Windows
Analysis Report
https://f005.backblazeb2.com/file/yahoos66/glogin.html
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 5432 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 5076 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2076 --fi eld-trial- handle=201 2,i,246955 8705971810 017,144508 8141518203 0102,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6536 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://f005.b ackblazeb2 .com/file/ yahoos66/g login.html MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | SlashNext: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.251.116.84 | true | false | high | |
f005.backblazeb2.com | 149.137.136.16 | true | false | unknown | |
www.google.com | 142.250.113.106 | true | false | high | |
clients.l.google.com | 142.250.115.113 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown | |
windowsupdatebg.s.llnwi.net | 208.111.176.192 | true | false | unknown | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
false | high | ||
false |
| unknown | |
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.113.106 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.115.113 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.116.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
149.137.136.16 | f005.backblazeb2.com | United States | 30103 | ZOOM-VIDEO-COMM-ASUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 38.0.0 Ammolite |
Analysis ID: | 1369054 |
Start date and time: | 2024-01-03 00:15:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 50s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://f005.backblazeb2.com/file/yahoos66/glogin.html |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@16/0@8/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.251.116.94, 34.104.35.123, 40.127.169.103, 208.111.176.192, 192.229.211.108, 13.95.31.18, 20.3.187.198
- Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://f005.backblazeb2.com/file/yahoos66/glogin.html
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 3, 2024 00:15:56.038455963 CET | 49678 | 443 | 192.168.2.4 | 104.46.162.224 |
Jan 3, 2024 00:15:57.335397959 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jan 3, 2024 00:16:04.538268089 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:04.538320065 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:04.538433075 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:04.538983107 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.538990021 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.539037943 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.543041945 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.543052912 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.543212891 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:04.543224096 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:04.828548908 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.829161882 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.829183102 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.829899073 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.830166101 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.830687046 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:04.830972910 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.830982924 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:04.830988884 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:04.831017017 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.832182884 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:04.832230091 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:04.833098888 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.833164930 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.833451986 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:04.833522081 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:04.833600044 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.833607912 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:04.835078001 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:04.835083961 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:04.930324078 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:04.930387974 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:05.089663029 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:05.089859009 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:05.090002060 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:05.090117931 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:05.090224028 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:05.091238022 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:05.091238022 CET | 49730 | 443 | 192.168.2.4 | 142.250.115.113 |
Jan 3, 2024 00:16:05.091264009 CET | 443 | 49730 | 142.250.115.113 | 192.168.2.4 |
Jan 3, 2024 00:16:05.091814041 CET | 49729 | 443 | 192.168.2.4 | 142.251.116.84 |
Jan 3, 2024 00:16:05.091820002 CET | 443 | 49729 | 142.251.116.84 | 192.168.2.4 |
Jan 3, 2024 00:16:05.965162039 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:05.965200901 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:05.965277910 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:05.965908051 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:05.965950012 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:05.966002941 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:05.966197014 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:05.966211081 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:05.966434956 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:05.966454029 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.297584057 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.297831059 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.297859907 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.298815012 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.298883915 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.299896955 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.299958944 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.300116062 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.300123930 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.304429054 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.304615974 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.304630041 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.306399107 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.306459904 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.307284117 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.307404995 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.352652073 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.352652073 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.352660894 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.399395943 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.609257936 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.609333038 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.609388113 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.610312939 CET | 49735 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.610328913 CET | 443 | 49735 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.652101994 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.692743063 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.811780930 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.811834097 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.811878920 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.812350035 CET | 49734 | 443 | 192.168.2.4 | 149.137.136.16 |
Jan 3, 2024 00:16:06.812369108 CET | 443 | 49734 | 149.137.136.16 | 192.168.2.4 |
Jan 3, 2024 00:16:06.945077896 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jan 3, 2024 00:16:07.925894976 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:07.925937891 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:07.926002026 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:07.927732944 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:07.927748919 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:08.181571960 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:08.182035923 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:08.182049036 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:08.182915926 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:08.182971954 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:08.186466932 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:08.186522007 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:08.226299047 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:08.226309061 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:08.273169041 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:09.465696096 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.465725899 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.465806961 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.469079971 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.469091892 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.722203970 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.722362995 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.725109100 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.725115061 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.725393057 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.772078991 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.836874008 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.884727001 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.960968018 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.961010933 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.964385986 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.977555037 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.977555037 CET | 49739 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:09.977566004 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:09.977574110 CET | 443 | 49739 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.045407057 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.045433998 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.045521021 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.046339989 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.046351910 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.302135944 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.302198887 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.303622961 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.303628922 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.303822041 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.305330038 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.352741957 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.543596029 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.543740988 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.543797970 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.544913054 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.544924974 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:10.544935942 CET | 49740 | 443 | 192.168.2.4 | 173.223.108.114 |
Jan 3, 2024 00:16:10.544941902 CET | 443 | 49740 | 173.223.108.114 | 192.168.2.4 |
Jan 3, 2024 00:16:18.184220076 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:18.184278965 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:16:18.184406996 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:18.896047115 CET | 49738 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:16:18.896071911 CET | 443 | 49738 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:07.846563101 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:07.846589088 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:07.846693993 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:07.847858906 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:07.847868919 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:08.100671053 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:08.101032972 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:08.101044893 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:08.101330042 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:08.102936029 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:08.102994919 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:08.147583008 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:14.991451979 CET | 49723 | 80 | 192.168.2.4 | 72.21.81.240 |
Jan 3, 2024 00:17:14.991571903 CET | 49724 | 80 | 192.168.2.4 | 72.21.81.240 |
Jan 3, 2024 00:17:15.112150908 CET | 80 | 49724 | 72.21.81.240 | 192.168.2.4 |
Jan 3, 2024 00:17:15.112190962 CET | 80 | 49723 | 72.21.81.240 | 192.168.2.4 |
Jan 3, 2024 00:17:15.112318993 CET | 49723 | 80 | 192.168.2.4 | 72.21.81.240 |
Jan 3, 2024 00:17:15.112395048 CET | 49724 | 80 | 192.168.2.4 | 72.21.81.240 |
Jan 3, 2024 00:17:18.127991915 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:18.128051043 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Jan 3, 2024 00:17:18.128099918 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:19.140160084 CET | 49749 | 443 | 192.168.2.4 | 142.250.113.106 |
Jan 3, 2024 00:17:19.140180111 CET | 443 | 49749 | 142.250.113.106 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 3, 2024 00:16:04.301476002 CET | 60824 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:04.305006027 CET | 53 | 61607 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:04.309448004 CET | 53877 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:04.311645985 CET | 51783 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:04.312212944 CET | 61066 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:04.424963951 CET | 53 | 60824 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:04.433836937 CET | 53 | 53877 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:04.435743093 CET | 53 | 51783 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:04.436089993 CET | 53 | 61066 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:05.262746096 CET | 53 | 52423 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:05.839560032 CET | 57732 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:05.840270042 CET | 60378 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:05.964449883 CET | 53 | 60378 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:05.964471102 CET | 53 | 57732 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:07.794236898 CET | 62333 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:07.794572115 CET | 64519 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2024 00:16:07.921705008 CET | 53 | 64519 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:07.922810078 CET | 53 | 62333 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:22.426980019 CET | 53 | 63609 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:16:26.560215950 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Jan 3, 2024 00:16:41.461690903 CET | 53 | 51696 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:17:03.900154114 CET | 53 | 51635 | 1.1.1.1 | 192.168.2.4 |
Jan 3, 2024 00:17:03.955634117 CET | 53 | 61853 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 3, 2024 00:16:04.301476002 CET | 192.168.2.4 | 1.1.1.1 | 0xc5af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2024 00:16:04.309448004 CET | 192.168.2.4 | 1.1.1.1 | 0xb3eb | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 3, 2024 00:16:04.311645985 CET | 192.168.2.4 | 1.1.1.1 | 0x2ac2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2024 00:16:04.312212944 CET | 192.168.2.4 | 1.1.1.1 | 0x97bc | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 3, 2024 00:16:05.839560032 CET | 192.168.2.4 | 1.1.1.1 | 0xdfed | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2024 00:16:05.840270042 CET | 192.168.2.4 | 1.1.1.1 | 0x93ba | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 3, 2024 00:16:07.794236898 CET | 192.168.2.4 | 1.1.1.1 | 0x66a4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 3, 2024 00:16:07.794572115 CET | 192.168.2.4 | 1.1.1.1 | 0xdd53 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 3, 2024 00:16:04.424963951 CET | 1.1.1.1 | 192.168.2.4 | 0xc5af | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.424963951 CET | 1.1.1.1 | 192.168.2.4 | 0xc5af | No error (0) | 142.250.115.113 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.424963951 CET | 1.1.1.1 | 192.168.2.4 | 0xc5af | No error (0) | 142.250.115.139 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.424963951 CET | 1.1.1.1 | 192.168.2.4 | 0xc5af | No error (0) | 142.250.115.101 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.424963951 CET | 1.1.1.1 | 192.168.2.4 | 0xc5af | No error (0) | 142.250.115.100 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.424963951 CET | 1.1.1.1 | 192.168.2.4 | 0xc5af | No error (0) | 142.250.115.138 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.424963951 CET | 1.1.1.1 | 192.168.2.4 | 0xc5af | No error (0) | 142.250.115.102 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.433836937 CET | 1.1.1.1 | 192.168.2.4 | 0xb3eb | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:04.435743093 CET | 1.1.1.1 | 192.168.2.4 | 0x2ac2 | No error (0) | 142.251.116.84 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:05.964471102 CET | 1.1.1.1 | 192.168.2.4 | 0xdfed | No error (0) | 149.137.136.16 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:07.921705008 CET | 1.1.1.1 | 192.168.2.4 | 0xdd53 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 3, 2024 00:16:07.922810078 CET | 1.1.1.1 | 192.168.2.4 | 0x66a4 | No error (0) | 142.250.113.106 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:07.922810078 CET | 1.1.1.1 | 192.168.2.4 | 0x66a4 | No error (0) | 142.250.113.99 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:07.922810078 CET | 1.1.1.1 | 192.168.2.4 | 0x66a4 | No error (0) | 142.250.113.103 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:07.922810078 CET | 1.1.1.1 | 192.168.2.4 | 0x66a4 | No error (0) | 142.250.113.104 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:07.922810078 CET | 1.1.1.1 | 192.168.2.4 | 0x66a4 | No error (0) | 142.250.113.147 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:07.922810078 CET | 1.1.1.1 | 192.168.2.4 | 0x66a4 | No error (0) | 142.250.113.105 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:20.609956980 CET | 1.1.1.1 | 192.168.2.4 | 0x749f | No error (0) | 208.111.176.192 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:20.609956980 CET | 1.1.1.1 | 192.168.2.4 | 0x749f | No error (0) | 208.111.176.128 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:21.044065952 CET | 1.1.1.1 | 192.168.2.4 | 0x62ad | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:21.044065952 CET | 1.1.1.1 | 192.168.2.4 | 0x62ad | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:34.239945889 CET | 1.1.1.1 | 192.168.2.4 | 0xaf06 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:34.239945889 CET | 1.1.1.1 | 192.168.2.4 | 0xaf06 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:56.535414934 CET | 1.1.1.1 | 192.168.2.4 | 0x8914 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 3, 2024 00:16:56.535414934 CET | 1.1.1.1 | 192.168.2.4 | 0x8914 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2024 00:17:16.896123886 CET | 1.1.1.1 | 192.168.2.4 | 0xf05c | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 3, 2024 00:17:16.896123886 CET | 1.1.1.1 | 192.168.2.4 | 0xf05c | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 142.250.115.113 | 443 | 5076 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-02 23:16:04 UTC | 752 | OUT | |
2024-01-02 23:16:05 UTC | 732 | IN | |
2024-01-02 23:16:05 UTC | 520 | IN | |
2024-01-02 23:16:05 UTC | 200 | IN | |
2024-01-02 23:16:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49729 | 142.251.116.84 | 443 | 5076 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-02 23:16:04 UTC | 680 | OUT | |
2024-01-02 23:16:04 UTC | 1 | OUT | |
2024-01-02 23:16:05 UTC | 1627 | IN | |
2024-01-02 23:16:05 UTC | 23 | IN | |
2024-01-02 23:16:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49735 | 149.137.136.16 | 443 | 5076 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-02 23:16:06 UTC | 688 | OUT | |
2024-01-02 23:16:06 UTC | 186 | IN | |
2024-01-02 23:16:06 UTC | 135 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49734 | 149.137.136.16 | 443 | 5076 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-02 23:16:06 UTC | 621 | OUT | |
2024-01-02 23:16:06 UTC | 185 | IN | |
2024-01-02 23:16:06 UTC | 86 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49739 | 173.223.108.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-02 23:16:09 UTC | 161 | OUT | |
2024-01-02 23:16:09 UTC | 494 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49740 | 173.223.108.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-02 23:16:10 UTC | 239 | OUT | |
2024-01-02 23:16:10 UTC | 530 | IN | |
2024-01-02 23:16:10 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 00:15:59 |
Start date: | 03/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 00:16:02 |
Start date: | 03/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 00:16:04 |
Start date: | 03/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |