Windows
Analysis Report
https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1084 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 4696 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2344 --fi eld-trial- handle=242 8,i,227069 2946507266 797,100379 0393656007 6564,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 2992 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://tracki ng.buttond own.email/ CL0/https: //www.mcss l.com*2Fst ore*2Flega lresources inc*2Fcata log*2Fprod uct*2Fc87e 4d3524fa4e 94a805de09 b044d518/1 /0100018c5 9fa26f5-be c197ad-03f d-4c72-8a3 0-ad75c687 443e-00000 0/iTBdFoOs TeSuB2-Nbs _6I6XBN2KQ 9NehnwScBG kwzZg=330 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 172.217.3.77 | true | false | high | |
www.google.com | 142.250.217.164 | true | false | high | |
clients.l.google.com | 192.178.50.46 | true | false | high | |
d1yws0jclnpzob.cloudfront.net | 108.157.162.89 | true | false | high | |
clients2.google.com | unknown | unknown | false | high | |
tracking.buttondown.email | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.217.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
192.178.50.46 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
108.157.162.89 | d1yws0jclnpzob.cloudfront.net | United States | 16509 | AMAZON-02US | false | |
172.217.3.77 | accounts.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 38.0.0 Ammolite |
Analysis ID: | 1361816 |
Start date and time: | 2023-12-14 01:26:11 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 1m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://tracking.buttondown.email/CL0/https://www.mcssl.com*2Fstore*2Flegalresourcesinc*2Fcatalog*2Fproduct*2Fc87e4d3524fa4e94a805de09b044d518/1/0100018c59fa26f5-bec197ad-03fd-4c72-8a30-ad75c687443e-000000/iTBdFoOsTeSuB2-Nbs_6I6XBN2KQ9NehnwScBGkwzZg=330 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | UNKNOWN |
Classification: | unknown1.win@17/6@8/6 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- URL not reachable
- Exclude process from analysis
(whitelisted): dllhost.exe, SI HClient.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 192.178.50.67, 34. 104.35.123, 104.91.175.157, 23 .193.106.15, 192.229.211.108 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, ocsp.digicert.com, edgedl. me.gvt1.com, slscr.update.micr osoft.com, ctldl.windowsupdate .com, clientservices.googleapi s.com, fe3cr.delivery.mp.micro soft.com - Not all processes where analyz
ed, report is missing behavior information
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9756426939503697 |
Encrypted: | false |
SSDEEP: | 48:8qgdqTWiFHDidAKZdA19ehwiZUklqehJy+3:8cT3Cy |
MD5: | 290651A79B415F1F712BB7FA0E4C5234 |
SHA1: | 27F238883C0528268C16E2C28353E2C371893693 |
SHA-256: | 3CF5B9404C118E8AF265D98217E97ABA91F8D41C913C3CCD18A7C2DD1B3BAA4B |
SHA-512: | 1E3CA43F04E4522ED69E99C46D22C4484891FE9E9E329768C9A3A0FE8FF79E7D3996A4B2595CE02DA9B7D5F1FF54594D2B48DE59348F1093FB1E6363624F5A67 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9911928229629074 |
Encrypted: | false |
SSDEEP: | 48:86dqTWiFHDidAKZdA1weh/iZUkAQkqehyy+2:8zT99Qjy |
MD5: | E34D3644E0DE2BE401C4193A60B0DCDD |
SHA1: | 62771BB0ECB04CF5A190ADAF722A5702191F6CB1 |
SHA-256: | 06A4CF3AE00537167A0E8F7F647E31BADF476D83D9C94B3038C384545F03EF5C |
SHA-512: | 43BC4C7841857BEB12B186476E255E79748049D106336B16EB177C5FC05C81244511D1F92F509C7135D3C72A6F8F37C9E2FFC16730985593F467C043FFC0B305 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.003163831466344 |
Encrypted: | false |
SSDEEP: | 48:8xjdqTWisHDidAKZdA14tseh7sFiZUkmgqeh7sky+BX:8xET2nmy |
MD5: | 58F781995171D4BDC31CCC31CB71A09C |
SHA1: | 275FFD609ECA1AA8C8997FED4340E2832871C443 |
SHA-256: | EE820802DA5C94173D16154F78595B2F34CD8FD657868C5138FB31FA0F0B8A60 |
SHA-512: | 80A1A2D97D22AD830ABBF3F0FA452F2541A2FC4489D6425067011046AE41E1FDD8D12EE3B0A09E11EC4E2EB15FB115EC39D20AC22AC18D9A1C26A97F433A27C2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.989425689035601 |
Encrypted: | false |
SSDEEP: | 48:8ddqTWiFHDidAKZdA1vehDiZUkwqeh+y+R:86T+8y |
MD5: | 06C54A627432C704B428CF81F928F4AE |
SHA1: | B7659AD81203963283D52153673BED5ADA3597B5 |
SHA-256: | A1F6B0BCA2EB7F15ADA4D09C95AB22531B5A731DFE0FDC51CBB8563E86C69920 |
SHA-512: | C00C13A4D04AAB6D792224227478CABF482647C21BFD872E5E180BEBB6738029AC73DF16035AAC37D6A7432DEE7438193CAC0634CFED7B93C1ADB09D6E68FF5C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9788457635776813 |
Encrypted: | false |
SSDEEP: | 48:8ldqTWiFHDidAKZdA1hehBiZUk1W1qeh4y+C:8STO9Yy |
MD5: | 8AE549768E960A9D1BC1CA3B21AD1A96 |
SHA1: | 6E7C5EFD8B0680ECDD27380D88E6C6F96686F537 |
SHA-256: | 20BB32B10EAC0D58BCE57A67A03B7F46A52BCCBBCBA55B60758DC7890E2938E9 |
SHA-512: | E918808D286EF00B514B742D67CCFE126831C86CBD7A32B470721F7B72C8B01A7DF528881AB5B51EF6F1457AC88C4860316F13A869340650638A1B14BC7B3968 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9896673518881407 |
Encrypted: | false |
SSDEEP: | 48:87OdqTWiFHDidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbmy+yT+:87vTwT/TbxWOvTbmy7T |
MD5: | C146BC1F4C6C297F1C4B9F6B7DEC717B |
SHA1: | 1BF1989C630E43F59EDEB6D92E39A26963807978 |
SHA-256: | F7E3AE1D1546303EEBEAF65DAE7FE1A17511D34987E7B538BBF718CFC06460C5 |
SHA-512: | FE566C238F919FDD86F68924E3614D0409DA8D49963C108161D2E8E4647F9315B016003CCB8D00BDE83E3F44654FE895C593356697D047FD72FEF6C5DC3195F9 |
Malicious: | false |
Reputation: | low |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 92
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 14, 2023 01:26:57.195966959 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:26:57.195972919 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:26:57.289799929 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:01.268671036 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.268704891 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.268762112 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.269177914 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.269212008 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.269259930 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.269527912 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.269540071 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.269756079 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.269769907 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.560337067 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.560695887 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.560717106 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.561856985 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.561918974 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.562792063 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.562845945 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.563018084 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.563029051 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.563782930 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.563961983 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.563985109 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.564312935 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.564369917 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.564922094 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.564990044 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.565826893 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.565893888 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.566077948 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.566083908 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.731465101 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.762721062 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.840111971 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.840257883 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.840343952 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.840766907 CET | 49706 | 443 | 192.168.2.5 | 192.178.50.46 |
Dec 14, 2023 01:27:01.840780973 CET | 443 | 49706 | 192.178.50.46 | 192.168.2.5 |
Dec 14, 2023 01:27:01.853698969 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.854259968 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:01.854406118 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.854937077 CET | 49705 | 443 | 192.168.2.5 | 172.217.3.77 |
Dec 14, 2023 01:27:01.854948997 CET | 443 | 49705 | 172.217.3.77 | 192.168.2.5 |
Dec 14, 2023 01:27:02.375577927 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.375672102 CET | 443 | 49709 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.375773907 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.376626015 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.376662016 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.376704931 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.377001047 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.377018929 CET | 443 | 49709 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.377217054 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.377228022 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.648909092 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.649270058 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.649282932 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.650145054 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.650213957 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.651120901 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.651175976 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.651329041 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.651334047 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.683562040 CET | 443 | 49709 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.683912992 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.683936119 CET | 443 | 49709 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.684954882 CET | 443 | 49709 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.685019016 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.685385942 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.685452938 CET | 443 | 49709 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.700870037 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.732214928 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.732225895 CET | 443 | 49709 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.778887987 CET | 49709 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.937125921 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.937494040 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.937572956 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.937745094 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.937745094 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:02.937757015 CET | 443 | 49710 | 108.157.162.89 | 192.168.2.5 |
Dec 14, 2023 01:27:02.937805891 CET | 49710 | 443 | 192.168.2.5 | 108.157.162.89 |
Dec 14, 2023 01:27:05.462465048 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.462500095 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:05.462589979 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.463114977 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.463126898 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:05.737591982 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:05.739054918 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.739067078 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:05.740124941 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:05.740282059 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.743886948 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.743957043 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:05.792558908 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.792572021 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:05.839431047 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:05.953704119 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:05.953763008 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:05.953850985 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:05.957066059 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:05.957103968 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.215631962 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.215738058 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.217753887 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.217772007 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.218010902 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.261334896 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.267518997 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.312769890 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.460922956 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.460993052 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.461100101 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.471345901 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.471414089 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.471455097 CET | 49714 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.471472025 CET | 443 | 49714 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.521327019 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.521382093 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.521473885 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.522639990 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.522654057 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.777604103 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.777717113 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.781095982 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.781105995 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.781481981 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.782938957 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:06.808191061 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:06.808192968 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:06.828746080 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:06.901973963 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:07.060502052 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:07.060687065 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:07.060748100 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:07.062660933 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:07.062681913 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:07.062695026 CET | 49715 | 443 | 192.168.2.5 | 23.205.142.165 |
Dec 14, 2023 01:27:07.062700987 CET | 443 | 49715 | 23.205.142.165 | 192.168.2.5 |
Dec 14, 2023 01:27:08.318592072 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Dec 14, 2023 01:27:08.318717003 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:15.715478897 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:15.715552092 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:15.715656996 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:17.332492113 CET | 49713 | 443 | 192.168.2.5 | 142.250.217.164 |
Dec 14, 2023 01:27:17.332525969 CET | 443 | 49713 | 142.250.217.164 | 192.168.2.5 |
Dec 14, 2023 01:27:17.428992987 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:17.429040909 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:17.429126024 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:17.431574106 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:17.431587934 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:17.921688080 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:17.921794891 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:18.033026934 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:18.033052921 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.033363104 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.073709011 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:18.572587013 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:18.610486984 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:18.610619068 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:18.611033916 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:18.611062050 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Dec 14, 2023 01:27:18.611139059 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:18.611390114 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:18.611402035 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Dec 14, 2023 01:27:18.616741896 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.793035984 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Dec 14, 2023 01:27:18.793164968 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891621113 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891650915 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891658068 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891669989 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891705990 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891766071 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:18.891793013 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891808987 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891819000 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:18.891824961 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:18.891880035 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:19.004640102 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Dec 14, 2023 01:27:19.004829884 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 14, 2023 01:27:19.190934896 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:19.190964937 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Dec 14, 2023 01:27:19.190980911 CET | 49716 | 443 | 192.168.2.5 | 13.85.23.86 |
Dec 14, 2023 01:27:19.190989017 CET | 443 | 49716 | 13.85.23.86 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 14, 2023 01:27:01.142054081 CET | 59477 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:01.142457008 CET | 65340 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:01.143033981 CET | 59592 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:01.143335104 CET | 62330 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:01.251549006 CET | 53 | 61951 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:01.267858028 CET | 53 | 59477 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:01.268178940 CET | 53 | 62330 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:01.268253088 CET | 53 | 59592 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:01.268341064 CET | 53 | 65340 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:02.011274099 CET | 53 | 57073 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:02.242957115 CET | 60039 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:02.243156910 CET | 59100 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:02.373641968 CET | 53 | 60039 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:02.373667002 CET | 53 | 59100 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:05.315639973 CET | 56959 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:05.316418886 CET | 52292 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 14, 2023 01:27:05.442394972 CET | 53 | 56959 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:05.456238031 CET | 53 | 52292 | 1.1.1.1 | 192.168.2.5 |
Dec 14, 2023 01:27:20.169315100 CET | 53 | 53884 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 14, 2023 01:27:01.142054081 CET | 192.168.2.5 | 1.1.1.1 | 0x21aa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 14, 2023 01:27:01.142457008 CET | 192.168.2.5 | 1.1.1.1 | 0xd50e | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 14, 2023 01:27:01.143033981 CET | 192.168.2.5 | 1.1.1.1 | 0xc98d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 14, 2023 01:27:01.143335104 CET | 192.168.2.5 | 1.1.1.1 | 0xa6b | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 14, 2023 01:27:02.242957115 CET | 192.168.2.5 | 1.1.1.1 | 0x92c6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 14, 2023 01:27:02.243156910 CET | 192.168.2.5 | 1.1.1.1 | 0x974c | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 14, 2023 01:27:05.315639973 CET | 192.168.2.5 | 1.1.1.1 | 0x3824 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 14, 2023 01:27:05.316418886 CET | 192.168.2.5 | 1.1.1.1 | 0xc21d | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 14, 2023 01:27:01.267858028 CET | 1.1.1.1 | 192.168.2.5 | 0x21aa | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:01.267858028 CET | 1.1.1.1 | 192.168.2.5 | 0x21aa | No error (0) | 192.178.50.46 | A (IP address) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:01.268253088 CET | 1.1.1.1 | 192.168.2.5 | 0xc98d | No error (0) | 172.217.3.77 | A (IP address) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:01.268341064 CET | 1.1.1.1 | 192.168.2.5 | 0xd50e | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:02.373641968 CET | 1.1.1.1 | 192.168.2.5 | 0x92c6 | No error (0) | d1yws0jclnpzob.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:02.373641968 CET | 1.1.1.1 | 192.168.2.5 | 0x92c6 | No error (0) | 108.157.162.89 | A (IP address) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:02.373641968 CET | 1.1.1.1 | 192.168.2.5 | 0x92c6 | No error (0) | 108.157.162.129 | A (IP address) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:02.373641968 CET | 1.1.1.1 | 192.168.2.5 | 0x92c6 | No error (0) | 108.157.162.66 | A (IP address) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:02.373641968 CET | 1.1.1.1 | 192.168.2.5 | 0x92c6 | No error (0) | 108.157.162.93 | A (IP address) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:02.373667002 CET | 1.1.1.1 | 192.168.2.5 | 0x974c | No error (0) | d1yws0jclnpzob.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:05.442394972 CET | 1.1.1.1 | 192.168.2.5 | 0x3824 | No error (0) | 142.250.217.164 | A (IP address) | IN (0x0001) | false | ||
Dec 14, 2023 01:27:05.456238031 CET | 1.1.1.1 | 192.168.2.5 | 0xc21d | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49705 | 172.217.3.77 | 443 | 4696 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-14 00:27:01 UTC | 680 | OUT | |
2023-12-14 00:27:01 UTC | 1 | OUT | |
2023-12-14 00:27:01 UTC | 1627 | IN | |
2023-12-14 00:27:01 UTC | 23 | IN | |
2023-12-14 00:27:01 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49706 | 192.178.50.46 | 443 | 4696 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-14 00:27:01 UTC | 752 | OUT | |
2023-12-14 00:27:01 UTC | 732 | IN | |
2023-12-14 00:27:01 UTC | 520 | IN | |
2023-12-14 00:27:01 UTC | 200 | IN | |
2023-12-14 00:27:01 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49710 | 108.157.162.89 | 443 | 4696 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-14 00:27:02 UTC | 887 | OUT | |
2023-12-14 00:27:02 UTC | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49714 | 23.205.142.165 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-14 00:27:06 UTC | 161 | OUT | |
2023-12-14 00:27:06 UTC | 495 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49715 | 23.205.142.165 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-14 00:27:06 UTC | 239 | OUT | |
2023-12-14 00:27:07 UTC | 531 | IN | |
2023-12-14 00:27:07 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49716 | 13.85.23.86 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2023-12-14 00:27:18 UTC | 306 | OUT | |
2023-12-14 00:27:18 UTC | 560 | IN | |
2023-12-14 00:27:18 UTC | 15824 | IN | |
2023-12-14 00:27:18 UTC | 8666 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 01:26:56 |
Start date: | 14/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 01:26:59 |
Start date: | 14/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 01:27:01 |
Start date: | 14/12/2023 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |