Windows
Analysis Report
http://pastebin.com/raw/6p50GgCV
Overview
Detection
Score: | 21 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 7124 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 3788 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2360 --fi eld-trial- handle=233 2,i,134123 9074213578 5727,10274 3118844386 3935,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 2892 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http ://pastebi n.com/raw/ 6p50GgCV MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Networking |
---|
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Web Service | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 1 Encrypted Channel | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 3 Non-Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 4 Application Layer Protocol | Data Destruction | Virtual Private Server | Employee Names | ||
Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Scheduled Transfer | 1 Ingress Tool Transfer | Data Encrypted for Impact | Server | Gather Victim Network Information |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 172.253.63.84 | true | false | high | |
www.google.com | 142.250.65.196 | true | false | high | |
clients.l.google.com | 142.251.40.206 | true | false | high | |
pastebin.com | 172.67.34.170 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown | |
windowsupdatebg.s.llnwi.net | 69.164.46.128 | true | false | unknown | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.65.196 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.253.63.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
142.251.40.206 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
104.20.67.143 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
172.67.34.170 | pastebin.com | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.6 |
192.168.2.5 |
Joe Sandbox version: | 38.0.0 Ammolite |
Analysis ID: | 1376882 |
Start date and time: | 2024-01-18 17:04:59 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://pastebin.com/raw/6p50GgCV |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus21.troj.win@17/9@12/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe, SIHClient.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.80.35, 34. 104.35.123, 13.85.23.86, 72.21 .81.240, 69.164.46.128, 192.22 9.211.108, 13.85.23.206, 13.95 .31.18, 142.250.65.163 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, slscr.update.microsoft.com , wu.ec.azureedge.net, clients ervices.googleapis.com, ctldl. windowsupdate.com, wu-bg-shim. trafficmanager.net, wu.azureed ge.net, fe3cr.delivery.mp.micr osoft.com, fe3.delivery.mp.mic rosoft.com, edgedl.me.gvt1.com , ocsp.digicert.com, ocsp.edge .digicert.com, glb.cws.prod.dc at.dsp.trafficmanager.net, bg. apr-52dd2-0503.edgecastdns.net , cs11.wpc.v0cdn.net, sls.upda te.microsoft.com, update.googl eapis.com, hlb.apr-52dd2-0.edg ecastdns.net, glb.sls.prod.dca t.dsp.trafficmanager.net - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: http:/
/pastebin.com/raw/6p50GgCV
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9811883734582194 |
Encrypted: | false |
SSDEEP: | 48:8Ewd1Td1VAHmidAKZdA19ehwiZUklqehKy+3:8Ea/7Fy |
MD5: | 110F98F69511A6A5342E5F497F6C4F49 |
SHA1: | EAEC2D019DECA57AE679C681B6DA1252D5B28236 |
SHA-256: | F5CA4B68BC10F434AB502770895FCA26D037521C3FA1101248F4F5CF73521F71 |
SHA-512: | 44B1C29ECDDEB96167A443F660D86974D6330A05EDA9D10793EC12251A294D7B880177801403BE9142A861877496DD1DD3D59A30A14996F2B01EC4D6B40A2F17 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9966533740572388 |
Encrypted: | false |
SSDEEP: | 48:8Gwd1Td1VAHmidAKZdA1weh/iZUkAQkqeh1y+2:8Ga/J9Qoy |
MD5: | 683648F4C0BEF8A85526D76E0F824CCC |
SHA1: | D02473D0EEF35F8279FE3172E0C3F7DFA68991BD |
SHA-256: | F8D822F7A51B6CFAD710C709A6D2D64895536DD0C57288F4AC8CBD6941536842 |
SHA-512: | C28B99D6C5ACF9EDB31700A48142508AFAC88DC4761CA8A2DED36708824309202EF5120B231F4F7DC44F4BBCB99A8BAF77934153EAEFD80E86407D6E512BA0F0 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.008085454159585 |
Encrypted: | false |
SSDEEP: | 48:8xdwd1Td1sHmidAKZdA14tseh7sFiZUkmgqeh7sby+BX:8xda/rn5y |
MD5: | 6F59390283EDD92E537A5E28340EB2D9 |
SHA1: | C4AE958C0A70197A28EA30A6336EF0767C69AAC8 |
SHA-256: | 6987F37F392BB3D8D7CA31F5691C164995CA8EEAD4CEA2E45CFADC51984ABA53 |
SHA-512: | E20CE7452755A9E99C5114D859E2DA0A8E95EACB2FFCA07AA4B547150BBD24A26131032470A548D9DB2BB00945D2BBE6A21119098024EDF68A29682A573F52D7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9939464730788923 |
Encrypted: | false |
SSDEEP: | 48:8Huwd1Td1VAHmidAKZdA1vehDiZUkwqehxy+R:8Hua/Kzy |
MD5: | 76E6D641EF34DEF16B5E3A98BA9772F6 |
SHA1: | D90C703691101A8F37DC7C9B0FC59BF7EFAFC49C |
SHA-256: | C56B9CFF52871BB2CE7212FA9C78AC817E590F286D56D17208CE0480337D2714 |
SHA-512: | 61165D37E8503AF794DEEF3277F76BCFE154D80D93CACBBC9E2E72BB4A2797A19DA2EB33BA893C351DF5E970189208265866817631338A6B7651D72510F10CD5 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.982809169158391 |
Encrypted: | false |
SSDEEP: | 48:86wd1Td1VAHmidAKZdA1hehBiZUk1W1qehPy+C:86a/q9vy |
MD5: | 73494264C44E26B70C22EAB9FED80D91 |
SHA1: | 4AF5EA571AF728D4BA9D8B10E19735EF1D2ABE40 |
SHA-256: | 52FA2640F2E5F7E12BBB1410C9F87D19388AE221E2D8925237BC3635240CE196 |
SHA-512: | C101E2AE3C97D5956733DF5C673676ADBA255A4681C0CBAC14C0EC08E23BDE467A94A885011B4DEE58B82B5042FCC76195596A1C96AEA4456166E9230A1F0B75 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.994641823195066 |
Encrypted: | false |
SSDEEP: | 48:8ywd1Td1VAHmidAKZdA1duT+ehOuTbbiZUk5OjqehOuTb5y+yT+:8ya/0T/TbxWOvTb5y7T |
MD5: | 6AE07AFFD0D7397520D8355E34D4BE34 |
SHA1: | EE9FF35EACB6A8BCB5FCA632DE81D3816BC38E3A |
SHA-256: | C754D765CE5F5415B45CD7EEB1938A519037719267B6BB8E7510AC783BA802FA |
SHA-512: | DD42786F4FD3C4347ECB232C9283F5F17E9241B5F1E2CB7E8496911049D367C42CFBF3A8C09E002F12B28AA130EDC8F4C42A6E9E876FF988D1367A4D1A8D16B2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 318 |
Entropy (8bit): | 3.8981821278788122 |
Encrypted: | false |
SSDEEP: | 6:8zE/6yXJr3lDyYtLv7Ydi+633+6/ADcWN/Qtmy/s:8w/6yXhVRQk3333/a/wmCs |
MD5: | DE86A6F000F8F84E20BC7EB2C7D320E3 |
SHA1: | 35AF87DEEF9E6C081D834D08963ADA2530DC0618 |
SHA-256: | 6A5E064AF00286681A3AE734E5407A2EA883955D875C5490E597D1DDB8EDA021 |
SHA-512: | E06A8F3101E1CAD5BB965A8543FFF987A2E22F8ED1FD9ABA00C86BB937118F75B280BCFB1C6649F5EC96D6182582AA64A346E7DD7637C0F73A26F79B3A3AEE96 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 318 |
Entropy (8bit): | 3.8981821278788122 |
Encrypted: | false |
SSDEEP: | 6:8zE/6yXJr3lDyYtLv7Ydi+633+6/ADcWN/Qtmy/s:8w/6yXhVRQk3333/a/wmCs |
MD5: | DE86A6F000F8F84E20BC7EB2C7D320E3 |
SHA1: | 35AF87DEEF9E6C081D834D08963ADA2530DC0618 |
SHA-256: | 6A5E064AF00286681A3AE734E5407A2EA883955D875C5490E597D1DDB8EDA021 |
SHA-512: | E06A8F3101E1CAD5BB965A8543FFF987A2E22F8ED1FD9ABA00C86BB937118F75B280BCFB1C6649F5EC96D6182582AA64A346E7DD7637C0F73A26F79B3A3AEE96 |
Malicious: | false |
Reputation: | low |
URL: | https://pastebin.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 520 |
Entropy (8bit): | 4.444885117965303 |
Encrypted: | false |
SSDEEP: | 12:DyTyJEaR7yUFunUzO8L0wXgeuyy+tm8z2f8HxjG9qGn:DbJEJPnUzO8ZuyF92ejg |
MD5: | 41878195D6629F2C954C6861CBC195D4 |
SHA1: | FFEABF7C83E9B0CDFBD718117086FFDD08D399A5 |
SHA-256: | B05A48CE20B351A527BFFD7410A7C267EB617BEB8F4BBBB989F8AA439E166EAA |
SHA-512: | F55ED65DC9710B5378925EC43CEC3EDD067D544C72A0C414295C71EC2C339F7479EC788ECE71ADA77E24C31A205C4F4F936E3E3542C8DDADAC6B4A56C161B83D |
Malicious: | false |
Reputation: | low |
URL: | https://pastebin.com/raw/6p50GgCV |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 118
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 18, 2024 17:05:46.491389990 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:05:46.491393089 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:05:46.590471983 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:05:52.186264038 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.186307907 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.186364889 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.186693907 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.186717033 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.187880039 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.187968016 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.188030958 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.188297987 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.188333035 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.391199112 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.391458035 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.391499043 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.393588066 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.393682957 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.394716024 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.394809961 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.394911051 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.394927979 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.461383104 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.461937904 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.461954117 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.462409019 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.462480068 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.463146925 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.463202000 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.464396000 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.464473963 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.464620113 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.464627028 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.524008036 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.555006027 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.623848915 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.624238014 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.624399900 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.625081062 CET | 49706 | 443 | 192.168.2.5 | 172.253.63.84 |
Jan 18, 2024 17:05:52.625113964 CET | 443 | 49706 | 172.253.63.84 | 192.168.2.5 |
Jan 18, 2024 17:05:52.741873980 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.742053986 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:52.742104053 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.742603064 CET | 49705 | 443 | 192.168.2.5 | 142.251.40.206 |
Jan 18, 2024 17:05:52.742624044 CET | 443 | 49705 | 142.251.40.206 | 192.168.2.5 |
Jan 18, 2024 17:05:53.843291998 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:53.843374014 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:53.843467951 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:53.843863964 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:53.843903065 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.033384085 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.033704042 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.033750057 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.035217047 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.036025047 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.036252022 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.036344051 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.036514044 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.036530972 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.077136040 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.726845026 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.726977110 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.727054119 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.745102882 CET | 49709 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.745141029 CET | 443 | 49709 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.848392010 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.848437071 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.848498106 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.848999023 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:54.849020004 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:54.897948027 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:54.897996902 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:05:54.898065090 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:54.898396969 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:54.898413897 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:05:55.036031961 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.036345005 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:55.036375046 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.036840916 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.037167072 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:55.037251949 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.037297964 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:55.077908039 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.086711884 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:55.105288982 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:05:55.120264053 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:55.120315075 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:05:55.124216080 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:05:55.124319077 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:55.125674009 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:55.125777960 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:05:55.180514097 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:55.180529118 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:05:55.227375984 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:05:55.266104937 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.266192913 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.266253948 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:55.267086983 CET | 49712 | 443 | 192.168.2.5 | 172.67.34.170 |
Jan 18, 2024 17:05:55.267112970 CET | 443 | 49712 | 172.67.34.170 | 192.168.2.5 |
Jan 18, 2024 17:05:55.376879930 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.376957893 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.377046108 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.377290010 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.377325058 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.563183069 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.563699961 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.563761950 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.565239906 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.565455914 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.566212893 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.566315889 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.566566944 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.566596031 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.617779016 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.788808107 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.788974047 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:55.789167881 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.826826096 CET | 49714 | 443 | 192.168.2.5 | 104.20.67.143 |
Jan 18, 2024 17:05:55.826848984 CET | 443 | 49714 | 104.20.67.143 | 192.168.2.5 |
Jan 18, 2024 17:05:56.101861000 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:05:56.101877928 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:05:56.195645094 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:05:56.900408983 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:56.900460005 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:56.900525093 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:56.930737972 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:56.930767059 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.129970074 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.130131960 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.135957956 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.135967970 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.136390924 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.179986954 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.362656116 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.405920982 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.452963114 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.453046083 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.453188896 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.453188896 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.453217030 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.453299999 CET | 49716 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.453309059 CET | 443 | 49716 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.504479885 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.504559040 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.504656076 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.505479097 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.505558014 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.635684013 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:05:57.635915041 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:05:57.692728043 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.692918062 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.694910049 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.694962025 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.695322037 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.696990967 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.741905928 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.868705034 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.868819952 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.868902922 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.901782990 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.901782990 CET | 49718 | 443 | 192.168.2.5 | 23.51.58.94 |
Jan 18, 2024 17:05:57.901797056 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:05:57.901808977 CET | 443 | 49718 | 23.51.58.94 | 192.168.2.5 |
Jan 18, 2024 17:06:05.133140087 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:05.133311987 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:05.133380890 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:06:06.244720936 CET | 49713 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:06:06.244791985 CET | 443 | 49713 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:07.884069920 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:07.885226011 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:07.885741949 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:07.885775089 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:07.885914087 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:07.886857033 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:07.886876106 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.036772013 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.037822962 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.206996918 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.207073927 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:08.238308907 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:08.238329887 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.238800049 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.238861084 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:08.239276886 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:08.239314079 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.239684105 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:08.239694118 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.556763887 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.556823969 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:08.557060003 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.557145119 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Jan 18, 2024 17:06:08.557189941 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 18, 2024 17:06:54.858366966 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:06:54.858397961 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:54.858474970 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:06:54.859038115 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:06:54.859051943 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:55.052700043 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:55.053369999 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:06:55.053390026 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:55.053844929 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:55.054445982 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:06:55.054526091 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:06:55.101830959 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:07:05.049951077 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:07:05.050044060 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Jan 18, 2024 17:07:05.050098896 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:07:06.464159966 CET | 49729 | 443 | 192.168.2.5 | 142.250.65.196 |
Jan 18, 2024 17:07:06.464179039 CET | 443 | 49729 | 142.250.65.196 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 18, 2024 17:05:52.097882986 CET | 62946 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:52.098087072 CET | 64435 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:52.098794937 CET | 52055 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:52.099098921 CET | 62265 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:52.141788006 CET | 53 | 60417 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:52.185411930 CET | 53 | 64435 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:52.185717106 CET | 53 | 62946 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:52.187228918 CET | 53 | 52055 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:52.187249899 CET | 53 | 62265 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:52.878108978 CET | 53 | 56924 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:53.651808023 CET | 64207 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:53.654309988 CET | 49926 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:53.739931107 CET | 53 | 64207 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:53.744265079 CET | 53 | 49926 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:53.752218962 CET | 62746 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:53.752490044 CET | 50787 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:53.841844082 CET | 53 | 62746 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:53.842623949 CET | 53 | 50787 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:54.807656050 CET | 60129 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:54.808120966 CET | 60782 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:54.896393061 CET | 53 | 60782 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:54.897178888 CET | 53 | 60129 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:55.271394968 CET | 53588 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:55.271653891 CET | 61067 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 18, 2024 17:05:55.360034943 CET | 53 | 53588 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:05:55.361917973 CET | 53 | 61067 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:06:10.026987076 CET | 53 | 56437 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:06:28.986875057 CET | 53 | 54573 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:06:51.365449905 CET | 53 | 64329 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:06:51.615798950 CET | 53 | 56336 | 1.1.1.1 | 192.168.2.5 |
Jan 18, 2024 17:07:19.519974947 CET | 53 | 60855 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 18, 2024 17:05:52.097882986 CET | 192.168.2.5 | 1.1.1.1 | 0x2c7b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2024 17:05:52.098087072 CET | 192.168.2.5 | 1.1.1.1 | 0x1a8 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 18, 2024 17:05:52.098794937 CET | 192.168.2.5 | 1.1.1.1 | 0x5a77 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2024 17:05:52.099098921 CET | 192.168.2.5 | 1.1.1.1 | 0x946d | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 18, 2024 17:05:53.651808023 CET | 192.168.2.5 | 1.1.1.1 | 0x8b83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2024 17:05:53.654309988 CET | 192.168.2.5 | 1.1.1.1 | 0x79c7 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 18, 2024 17:05:53.752218962 CET | 192.168.2.5 | 1.1.1.1 | 0xdafc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2024 17:05:53.752490044 CET | 192.168.2.5 | 1.1.1.1 | 0x568e | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 18, 2024 17:05:54.807656050 CET | 192.168.2.5 | 1.1.1.1 | 0xd183 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2024 17:05:54.808120966 CET | 192.168.2.5 | 1.1.1.1 | 0x8d94 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 18, 2024 17:05:55.271394968 CET | 192.168.2.5 | 1.1.1.1 | 0x9816 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 18, 2024 17:05:55.271653891 CET | 192.168.2.5 | 1.1.1.1 | 0x80a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 18, 2024 17:05:52.185411930 CET | 1.1.1.1 | 192.168.2.5 | 0x1a8 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:52.185717106 CET | 1.1.1.1 | 192.168.2.5 | 0x2c7b | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:52.185717106 CET | 1.1.1.1 | 192.168.2.5 | 0x2c7b | No error (0) | 142.251.40.206 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:52.187228918 CET | 1.1.1.1 | 192.168.2.5 | 0x5a77 | No error (0) | 172.253.63.84 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:53.739931107 CET | 1.1.1.1 | 192.168.2.5 | 0x8b83 | No error (0) | 172.67.34.170 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:53.739931107 CET | 1.1.1.1 | 192.168.2.5 | 0x8b83 | No error (0) | 104.20.67.143 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:53.739931107 CET | 1.1.1.1 | 192.168.2.5 | 0x8b83 | No error (0) | 104.20.68.143 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:53.744265079 CET | 1.1.1.1 | 192.168.2.5 | 0x79c7 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 18, 2024 17:05:53.841844082 CET | 1.1.1.1 | 192.168.2.5 | 0xdafc | No error (0) | 172.67.34.170 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:53.841844082 CET | 1.1.1.1 | 192.168.2.5 | 0xdafc | No error (0) | 104.20.68.143 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:53.841844082 CET | 1.1.1.1 | 192.168.2.5 | 0xdafc | No error (0) | 104.20.67.143 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:53.842623949 CET | 1.1.1.1 | 192.168.2.5 | 0x568e | No error (0) | 65 | IN (0x0001) | false | |||
Jan 18, 2024 17:05:54.896393061 CET | 1.1.1.1 | 192.168.2.5 | 0x8d94 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 18, 2024 17:05:54.897178888 CET | 1.1.1.1 | 192.168.2.5 | 0xd183 | No error (0) | 142.250.65.196 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:55.360034943 CET | 1.1.1.1 | 192.168.2.5 | 0x9816 | No error (0) | 104.20.67.143 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:55.360034943 CET | 1.1.1.1 | 192.168.2.5 | 0x9816 | No error (0) | 172.67.34.170 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:55.360034943 CET | 1.1.1.1 | 192.168.2.5 | 0x9816 | No error (0) | 104.20.68.143 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:05:55.361917973 CET | 1.1.1.1 | 192.168.2.5 | 0x80a | No error (0) | 65 | IN (0x0001) | false | |||
Jan 18, 2024 17:06:07.234884024 CET | 1.1.1.1 | 192.168.2.5 | 0xb11c | No error (0) | 69.164.46.128 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:06:07.553719997 CET | 1.1.1.1 | 192.168.2.5 | 0xdc0 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2024 17:06:07.553719997 CET | 1.1.1.1 | 192.168.2.5 | 0xdc0 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:06:20.475281000 CET | 1.1.1.1 | 192.168.2.5 | 0x7ae2 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2024 17:06:20.475281000 CET | 1.1.1.1 | 192.168.2.5 | 0x7ae2 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:06:44.067569017 CET | 1.1.1.1 | 192.168.2.5 | 0x4742 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2024 17:06:44.067569017 CET | 1.1.1.1 | 192.168.2.5 | 0x4742 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Jan 18, 2024 17:07:04.303438902 CET | 1.1.1.1 | 192.168.2.5 | 0xd38 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 18, 2024 17:07:04.303438902 CET | 1.1.1.1 | 192.168.2.5 | 0xd38 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49706 | 172.253.63.84 | 443 | 3788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:05:52 UTC | 680 | OUT | |
2024-01-18 16:05:52 UTC | 1 | OUT | |
2024-01-18 16:05:52 UTC | 1627 | IN | |
2024-01-18 16:05:52 UTC | 23 | IN | |
2024-01-18 16:05:52 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49705 | 142.251.40.206 | 443 | 3788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:05:52 UTC | 752 | OUT | |
2024-01-18 16:05:52 UTC | 732 | IN | |
2024-01-18 16:05:52 UTC | 520 | IN | |
2024-01-18 16:05:52 UTC | 200 | IN | |
2024-01-18 16:05:52 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49709 | 172.67.34.170 | 443 | 3788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:05:54 UTC | 667 | OUT | |
2024-01-18 16:05:54 UTC | 420 | IN | |
2024-01-18 16:05:54 UTC | 527 | IN | |
2024-01-18 16:05:54 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49712 | 172.67.34.170 | 443 | 3788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:05:55 UTC | 592 | OUT | |
2024-01-18 16:05:55 UTC | 330 | IN | |
2024-01-18 16:05:55 UTC | 318 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49714 | 104.20.67.143 | 443 | 3788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:05:55 UTC | 347 | OUT | |
2024-01-18 16:05:55 UTC | 330 | IN | |
2024-01-18 16:05:55 UTC | 318 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49716 | 23.51.58.94 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:05:57 UTC | 161 | OUT | |
2024-01-18 16:05:57 UTC | 494 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49718 | 23.51.58.94 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:05:57 UTC | 239 | OUT | |
2024-01-18 16:05:57 UTC | 455 | IN | |
2024-01-18 16:05:57 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
7 | 192.168.2.5 | 49725 | 23.1.237.91 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-01-18 16:06:08 UTC | 2148 | OUT | |
2024-01-18 16:06:08 UTC | 1 | OUT | |
2024-01-18 16:06:08 UTC | 2482 | OUT | |
2024-01-18 16:06:08 UTC | 475 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 17:05:45 |
Start date: | 18/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 17:05:49 |
Start date: | 18/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 17:05:52 |
Start date: | 18/01/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |