Windows
Analysis Report
http://81hmpnd6.r.us-east-1.awstrack.me/L0/http:%2F%2Fwww.adp.com%2Fgomobile/1/0100018cfc63f3fc-968a7e9a-df04-4629-a446-bbb33b6a491f-000000/teyeg_3VLgxNN0FH6agO8tyAygs=356
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6836 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 6552 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2884 --fi eld-trial- handle=230 8,i,133329 7501820584 7990,12237 4395242003 86751,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6928 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http ://81hmpnd 6.r.us-eas t-1.awstra ck.me/L0/h ttp:%2F%2F www.adp.co m%2Fgomobi le/1/01000 18cfc63f3f c-968a7e9a -df04-4629 -a446-bbb3 3b6a491f-0 00000/teye g_3VLgxNN0 FH6agO8tyA ygs=356 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 3 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 4 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 172.253.115.84 | true | false | high | |
www.google.com | 172.253.115.99 | true | false | high | |
clients.l.google.com | 142.251.16.113 | true | false | high | |
baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com | 52.71.223.223 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown | |
clients1.google.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high | |
www.adp.com | unknown | unknown | false | high | |
81hmpnd6.r.us-east-1.awstrack.me | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false |
| unknown | |
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.253.115.99 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
52.71.223.223 | baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com | United States | 14618 | AMAZON-AESUS | false | |
142.251.16.113 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
35.169.72.125 | unknown | United States | 14618 | AMAZON-AESUS | false | |
172.253.115.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.30 |
192.168.2.8 |
Joe Sandbox version: | 38.0.0 Ammolite |
Analysis ID: | 1373804 |
Start date and time: | 2024-01-12 15:20:19 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 8s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://81hmpnd6.r.us-east-1.awstrack.me/L0/http:%2F%2Fwww.adp.com%2Fgomobile/1/0100018cfc63f3fc-968a7e9a-df04-4629-a446-bbb33b6a491f-000000/teyeg_3VLgxNN0FH6agO8tyAygs=356 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@17/7@14/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, SIHClient.exe, con host.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 172.253.63.94, 34. 104.35.123, 23.48.203.82, 23.4 8.203.77, 20.114.59.183, 192.2 29.211.108, 52.165.164.15, 20. 166.126.56, 142.251.167.94 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, slscr.update.microsoft.com , clientservices.googleapis.co m, fe3cr.delivery.mp.microsoft .com, fe3.delivery.mp.microsof t.com, edgedl.me.gvt1.com, ocs p.digicert.com, e178235.x.akam aiedge.net, ocsp.edge.digicert .com, glb.cws.prod.dcat.dsp.tr afficmanager.net, sls.update.m icrosoft.com, update.googleapi s.com, www.adp.com.edgekey.net , glb.sls.prod.dcat.dsp.traffi cmanager.net - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: http:/
/81hmpnd6.r.us-east-1.awstrack .me/L0/http:%2F%2Fwww.adp.com% 2Fgomobile/1/0100018cfc63f3fc- 968a7e9a-df04-4629-a446-bbb33b 6a491f-000000/teyeg_3VLgxNN0FH 6agO8tyAygs=356
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9779787890328713 |
Encrypted: | false |
SSDEEP: | 48:8I20d4T8kEHWZidAKZdA1oehwiZUklqehVy+3:8bLv4ay |
MD5: | 2D0B9FF11A8279BB5E4FBDC87F613076 |
SHA1: | 0EAA211250661337E34508A9E1E09D951BD6CC1F |
SHA-256: | 8392E28A4A3CD71F7D3F127A48902302FC599EFD82B0D21B733679FEB49B67A4 |
SHA-512: | FC9B759498F4F38583E52A7968EBAB2B9E9DDBC6C43F57EBFE2C8A9801FEC750CAAF95B4425352B35440A021DB5F56508EC142432B6AD0526BD879947B3CC361 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.991420528892717 |
Encrypted: | false |
SSDEEP: | 48:8z20d4T8kEHWZidAKZdA1leh/iZUkAQkqehKy+2:8qLvy9Q/y |
MD5: | 36B591D577BC424417E739736E0D4D63 |
SHA1: | E770C93AA3B9994B4F3E0EDE27199FF173223B8C |
SHA-256: | 7840392E79D9B7762877CFCD27D64CBA65C425057977C721C318196910E3F5EF |
SHA-512: | 2DADF0321D140BA23F6D507E65854FD273458289EB895E74E8BB6D8B8F78C12BA1C59CE86F43A98DDEA4687C73B48F9CCF56E607476C6093894F84AB86ECD976 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.00503662072569 |
Encrypted: | false |
SSDEEP: | 48:8J0d4T8kbHWZidAKZdA14t5eh7sFiZUkmgqeh7sEy+BX:8JLvjney |
MD5: | D8D764341DBC6920526A90572978760A |
SHA1: | A56A8EDDA979B669337F2A42C6A3BFA52C0C656B |
SHA-256: | 35B4325C5068A2598692E43F727F8BB58BE3E41750D7A7A8043B95AE6235F978 |
SHA-512: | AF8D5D139CFE21A6E091E7E1B9447D364CF6774F32B1F185B27799E9B5437ED9A41F8F75221E0D65F4CD225A1454FC293E08D8E2DE61D2C2494766BFCBB693F2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9912265969766527 |
Encrypted: | false |
SSDEEP: | 48:88a20d4T8kEHWZidAKZdA16ehDiZUkwqehmy+R:88dLvpMy |
MD5: | 51BD905E67E42E307FD591AF2646819F |
SHA1: | 5D80CEB2E7BE01E7349D634171ED26D2B23EC85D |
SHA-256: | 669BB6A704599B94C739FCF64363B6DC3074999462B0C58C0DE563D544C0ECCE |
SHA-512: | 296F7C0A4B1C282601F133D1193F5631F4DDDD65169D8B2097F456EBAFD7DFE1614048ED2BC49A2506AC65C0A339911FF00711F74CC8F57DB1E866FA70305687 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9812676907514994 |
Encrypted: | false |
SSDEEP: | 48:8j20d4T8kEHWZidAKZdA1UehBiZUk1W1qeh4y+C:8aLv59Yy |
MD5: | 57892CADF1A299770624D553418B747A |
SHA1: | 78485EF19257AEB95304B408D64494E708ED1F6B |
SHA-256: | 1BC4AB7C6FAF163C25A6B29F342891A1BB4AEB8FEEC1F80AADEBBB45AFABBB6A |
SHA-512: | 874163C0A8F71F0F50321B3A0494C9A36E358CF3702EF4F52F0EE3D6B0C4AE0561491997025966DEC6ECA5AD2C3C6A69F1D3A117FBEC8654F8104302CBF21DBC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.992447321769875 |
Encrypted: | false |
SSDEEP: | 48:8le20d4T8kEHWZidAKZdA1duTrehOuTbbiZUk5OjqehOuTbey+yT+:8TLvmTYTbxWOvTbey7T |
MD5: | 84F8613DB4C81DFC85E47DC6245A912D |
SHA1: | 15B05012A10DD123ED22FECD7C0D70BE05EB8B42 |
SHA-256: | 9B1D194D6555007E728B57B19F7B1F1491A8197E6169BC725FC33B5FDEF5DD23 |
SHA-512: | A5EA9C22F5BB608C316A2F4A96BBF598B9CF9F043A481ACADCD629C8E4BED01996770A281FB07B73F77791AB9458D3FEE99AFD5134FCEF34100BEE3E6750733E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 276 |
Entropy (8bit): | 5.356053140714409 |
Encrypted: | false |
SSDEEP: | 6:wBqWekiTakpxxdGztoIhS3EaTnRCsDPLCmKJ2U1XRJ3T:dkK9dg5qEaTnchdRJj |
MD5: | 87B7B3622F280ADFD6678A80D6856983 |
SHA1: | A69F1E71D42C89FD1C7E6EF58E84C31EA919E91B |
SHA-256: | 1444DF85EE372520F10533E1C58A7C0A5E23FB1CE40FEA702403914B0DBB2F39 |
SHA-512: | 896DD696B1F23789AA186DA5142D8B026DCDED56D1C5C1271AC5D02DFCC6B9C4E854491AB8F99532DE6EFCA47E75D8FA8CA2FD94863C0C4531480D54C8F8D02E |
Malicious: | false |
Reputation: | low |
URL: | https://www.adp.com/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 125
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 12, 2024 15:21:08.975197077 CET | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:09.249479055 CET | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:09.772012949 CET | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
Jan 12, 2024 15:21:11.037664890 CET | 49671 | 443 | 192.168.2.8 | 204.79.197.203 |
Jan 12, 2024 15:21:16.314548016 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.314558029 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.314616919 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.314891100 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.314903021 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.324542999 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.324599981 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.324691057 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.325007915 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.325036049 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.537796021 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.538027048 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.538037062 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.539319038 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.539395094 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.540258884 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.540333986 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.540447950 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.540455103 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.557851076 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.558099985 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.558116913 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.558700085 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.559112072 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.559381962 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.559442997 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.560539961 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.560607910 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.560677052 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.560686111 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.639056921 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.685882092 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.781526089 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.781968117 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.782037020 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.783201933 CET | 49706 | 443 | 192.168.2.8 | 172.253.115.84 |
Jan 12, 2024 15:21:16.783215046 CET | 443 | 49706 | 172.253.115.84 | 192.168.2.8 |
Jan 12, 2024 15:21:16.793524027 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.793629885 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:16.793688059 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.799770117 CET | 49707 | 443 | 192.168.2.8 | 142.251.16.113 |
Jan 12, 2024 15:21:16.799791098 CET | 443 | 49707 | 142.251.16.113 | 192.168.2.8 |
Jan 12, 2024 15:21:18.125598907 CET | 49710 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:18.125730991 CET | 49711 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:18.126193047 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.126291037 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.126384020 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.126629114 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.126662016 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.221929073 CET | 80 | 49710 | 52.71.223.223 | 192.168.2.8 |
Jan 12, 2024 15:21:18.222012043 CET | 80 | 49711 | 52.71.223.223 | 192.168.2.8 |
Jan 12, 2024 15:21:18.222022057 CET | 49710 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:18.222074986 CET | 49711 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:18.425462008 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.427038908 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.427103043 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.428188086 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.428275108 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.433759928 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.433856964 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.434514999 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.434533119 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.485723972 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.534141064 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.534240007 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.534307003 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.565015078 CET | 49712 | 443 | 192.168.2.8 | 35.169.72.125 |
Jan 12, 2024 15:21:18.565053940 CET | 443 | 49712 | 35.169.72.125 | 192.168.2.8 |
Jan 12, 2024 15:21:18.577775002 CET | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:18.672521114 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:18.672559977 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:18.672625065 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:18.673338890 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:18.673352003 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:18.859802961 CET | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:18.899452925 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:18.914586067 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:18.914608002 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:18.915707111 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:18.915775061 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:18.919095993 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:18.919255018 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:18.969033003 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:18.969044924 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:19.016275883 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:19.378087044 CET | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
Jan 12, 2024 15:21:20.268115997 CET | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:20.268205881 CET | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:20.877053976 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:20.877144098 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:20.877237082 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:20.884084940 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:20.884124041 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.098025084 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.098196030 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.104645014 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.104671001 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.105091095 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.154639006 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.196465015 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.237905979 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.304409027 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.304519892 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.304781914 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.304817915 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.304855108 CET | 49718 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.304863930 CET | 443 | 49718 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.365684032 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.365710020 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.365819931 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.366429090 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.366446018 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.582604885 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.582722902 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.588572979 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.588583946 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.589000940 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.591891050 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.637904882 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.815239906 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.815344095 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.815392017 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.817003965 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.817018032 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:21.817025900 CET | 49719 | 443 | 192.168.2.8 | 23.33.180.114 |
Jan 12, 2024 15:21:21.817032099 CET | 443 | 49719 | 23.33.180.114 | 192.168.2.8 |
Jan 12, 2024 15:21:28.900803089 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:28.900875092 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:28.900968075 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:30.454144001 CET | 49715 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:21:30.454159975 CET | 443 | 49715 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:21:31.591164112 CET | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:31.591617107 CET | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:31.649857044 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:31.649915934 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:31.650124073 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:31.668277979 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:31.668302059 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:31.745769978 CET | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:31.746124983 CET | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:31.987430096 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:31.987520933 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:32.037322998 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:32.037345886 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:32.037759066 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:32.037908077 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:32.040076017 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:32.040105104 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:32.040713072 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:32.085905075 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:32.339685917 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:32.339844942 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:32.339885950 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:32.339940071 CET | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
Jan 12, 2024 15:21:32.339975119 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:32.339993000 CET | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
Jan 12, 2024 15:21:49.055259943 CET | 80 | 49711 | 52.71.223.223 | 192.168.2.8 |
Jan 12, 2024 15:21:49.055284023 CET | 80 | 49710 | 52.71.223.223 | 192.168.2.8 |
Jan 12, 2024 15:21:49.055352926 CET | 49711 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:49.055375099 CET | 49710 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:50.490880966 CET | 49711 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:50.490950108 CET | 49710 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:50.795327902 CET | 49710 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:50.795331001 CET | 49711 | 80 | 192.168.2.8 | 52.71.223.223 |
Jan 12, 2024 15:21:50.890554905 CET | 80 | 49710 | 52.71.223.223 | 192.168.2.8 |
Jan 12, 2024 15:21:50.890595913 CET | 80 | 49711 | 52.71.223.223 | 192.168.2.8 |
Jan 12, 2024 15:22:00.160624027 CET | 49703 | 80 | 192.168.2.8 | 72.21.81.240 |
Jan 12, 2024 15:22:00.254972935 CET | 80 | 49703 | 72.21.81.240 | 192.168.2.8 |
Jan 12, 2024 15:22:00.255028009 CET | 49703 | 80 | 192.168.2.8 | 72.21.81.240 |
Jan 12, 2024 15:22:18.625840902 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:18.625916004 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:18.625982046 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:18.626319885 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:18.626337051 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:18.837847948 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:18.838315010 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:18.838341951 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:18.838692904 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:18.839943886 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:18.840008020 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:18.889622927 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:28.885416031 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:28.885577917 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:28.885657072 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:30.423541069 CET | 49725 | 443 | 192.168.2.8 | 172.253.115.99 |
Jan 12, 2024 15:22:30.423614025 CET | 443 | 49725 | 172.253.115.99 | 192.168.2.8 |
Jan 12, 2024 15:22:43.676481009 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.676529884 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:43.676599026 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.676873922 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.676887989 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:43.939625978 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:43.939954996 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.939985991 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:43.940375090 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:43.940470934 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.941168070 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:43.941237926 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.942399979 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.942470074 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:43.942575932 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.983287096 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:43.983314991 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:44.030292988 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Jan 12, 2024 15:22:44.217331886 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:44.217566013 CET | 443 | 49726 | 142.251.163.101 | 192.168.2.8 |
Jan 12, 2024 15:22:44.217674017 CET | 49726 | 443 | 192.168.2.8 | 142.251.163.101 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 12, 2024 15:21:16.216744900 CET | 62579 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:16.217021942 CET | 61267 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:16.217467070 CET | 56347 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:16.217709064 CET | 51524 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:16.308149099 CET | 53 | 54966 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:16.313376904 CET | 53 | 62579 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:16.313955069 CET | 53 | 56347 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:16.313991070 CET | 53 | 51524 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:16.324071884 CET | 53 | 61267 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:16.944164038 CET | 53 | 54208 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:17.994328022 CET | 51614 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:17.994605064 CET | 51205 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:18.010710001 CET | 65275 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:18.011032104 CET | 52919 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:18.093060017 CET | 53 | 51614 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:18.108577967 CET | 53 | 65275 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:18.124248981 CET | 53 | 51205 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:18.124353886 CET | 53 | 52919 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:18.574244022 CET | 62903 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:18.574501038 CET | 60504 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:18.577641010 CET | 61508 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:18.579147100 CET | 52371 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:21:18.669512987 CET | 53 | 62903 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:18.669805050 CET | 53 | 60504 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:33.972104073 CET | 53 | 65194 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:21:52.708684921 CET | 53 | 57868 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:22:00.194921017 CET | 138 | 138 | 192.168.2.8 | 192.168.2.255 |
Jan 12, 2024 15:22:15.288752079 CET | 53 | 49625 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:22:15.598341942 CET | 53 | 64103 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:22:43.158884048 CET | 53 | 53320 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:22:43.579982996 CET | 50343 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:22:43.580357075 CET | 51141 | 53 | 192.168.2.8 | 1.1.1.1 |
Jan 12, 2024 15:22:43.674963951 CET | 53 | 50343 | 1.1.1.1 | 192.168.2.8 |
Jan 12, 2024 15:22:43.676050901 CET | 53 | 51141 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 12, 2024 15:21:16.216744900 CET | 192.168.2.8 | 1.1.1.1 | 0x4ba9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2024 15:21:16.217021942 CET | 192.168.2.8 | 1.1.1.1 | 0x44d2 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 12, 2024 15:21:16.217467070 CET | 192.168.2.8 | 1.1.1.1 | 0xae60 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2024 15:21:16.217709064 CET | 192.168.2.8 | 1.1.1.1 | 0x7317 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 12, 2024 15:21:17.994328022 CET | 192.168.2.8 | 1.1.1.1 | 0x7513 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2024 15:21:17.994605064 CET | 192.168.2.8 | 1.1.1.1 | 0xb5a4 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 12, 2024 15:21:18.010710001 CET | 192.168.2.8 | 1.1.1.1 | 0xeb28 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2024 15:21:18.011032104 CET | 192.168.2.8 | 1.1.1.1 | 0x375a | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 12, 2024 15:21:18.574244022 CET | 192.168.2.8 | 1.1.1.1 | 0x4caf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2024 15:21:18.574501038 CET | 192.168.2.8 | 1.1.1.1 | 0x302a | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 12, 2024 15:21:18.577641010 CET | 192.168.2.8 | 1.1.1.1 | 0xa541 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2024 15:21:18.579147100 CET | 192.168.2.8 | 1.1.1.1 | 0x52bd | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 12, 2024 15:22:43.579982996 CET | 192.168.2.8 | 1.1.1.1 | 0x29f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 12, 2024 15:22:43.580357075 CET | 192.168.2.8 | 1.1.1.1 | 0x5995 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 12, 2024 15:21:16.313376904 CET | 1.1.1.1 | 192.168.2.8 | 0x4ba9 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.313376904 CET | 1.1.1.1 | 192.168.2.8 | 0x4ba9 | No error (0) | 142.251.16.113 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.313376904 CET | 1.1.1.1 | 192.168.2.8 | 0x4ba9 | No error (0) | 142.251.16.101 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.313376904 CET | 1.1.1.1 | 192.168.2.8 | 0x4ba9 | No error (0) | 142.251.16.100 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.313376904 CET | 1.1.1.1 | 192.168.2.8 | 0x4ba9 | No error (0) | 142.251.16.139 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.313376904 CET | 1.1.1.1 | 192.168.2.8 | 0x4ba9 | No error (0) | 142.251.16.102 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.313376904 CET | 1.1.1.1 | 192.168.2.8 | 0x4ba9 | No error (0) | 142.251.16.138 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.313955069 CET | 1.1.1.1 | 192.168.2.8 | 0xae60 | No error (0) | 172.253.115.84 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:16.324071884 CET | 1.1.1.1 | 192.168.2.8 | 0x44d2 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.093060017 CET | 1.1.1.1 | 192.168.2.8 | 0x7513 | No error (0) | r.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.093060017 CET | 1.1.1.1 | 192.168.2.8 | 0x7513 | No error (0) | r.delegate.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.093060017 CET | 1.1.1.1 | 192.168.2.8 | 0x7513 | No error (0) | baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.093060017 CET | 1.1.1.1 | 192.168.2.8 | 0x7513 | No error (0) | 52.71.223.223 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.093060017 CET | 1.1.1.1 | 192.168.2.8 | 0x7513 | No error (0) | 52.71.158.82 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.093060017 CET | 1.1.1.1 | 192.168.2.8 | 0x7513 | No error (0) | 35.169.72.125 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.108577967 CET | 1.1.1.1 | 192.168.2.8 | 0xeb28 | No error (0) | r.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.108577967 CET | 1.1.1.1 | 192.168.2.8 | 0xeb28 | No error (0) | r.delegate.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.108577967 CET | 1.1.1.1 | 192.168.2.8 | 0xeb28 | No error (0) | baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.108577967 CET | 1.1.1.1 | 192.168.2.8 | 0xeb28 | No error (0) | 35.169.72.125 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.108577967 CET | 1.1.1.1 | 192.168.2.8 | 0xeb28 | No error (0) | 52.71.223.223 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.108577967 CET | 1.1.1.1 | 192.168.2.8 | 0xeb28 | No error (0) | 52.71.158.82 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.124248981 CET | 1.1.1.1 | 192.168.2.8 | 0xb5a4 | No error (0) | r.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.124248981 CET | 1.1.1.1 | 192.168.2.8 | 0xb5a4 | No error (0) | r.delegate.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.124248981 CET | 1.1.1.1 | 192.168.2.8 | 0xb5a4 | No error (0) | baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.124353886 CET | 1.1.1.1 | 192.168.2.8 | 0x375a | No error (0) | r.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.124353886 CET | 1.1.1.1 | 192.168.2.8 | 0x375a | No error (0) | r.delegate.us-east-1.awstrack.me | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.124353886 CET | 1.1.1.1 | 192.168.2.8 | 0x375a | No error (0) | baconredirects-elb-1w79jy7i6g0wf-1154668140.us-east-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.669512987 CET | 1.1.1.1 | 192.168.2.8 | 0x4caf | No error (0) | 172.253.115.99 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.669512987 CET | 1.1.1.1 | 192.168.2.8 | 0x4caf | No error (0) | 172.253.115.105 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.669512987 CET | 1.1.1.1 | 192.168.2.8 | 0x4caf | No error (0) | 172.253.115.104 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.669512987 CET | 1.1.1.1 | 192.168.2.8 | 0x4caf | No error (0) | 172.253.115.106 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.669512987 CET | 1.1.1.1 | 192.168.2.8 | 0x4caf | No error (0) | 172.253.115.103 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.669512987 CET | 1.1.1.1 | 192.168.2.8 | 0x4caf | No error (0) | 172.253.115.147 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.669805050 CET | 1.1.1.1 | 192.168.2.8 | 0x302a | No error (0) | 65 | IN (0x0001) | false | |||
Jan 12, 2024 15:21:18.674695015 CET | 1.1.1.1 | 192.168.2.8 | 0x52bd | No error (0) | www.adp.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:18.676369905 CET | 1.1.1.1 | 192.168.2.8 | 0xa541 | No error (0) | www.adp.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:29.738853931 CET | 1.1.1.1 | 192.168.2.8 | 0x5fa5 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:29.738853931 CET | 1.1.1.1 | 192.168.2.8 | 0x5fa5 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:43.849261999 CET | 1.1.1.1 | 192.168.2.8 | 0xf3b4 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:21:43.849261999 CET | 1.1.1.1 | 192.168.2.8 | 0xf3b4 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:07.813688040 CET | 1.1.1.1 | 192.168.2.8 | 0x72f3 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:07.813688040 CET | 1.1.1.1 | 192.168.2.8 | 0x72f3 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:28.571427107 CET | 1.1.1.1 | 192.168.2.8 | 0x555a | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:28.571427107 CET | 1.1.1.1 | 192.168.2.8 | 0x555a | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.674963951 CET | 1.1.1.1 | 192.168.2.8 | 0x29f4 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.674963951 CET | 1.1.1.1 | 192.168.2.8 | 0x29f4 | No error (0) | 142.251.163.101 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.674963951 CET | 1.1.1.1 | 192.168.2.8 | 0x29f4 | No error (0) | 142.251.163.113 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.674963951 CET | 1.1.1.1 | 192.168.2.8 | 0x29f4 | No error (0) | 142.251.163.138 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.674963951 CET | 1.1.1.1 | 192.168.2.8 | 0x29f4 | No error (0) | 142.251.163.139 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.674963951 CET | 1.1.1.1 | 192.168.2.8 | 0x29f4 | No error (0) | 142.251.163.102 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.674963951 CET | 1.1.1.1 | 192.168.2.8 | 0x29f4 | No error (0) | 142.251.163.100 | A (IP address) | IN (0x0001) | false | ||
Jan 12, 2024 15:22:43.676050901 CET | 1.1.1.1 | 192.168.2.8 | 0x5995 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49706 | 172.253.115.84 | 443 | 6552 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-12 14:21:16 UTC | 680 | OUT | |
2024-01-12 14:21:16 UTC | 1 | OUT | |
2024-01-12 14:21:16 UTC | 1627 | IN | |
2024-01-12 14:21:16 UTC | 23 | IN | |
2024-01-12 14:21:16 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49707 | 142.251.16.113 | 443 | 6552 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-12 14:21:16 UTC | 752 | OUT | |
2024-01-12 14:21:16 UTC | 732 | IN | |
2024-01-12 14:21:16 UTC | 520 | IN | |
2024-01-12 14:21:16 UTC | 200 | IN | |
2024-01-12 14:21:16 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49712 | 35.169.72.125 | 443 | 6552 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-12 14:21:18 UTC | 806 | OUT | |
2024-01-12 14:21:18 UTC | 136 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49718 | 23.33.180.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-12 14:21:21 UTC | 161 | OUT | |
2024-01-12 14:21:21 UTC | 495 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49719 | 23.33.180.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-12 14:21:21 UTC | 239 | OUT | |
2024-01-12 14:21:21 UTC | 530 | IN | |
2024-01-12 14:21:21 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
5 | 192.168.2.8 | 49722 | 23.206.229.226 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-12 14:21:32 UTC | 2171 | OUT | |
2024-01-12 14:21:32 UTC | 1 | OUT | |
2024-01-12 14:21:32 UTC | 515 | OUT | |
2024-01-12 14:21:32 UTC | 476 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
6 | 192.168.2.8 | 49726 | 142.251.163.101 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-12 14:22:43 UTC | 449 | OUT | |
2024-01-12 14:22:44 UTC | 817 | IN | |
2024-01-12 14:22:44 UTC | 220 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 15:21:11 |
Start date: | 12/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 15:21:14 |
Start date: | 12/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 15:21:17 |
Start date: | 12/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |