 6:J0MEidG5o7UH6H9xwEqkYdtEn/DmMxsdCLj2I+fYXrPPkhoWPwkFhgWw/13s1tGw:JOkG5lHYLqMmdK2IfzkCkFOP30BZ |
MD5: | E09531B89414706804DA63BADE235FF4 |
SHA1: | 48CBDD29895F66F4D348A9C9A1C7E9A25C3D1F09 |
SHA-256: | F53D82D21E02449FB279D235FE11F5682A30D0368F3F883434DD469C1E2D1377 |
SHA-512: | 65ED1D05872B98FB3FDBBAE28E1CB71D5ACF2EC79B92C7E3147F1E7D20C446BD15B15F7B06850E14CDE6B4CAB5500312A9E6E3D0BF139E31596D722B00997AEE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 471 |
Entropy (8bit): | 7.2065006082985725 |
Encrypted: | false |
SSDEEP: | 6:J0MEidG5o7UH6H9xwEqkYdtEn/DmMxsdCLj2I+fYXrPPkhoWPwkFhgWw/13s1tGw:JOkG5lHYLqMmdK2IfzkCkFOP30BZ |
MD5: | E09531B89414706804DA63BADE235FF4 |
SHA1: | 48CBDD29895F66F4D348A9C9A1C7E9A25C3D1F09 |
SHA-256: | F53D82D21E02449FB279D235FE11F5682A30D0368F3F883434DD469C1E2D1377 |
SHA-512: | 65ED1D05872B98FB3FDBBAE28E1CB71D5ACF2EC79B92C7E3147F1E7D20C446BD15B15F7B06850E14CDE6B4CAB5500312A9E6E3D0BF139E31596D722B00997AEE |
Malicious: | false |
Reputation: | low |
URL: | http://status.thawte.com//MFEwTzBNMEswSTAJBgUrDgMCGgUABBRzhKfQYsAHQZZDzb8RtQ5PgsTjQQQUpYz%2BMszrDyzUGcYIuAAkiF3DxbcCEAuHlVK1KTZl0evTeFWOnVg%3D |
Preview: |
Icon Hash: | 00b29a8e86828200 |
Download Network PCAP: filtered – full
- Total Packets: 95
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 7, 2023 15:02:49.917004108 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:02:49.917020082 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:02:50.026473999 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:02:55.764755964 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:55.764808893 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:55.764888048 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:55.765194893 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:55.765283108 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:55.765362024 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:55.766189098 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:55.766206026 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:55.766428947 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:55.766462088 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.085910082 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.086255074 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.086313009 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.087057114 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.087152004 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.088901997 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.088985920 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.090070963 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:56.095181942 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:56.095206976 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:56.095551968 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.095684052 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.095864058 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.095874071 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.096858978 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:56.096929073 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:56.098258018 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:56.098345041 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:56.098501921 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:56.098514080 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:56.230448961 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.230448008 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:56.362190008 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.363244057 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.363333941 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.363648891 CET | 49705 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 7, 2023 15:02:56.363688946 CET | 443 | 49705 | 192.178.50.46 | 192.168.2.5 |
Dec 7, 2023 15:02:56.375889063 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:56.376173973 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:56.376281023 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:56.376874924 CET | 49704 | 443 | 192.168.2.5 | 142.250.64.141 |
Dec 7, 2023 15:02:56.376904964 CET | 443 | 49704 | 142.250.64.141 | 192.168.2.5 |
Dec 7, 2023 15:02:58.040376902 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:58.040435076 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:02:58.040513992 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:58.040935040 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:58.040955067 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:02:58.330024004 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:02:58.330367088 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:58.330430031 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:02:58.332068920 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:02:58.332180977 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:58.333447933 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:58.333559990 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:02:58.373454094 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:58.373466015 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:02:58.420639038 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:02:59.526632071 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:02:59.526633978 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:02:59.628803968 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:00.529115915 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:00.529159069 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:00.529242992 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:00.532367945 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:00.532386065 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:00.800410032 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:00.800683975 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:00.804109097 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:00.804124117 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:00.804553986 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:00.858104944 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:00.894768953 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:00.936743975 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.049007893 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.049093962 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.049200058 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.049398899 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.049417973 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.049459934 CET | 49714 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.049467087 CET | 443 | 49714 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.058665991 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Dec 7, 2023 15:03:01.058772087 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:01.103388071 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.103430033 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.103537083 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.104144096 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.104157925 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.361572981 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.361758947 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.363020897 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.363053083 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.363390923 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.364599943 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.408740044 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.612252951 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.612411022 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.612508059 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.613545895 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.613545895 CET | 49715 | 443 | 192.168.2.5 | 23.204.156.130 |
Dec 7, 2023 15:03:01.613593102 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:01.613621950 CET | 443 | 49715 | 23.204.156.130 | 192.168.2.5 |
Dec 7, 2023 15:03:08.305449009 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:08.305510998 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:08.305619955 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:03:10.094424963 CET | 49711 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:03:10.094502926 CET | 443 | 49711 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:10.164587021 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:10.164632082 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:10.164740086 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:10.167124033 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:10.167135954 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:10.664676905 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:10.664792061 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:10.678982019 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:10.679019928 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:10.679486036 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:10.731661081 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.230439901 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.247517109 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:11.248758078 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:11.249744892 CET | 49720 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:11.249798059 CET | 443 | 49720 | 23.1.237.91 | 192.168.2.5 |
Dec 7, 2023 15:03:11.249880075 CET | 49720 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:11.250719070 CET | 49720 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:11.250740051 CET | 443 | 49720 | 23.1.237.91 | 192.168.2.5 |
Dec 7, 2023 15:03:11.272743940 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.430450916 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Dec 7, 2023 15:03:11.431746006 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Dec 7, 2023 15:03:11.549880028 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.549916029 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.549925089 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.549947977 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.549971104 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.549978971 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.549989939 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.550013065 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.550050974 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.550085068 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.550544024 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.550637960 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.550642967 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.550656080 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.550729036 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.632666111 CET | 443 | 49720 | 23.1.237.91 | 192.168.2.5 |
Dec 7, 2023 15:03:11.632837057 CET | 49720 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:11.867788076 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.867788076 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:11.867836952 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:11.867854118 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:21.294608116 CET | 80 | 49709 | 195.200.45.10 | 192.168.2.5 |
Dec 7, 2023 15:03:30.806865931 CET | 443 | 49720 | 23.1.237.91 | 192.168.2.5 |
Dec 7, 2023 15:03:30.807096004 CET | 49720 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 7, 2023 15:03:48.234379053 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:48.234425068 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:48.234524965 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:48.235152960 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:48.235169888 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:48.749973059 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:48.750102997 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:48.755405903 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:48.755426884 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:48.755836964 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:48.768706083 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:48.812733889 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:49.224703074 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:49.224837065 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:49.224952936 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:49.225150108 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:49.225150108 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:49.225199938 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:49.225229979 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:49.225280046 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:49.225326061 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:49.236581087 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:49.236613035 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:49.236685991 CET | 49724 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 7, 2023 15:03:49.236700058 CET | 443 | 49724 | 13.85.23.86 | 192.168.2.5 |
Dec 7, 2023 15:03:57.955111980 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:03:57.955204964 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:57.955303907 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:03:57.956655025 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:03:57.956693888 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:58.241117954 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:58.241538048 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:03:58.241578102 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:58.241967916 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:58.242659092 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:03:58.242731094 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:03:58.283001900 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:04:08.219012976 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:04:08.219163895 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Dec 7, 2023 15:04:08.219337940 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:04:10.117304087 CET | 49726 | 443 | 192.168.2.5 | 142.250.217.228 |
Dec 7, 2023 15:04:10.117366076 CET | 443 | 49726 | 142.250.217.228 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 7, 2023 15:02:55.571717978 CET | 58527 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:55.600485086 CET | 56306 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:55.604577065 CET | 57047 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:55.604877949 CET | 56005 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:55.696245909 CET | 53 | 62932 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:02:55.697247982 CET | 53 | 58527 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:02:55.727010012 CET | 53 | 56306 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:02:55.729518890 CET | 53 | 56005 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:02:55.730360985 CET | 53 | 57047 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:02:56.555212975 CET | 53 | 52311 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:02:57.590269089 CET | 58641 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:57.590503931 CET | 50559 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:57.910032034 CET | 49685 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:57.910985947 CET | 55943 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 7, 2023 15:02:58.035283089 CET | 53 | 49685 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:02:58.036242008 CET | 53 | 55943 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:03:13.561676979 CET | 53 | 63409 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:03:32.530524015 CET | 53 | 64833 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:03:55.006676912 CET | 53 | 58510 | 1.1.1.1 | 192.168.2.5 |
Dec 7, 2023 15:03:55.084480047 CET | 53 | 61900 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 7, 2023 15:02:55.571717978 CET | 192.168.2.5 | 1.1.1.1 | 0x9dc2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 7, 2023 15:02:55.600485086 CET | 192.168.2.5 | 1.1.1.1 | 0x1789 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 7, 2023 15:02:55.604577065 CET | 192.168.2.5 | 1.1.1.1 | 0x41b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 7, 2023 15:02:55.604877949 CET | 192.168.2.5 | 1.1.1.1 | 0x9ec8 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 7, 2023 15:02:57.590269089 CET | 192.168.2.5 | 1.1.1.1 | 0x308a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 7, 2023 15:02:57.590503931 CET | 192.168.2.5 | 1.1.1.1 | 0xba38 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 7, 2023 15:02:57.910032034 CET | 192.168.2.5 | 1.1.1.1 | 0xf540 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 7, 2023 15:02:57.910985947 CET | 192.168.2.5 | 1.1.1.1 | 0xafb4 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 7, 2023 15:02:55.697247982 CET | 1.1.1.1 | 192.168.2.5 | 0x9dc2 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 7, 2023 15:02:55.697247982 CET | 1.1.1.1 | 192.168.2.5 | 0x9dc2 | No error (0) | 192.178.50.46 | A (IP address) | IN (0x0001) | false | ||
Dec 7, 2023 15:02:55.727010012 CET | 1.1.1.1 | 192.168.2.5 | 0x1789 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 7, 2023 15:02:55.730360985 CET | 1.1.1.1 | 192.168.2.5 | 0x41b8 | No error (0) | 142.250.64.141 | A (IP address) | IN (0x0001) | false | ||
Dec 7, 2023 15:02:58.035283089 CET | 1.1.1.1 | 192.168.2.5 | 0xf540 | No error (0) | 142.250.217.228 | A (IP address) | IN (0x0001) | false | ||
Dec 7, 2023 15:02:58.036242008 CET | 1.1.1.1 | 192.168.2.5 | 0xafb4 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49705 | 192.178.50.46 | 443 | 6696 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-07 14:02:56 UTC | 752 | OUT | |
2023-12-07 14:02:56 UTC | 732 | IN | |
2023-12-07 14:02:56 UTC | 520 | IN | |
2023-12-07 14:02:56 UTC | 200 | IN | |
2023-12-07 14:02:56 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49704 | 142.250.64.141 | 443 | 6696 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-07 14:02:56 UTC | 680 | OUT | |
2023-12-07 14:02:56 UTC | 1 | OUT | |
2023-12-07 14:02:56 UTC | 1627 | IN | |
2023-12-07 14:02:56 UTC | 23 | IN | |
2023-12-07 14:02:56 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49714 | 23.204.156.130 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-07 14:03:00 UTC | 161 | OUT | |
2023-12-07 14:03:01 UTC | 495 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49715 | 23.204.156.130 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-07 14:03:01 UTC | 239 | OUT | |
2023-12-07 14:03:01 UTC | 531 | IN | |
2023-12-07 14:03:01 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49716 | 13.85.23.86 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-07 14:03:11 UTC | 306 | OUT | |
2023-12-07 14:03:11 UTC | 560 | IN | |
2023-12-07 14:03:11 UTC | 15824 | IN | |
2023-12-07 14:03:11 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49724 | 13.85.23.86 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-07 14:03:48 UTC | 306 | OUT | |
2023-12-07 14:03:49 UTC | 560 | IN | |
2023-12-07 14:03:49 UTC | 15824 | IN | |
2023-12-07 14:03:49 UTC | 9633 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 15:02:51 |
Start date: | 07/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 15:02:52 |
Start date: | 07/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 15:02:56 |
Start date: | 07/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |