Windows
Analysis Report
http://gamedot.afafb.com
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 5188 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t http://g amedot.afa fb.com/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 5568 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2088 --fi eld-trial- handle=189 2,i,839035 8284640917 908,899713 9921855909 791,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.250.105.84 | true | false | high | |
www.google.com | 142.250.9.104 | true | false | high | |
clients.l.google.com | 64.233.185.113 | true | false | high | |
shucang-gamedot-web-alb-400092662.us-east-2.elb.amazonaws.com | 3.130.203.242 | true | false | high | |
clients1.google.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high | |
gamedot.afafb.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | high | ||
false | high | ||
false | unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
64.233.185.113 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
3.130.203.242 | shucang-gamedot-web-alb-400092662.us-east-2.elb.amazonaws.com | United States | 16509 | AMAZON-02US | false | |
172.217.215.101 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.105.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.9.104 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 39.0.0 Ruby |
Analysis ID: | 1385896 |
Start date and time: | 2024-02-02 23:45:51 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | http://gamedot.afafb.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@14/10@10/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, WMIADAP.exe, SIHCl ient.exe, conhost.exe - Excluded IPs from analysis (wh
itelisted): 74.125.136.94, 34. 104.35.123, 192.229.211.108, 6 4.233.176.94 - Excluded domains from analysis
(whitelisted): ocsp.digicert. com, edgedl.me.gvt1.com, slscr .update.microsoft.com, update. googleapis.com, clientservices .googleapis.com, fe3cr.deliver y.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: http:/
/gamedot.afafb.com
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.992017198570012 |
Encrypted: | false |
SSDEEP: | 48:8qdaGT6CFjiHhidAKZdA1FehwiZUklqeh3y+3:8Y7jY8y |
MD5: | FF61A1F1B0C68C3A4A2510347252A7E9 |
SHA1: | 5D6DEDB923E1B1D2BEEE5194F9357329A276F533 |
SHA-256: | 679D2091248F84EB086792B85A7D9CD529D85C5CA31F4D0D2FE075F73DFADBE4 |
SHA-512: | 04F05EB125832C80E4081DCA7B93A9F54990FA318F0F9C697B69BC07719DD833CFC899DC9F6C9FABFE3C53E1C0656D6884B7986BE26AB84BDFD0AD3F8FFAD4C7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.008515306543397 |
Encrypted: | false |
SSDEEP: | 48:8bdaGT6CFjiHhidAKZdA1seh/iZUkAQkqehsy+2:8b7ju9Qly |
MD5: | E16D91CA363B2346A9034E57F4B0BAF4 |
SHA1: | A17F95965F704AEB2011BFCC73DF786137498E92 |
SHA-256: | EEC2C54B82DF53330228A2B193196D4F5BCA5CD71D22CEC423346FC20931DD7A |
SHA-512: | 5E2126B61E0EE98E360330299A5DD3EA4787F8BBDADC0B509E8317A745EB17F9302DBFE73E1F4AB9D331851064EF1E177068D17F62AB082AA3469EC83A9EF944 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.015295510781956 |
Encrypted: | false |
SSDEEP: | 48:82daGT6CFjAHhidAKZdA14meh7sFiZUkmgqeh7syy+BX:8c7jwngy |
MD5: | EF5C445CFCF6A373386798E902FDC126 |
SHA1: | CCDE2B2BB780E99E7C8FB6EC24C0EEB3C7FFB141 |
SHA-256: | D13EBCBC79E47C27C96696FFA60743856267F368F39377CA36079883957E107F |
SHA-512: | 3A53296E8F42C036F2A1CE5E1D0F822384B97909FC3CC03C9E35D4206AFBB70A2203093910AC02928E8D6B019BDD8752B5CFAD2A659C9C3B3C2D7668D691AB03 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.0060339917484 |
Encrypted: | false |
SSDEEP: | 48:8WdaGT6CFjiHhidAKZdA1TehDiZUkwqeh4y+R:887jFKy |
MD5: | 311907D8313E98285296FE2E4A83EFD8 |
SHA1: | C70110308175E7A616BE3E107F4743D5685179B7 |
SHA-256: | 08018D961C55B0BF463B90926C4C9B5726033ABA027DEFF77879E828610080DB |
SHA-512: | 411E3D9D142A8C30E5AFF6C6C71C68609357671C387813EF9BC9D7F1CDDAB57C0738F3746AE5D17D147540091201C3B064470DE8F05FB66953680AAC5F8F6910 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9950456770743394 |
Encrypted: | false |
SSDEEP: | 48:8FdaGT6CFjiHhidAKZdA1dehBiZUk1W1qehmy+C:897j19Gy |
MD5: | A4D6508F03297D1C2AD09FC13C8A7A06 |
SHA1: | 498ED24AAEB0AB36341584ABF26D932C23A494F0 |
SHA-256: | 50134D694C7C00A0E1C977DBA211E5B1D99EF571C55D429F8C904E96745ABD7F |
SHA-512: | 6C80CC080A03B87D9EA3C8DC6511BC17E8B3C012F435D41F3D9417B8C9E018D2D21E4EC3B79409E891C03F2F0D9DF53D45677A829A4D38FB8EACE927DAB0C552 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.005794547242781 |
Encrypted: | false |
SSDEEP: | 48:8jdaGT6CFjiHhidAKZdA1duTeehOuTbbiZUk5OjqehOuTbgy+yT+:8z7j9TfTbxWOvTbgy7T |
MD5: | BF9C3E376B686F3891E944DC74D6B649 |
SHA1: | E6C52545778B681AB4CE8BD715B52279B01B66D6 |
SHA-256: | 6FD56CFEF2D0E6DCC59FF4F696A76889DE2FDA23910EC808242FC7F0E7EAA3CF |
SHA-512: | BA93450D387DCE182BC9352362564F1B6E49487CB53C9FF5DAD079CDC15AB989D62D05859FC6EDF154C57139328CA9F865E61500A6D998023233AD45267A2BB1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 18 |
Entropy (8bit): | 3.5724312513221195 |
Encrypted: | false |
SSDEEP: | 3:uZuUeB:u5eB |
MD5: | 53AF239EE5D3E261545DEDEDCB6FFD57 |
SHA1: | 04CA7E137E1E9FEEAD96A7DF45BB67D5AB3DE190 |
SHA-256: | 99EB12F2AB3C4866A353E098FFA3CB7A967E617C49B98480394EC5D8EA92B094 |
SHA-512: | C734E4A5FF5D335A91518DBF47861BDAF8012AF49371DCD2E3350E269C9A5A1CC094114D17C4F5B053F3757B4B07487EBD0D309C91EF97ACF4665CC5D5C9A2D3 |
Malicious: | false |
Reputation: | low |
URL: | http://gamedot.afafb.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 18 |
Entropy (8bit): | 3.5724312513221195 |
Encrypted: | false |
SSDEEP: | 3:uZuUeB:u5eB |
MD5: | 53AF239EE5D3E261545DEDEDCB6FFD57 |
SHA1: | 04CA7E137E1E9FEEAD96A7DF45BB67D5AB3DE190 |
SHA-256: | 99EB12F2AB3C4866A353E098FFA3CB7A967E617C49B98480394EC5D8EA92B094 |
SHA-512: | C734E4A5FF5D335A91518DBF47861BDAF8012AF49371DCD2E3350E269C9A5A1CC094114D17C4F5B053F3757B4B07487EBD0D309C91EF97ACF4665CC5D5C9A2D3 |
Malicious: | false |
Reputation: | low |
URL: | http://gamedot.afafb.com/ |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 126
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 2, 2024 23:46:19.857292891 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:19.857498884 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:22.406693935 CET | 49722 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:22.407654047 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:22.408384085 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.408410072 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.408457994 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.409367085 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.409411907 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.409470081 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.411173105 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.411192894 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.411521912 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.411544085 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.531246901 CET | 80 | 49723 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:46:22.531327963 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:22.532033920 CET | 80 | 49722 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:46:22.532118082 CET | 49722 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:22.533103943 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:22.645710945 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.646123886 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.646140099 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.647500992 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.647569895 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.650108099 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.650201082 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.651060104 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.651071072 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.656518936 CET | 80 | 49723 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:46:22.656661987 CET | 80 | 49723 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:46:22.662306070 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.695939064 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.695992947 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.696657896 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.696758986 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.698159933 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.698226929 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.700809002 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.700902939 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.701128960 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.701148033 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.706590891 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.706595898 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:22.752161980 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:22.754607916 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.818631887 CET | 49674 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:22.818659067 CET | 49673 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:22.869640112 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.869884968 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.869973898 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.870178938 CET | 49725 | 443 | 192.168.2.16 | 64.233.185.113 |
Feb 2, 2024 23:46:22.870220900 CET | 443 | 49725 | 64.233.185.113 | 192.168.2.16 |
Feb 2, 2024 23:46:22.873899937 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.874032021 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.874085903 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.874778986 CET | 49724 | 443 | 192.168.2.16 | 142.250.105.84 |
Feb 2, 2024 23:46:22.874803066 CET | 443 | 49724 | 142.250.105.84 | 192.168.2.16 |
Feb 2, 2024 23:46:22.876269102 CET | 80 | 49723 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:46:22.926588058 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:46:23.244638920 CET | 49672 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:26.754821062 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:26.754921913 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:26.755007029 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:26.755294085 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:26.755321980 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:26.968096018 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:26.968442917 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:26.968486071 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:26.969405890 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:26.969484091 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:26.970484972 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:26.970558882 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:27.016627073 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:27.016649961 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:27.064616919 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:33.463090897 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:33.463165998 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:33.463428020 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:33.467025042 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:33.467048883 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:33.839972973 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:33.879199028 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:33.879336119 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:33.881556988 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:33.881587982 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:33.881817102 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:33.926620007 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:33.988230944 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:33.989474058 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:33.989492893 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:33.989510059 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:33.989526033 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:33.989561081 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:33.989561081 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:33.989658117 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.011544943 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.053915977 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277297020 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277318001 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277324915 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277335882 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277379036 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277391911 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.277461052 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277501106 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.277502060 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.277512074 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.277542114 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.277601957 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.299504995 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.299505949 CET | 49728 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:46:34.299546003 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.299575090 CET | 443 | 49728 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:46:34.372087002 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.520427942 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.522669077 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.522747993 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.523538113 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.523613930 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.523948908 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.524005890 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.671920061 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.671948910 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.671963930 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.671981096 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.672074080 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.672252893 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.673593044 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.719341040 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.719530106 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.719667912 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:34.719722033 CET | 49703 | 443 | 192.168.2.16 | 23.1.237.25 |
Feb 2, 2024 23:46:34.861223936 CET | 443 | 49703 | 23.1.237.25 | 192.168.2.16 |
Feb 2, 2024 23:46:36.971667051 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:36.971822977 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:46:36.971901894 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:38.474987984 CET | 49727 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:46:38.475018024 CET | 443 | 49727 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:07.545769930 CET | 49722 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:47:07.671252012 CET | 80 | 49722 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:47:07.881820917 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:47:08.005399942 CET | 80 | 49723 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:47:09.446021080 CET | 49713 | 80 | 192.168.2.16 | 72.21.81.240 |
Feb 2, 2024 23:47:09.547389984 CET | 80 | 49713 | 72.21.81.240 | 192.168.2.16 |
Feb 2, 2024 23:47:09.547472000 CET | 49713 | 80 | 192.168.2.16 | 72.21.81.240 |
Feb 2, 2024 23:47:10.769407988 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:10.769474030 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:10.769567966 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:10.770994902 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:10.771018028 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.203820944 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.203944921 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.206660986 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.206687927 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.207093954 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.209147930 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.253902912 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.601334095 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.601398945 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.601442099 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.601610899 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.601649046 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.601665974 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.601675987 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.601767063 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.601768970 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.601843119 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.608316898 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.608334064 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:11.608391047 CET | 49730 | 443 | 192.168.2.16 | 52.165.165.26 |
Feb 2, 2024 23:47:11.608397961 CET | 443 | 49730 | 52.165.165.26 | 192.168.2.16 |
Feb 2, 2024 23:47:22.657068014 CET | 80 | 49722 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:47:22.657160044 CET | 49722 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:47:22.874456882 CET | 80 | 49723 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:47:22.874680996 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:47:24.468072891 CET | 49722 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:47:24.468460083 CET | 49723 | 80 | 192.168.2.16 | 3.130.203.242 |
Feb 2, 2024 23:47:24.591655016 CET | 80 | 49723 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:47:24.593363047 CET | 80 | 49722 | 3.130.203.242 | 192.168.2.16 |
Feb 2, 2024 23:47:26.701335907 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:26.701406956 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:26.701548100 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:26.702048063 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:26.702095032 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:26.920129061 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:26.920558929 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:26.920592070 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:26.921298981 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:26.921629906 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:26.921720982 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:26.967869997 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:36.912959099 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:36.913131952 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:36.913233995 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:38.475471020 CET | 49732 | 443 | 192.168.2.16 | 142.250.9.104 |
Feb 2, 2024 23:47:38.475503922 CET | 443 | 49732 | 142.250.9.104 | 192.168.2.16 |
Feb 2, 2024 23:47:51.757972002 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.758037090 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:51.758121014 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.758440971 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.758469105 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:51.979134083 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:51.979428053 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.979458094 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:51.980736971 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:51.980829000 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.982120991 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:51.982184887 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.983155012 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.983246088 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:51.983360052 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:51.983376026 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:52.032782078 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:52.189398050 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:52.190722942 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:47:52.190926075 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:52.190975904 CET | 49733 | 443 | 192.168.2.16 | 172.217.215.101 |
Feb 2, 2024 23:47:52.191005945 CET | 443 | 49733 | 172.217.215.101 | 192.168.2.16 |
Feb 2, 2024 23:48:01.232093096 CET | 49715 | 443 | 192.168.2.16 | 23.201.212.130 |
Feb 2, 2024 23:48:01.334319115 CET | 443 | 49715 | 23.201.212.130 | 192.168.2.16 |
Feb 2, 2024 23:48:01.334368944 CET | 443 | 49715 | 23.201.212.130 | 192.168.2.16 |
Feb 2, 2024 23:48:01.334459066 CET | 49715 | 443 | 192.168.2.16 | 23.201.212.130 |
Feb 2, 2024 23:48:01.334542036 CET | 49715 | 443 | 192.168.2.16 | 23.201.212.130 |
Feb 2, 2024 23:48:01.808247089 CET | 49718 | 443 | 192.168.2.16 | 23.201.212.130 |
Feb 2, 2024 23:48:01.910444975 CET | 443 | 49718 | 23.201.212.130 | 192.168.2.16 |
Feb 2, 2024 23:48:01.910505056 CET | 443 | 49718 | 23.201.212.130 | 192.168.2.16 |
Feb 2, 2024 23:48:01.910670042 CET | 49718 | 443 | 192.168.2.16 | 23.201.212.130 |
Feb 2, 2024 23:48:01.910758972 CET | 49718 | 443 | 192.168.2.16 | 23.201.212.130 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 2, 2024 23:46:22.284621000 CET | 62934 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:22.285001993 CET | 61781 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:22.286587000 CET | 63299 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:22.286930084 CET | 53714 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:22.287599087 CET | 60559 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:22.287868977 CET | 52138 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:22.402856112 CET | 53 | 61781 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:22.402915955 CET | 53 | 62934 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:22.403053999 CET | 53 | 49547 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:22.403870106 CET | 53 | 63299 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:22.404280901 CET | 53 | 53714 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:22.404856920 CET | 53 | 52138 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:22.405038118 CET | 53 | 60559 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:23.042089939 CET | 53 | 53422 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:26.635485888 CET | 63838 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:26.635668993 CET | 61222 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:46:26.753447056 CET | 53 | 61222 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:26.753509998 CET | 53 | 63838 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:35.736716032 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Feb 2, 2024 23:46:40.037652969 CET | 53 | 55348 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:46:59.101712942 CET | 53 | 50574 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:47:21.821855068 CET | 53 | 59702 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:47:21.986862898 CET | 53 | 50931 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:47:50.064306974 CET | 53 | 57194 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:47:51.639600039 CET | 57509 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:47:51.639842033 CET | 63292 | 53 | 192.168.2.16 | 1.1.1.1 |
Feb 2, 2024 23:47:51.757080078 CET | 53 | 57509 | 1.1.1.1 | 192.168.2.16 |
Feb 2, 2024 23:47:51.757113934 CET | 53 | 63292 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Feb 2, 2024 23:46:22.284621000 CET | 192.168.2.16 | 1.1.1.1 | 0xf3e3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 2, 2024 23:46:22.285001993 CET | 192.168.2.16 | 1.1.1.1 | 0x6fae | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 2, 2024 23:46:22.286587000 CET | 192.168.2.16 | 1.1.1.1 | 0x18a2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 2, 2024 23:46:22.286930084 CET | 192.168.2.16 | 1.1.1.1 | 0xffdf | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 2, 2024 23:46:22.287599087 CET | 192.168.2.16 | 1.1.1.1 | 0x2c9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 2, 2024 23:46:22.287868977 CET | 192.168.2.16 | 1.1.1.1 | 0xbf70 | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 2, 2024 23:46:26.635485888 CET | 192.168.2.16 | 1.1.1.1 | 0x9e90 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 2, 2024 23:46:26.635668993 CET | 192.168.2.16 | 1.1.1.1 | 0x5861 | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 2, 2024 23:47:51.639600039 CET | 192.168.2.16 | 1.1.1.1 | 0x9ea3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 2, 2024 23:47:51.639842033 CET | 192.168.2.16 | 1.1.1.1 | 0x92dc | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Feb 2, 2024 23:46:22.402856112 CET | 1.1.1.1 | 192.168.2.16 | 0x6fae | No error (0) | shucang-gamedot-web-alb-400092662.us-east-2.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.402915955 CET | 1.1.1.1 | 192.168.2.16 | 0xf3e3 | No error (0) | shucang-gamedot-web-alb-400092662.us-east-2.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.402915955 CET | 1.1.1.1 | 192.168.2.16 | 0xf3e3 | No error (0) | 3.130.203.242 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.402915955 CET | 1.1.1.1 | 192.168.2.16 | 0xf3e3 | No error (0) | 3.140.70.29 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.402915955 CET | 1.1.1.1 | 192.168.2.16 | 0xf3e3 | No error (0) | 3.136.254.45 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.402915955 CET | 1.1.1.1 | 192.168.2.16 | 0xf3e3 | No error (0) | 3.13.188.55 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.403870106 CET | 1.1.1.1 | 192.168.2.16 | 0x18a2 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.403870106 CET | 1.1.1.1 | 192.168.2.16 | 0x18a2 | No error (0) | 64.233.185.113 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.403870106 CET | 1.1.1.1 | 192.168.2.16 | 0x18a2 | No error (0) | 64.233.185.139 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.403870106 CET | 1.1.1.1 | 192.168.2.16 | 0x18a2 | No error (0) | 64.233.185.138 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.403870106 CET | 1.1.1.1 | 192.168.2.16 | 0x18a2 | No error (0) | 64.233.185.102 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.403870106 CET | 1.1.1.1 | 192.168.2.16 | 0x18a2 | No error (0) | 64.233.185.101 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.403870106 CET | 1.1.1.1 | 192.168.2.16 | 0x18a2 | No error (0) | 64.233.185.100 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.404280901 CET | 1.1.1.1 | 192.168.2.16 | 0xffdf | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:22.405038118 CET | 1.1.1.1 | 192.168.2.16 | 0x2c9f | No error (0) | 142.250.105.84 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:26.753447056 CET | 1.1.1.1 | 192.168.2.16 | 0x5861 | No error (0) | 65 | IN (0x0001) | false | |||
Feb 2, 2024 23:46:26.753509998 CET | 1.1.1.1 | 192.168.2.16 | 0x9e90 | No error (0) | 142.250.9.104 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:26.753509998 CET | 1.1.1.1 | 192.168.2.16 | 0x9e90 | No error (0) | 142.250.9.99 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:26.753509998 CET | 1.1.1.1 | 192.168.2.16 | 0x9e90 | No error (0) | 142.250.9.147 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:26.753509998 CET | 1.1.1.1 | 192.168.2.16 | 0x9e90 | No error (0) | 142.250.9.106 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:26.753509998 CET | 1.1.1.1 | 192.168.2.16 | 0x9e90 | No error (0) | 142.250.9.103 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:46:26.753509998 CET | 1.1.1.1 | 192.168.2.16 | 0x9e90 | No error (0) | 142.250.9.105 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757080078 CET | 1.1.1.1 | 192.168.2.16 | 0x9ea3 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757080078 CET | 1.1.1.1 | 192.168.2.16 | 0x9ea3 | No error (0) | 172.217.215.101 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757080078 CET | 1.1.1.1 | 192.168.2.16 | 0x9ea3 | No error (0) | 172.217.215.138 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757080078 CET | 1.1.1.1 | 192.168.2.16 | 0x9ea3 | No error (0) | 172.217.215.102 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757080078 CET | 1.1.1.1 | 192.168.2.16 | 0x9ea3 | No error (0) | 172.217.215.113 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757080078 CET | 1.1.1.1 | 192.168.2.16 | 0x9ea3 | No error (0) | 172.217.215.139 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757080078 CET | 1.1.1.1 | 192.168.2.16 | 0x9ea3 | No error (0) | 172.217.215.100 | A (IP address) | IN (0x0001) | false | ||
Feb 2, 2024 23:47:51.757113934 CET | 1.1.1.1 | 192.168.2.16 | 0x92dc | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49723 | 3.130.203.242 | 80 | 5568 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 2, 2024 23:46:22.533103943 CET | 432 | OUT | |
Feb 2, 2024 23:46:22.656661987 CET | 166 | IN | |
Feb 2, 2024 23:46:22.752161980 CET | 378 | OUT | |
Feb 2, 2024 23:46:22.876269102 CET | 166 | IN | |
Feb 2, 2024 23:47:07.881820917 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49722 | 3.130.203.242 | 80 | 5568 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 2, 2024 23:47:07.545769930 CET | 6 | OUT |
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Feb 2, 2024 23:46:33.989510059 CET | 23.1.237.25 | 443 | 192.168.2.16 | 49703 | CN=r.bing.com, O=Microsoft Corporation, L=Redmond, ST=WA, C=US CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Oct 18 22:32:40 CEST 2023 Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 Fri Jun 28 01:59:59 CEST 2024 | 771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-16-23-65281,29-23-24,0 | 28a2c9bd18a11de089ef85a160da29e4 |
CN=Microsoft Azure ECC TLS Issuing CA 05, O=Microsoft Corporation, C=US | CN=DigiCert Global Root G3, OU=www.digicert.com, O=DigiCert Inc, C=US | Wed Aug 12 02:00:00 CEST 2020 | Fri Jun 28 01:59:59 CEST 2024 |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49724 | 142.250.105.84 | 443 | 5568 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-02 22:46:22 UTC | 680 | OUT | |
2024-02-02 22:46:22 UTC | 1 | OUT | |
2024-02-02 22:46:22 UTC | 1799 | IN | |
2024-02-02 22:46:22 UTC | 23 | IN | |
2024-02-02 22:46:22 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49725 | 64.233.185.113 | 443 | 5568 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-02 22:46:22 UTC | 752 | OUT | |
2024-02-02 22:46:22 UTC | 732 | IN | |
2024-02-02 22:46:22 UTC | 520 | IN | |
2024-02-02 22:46:22 UTC | 200 | IN | |
2024-02-02 22:46:22 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49728 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-02 22:46:34 UTC | 306 | OUT | |
2024-02-02 22:46:34 UTC | 560 | IN | |
2024-02-02 22:46:34 UTC | 15824 | IN | |
2024-02-02 22:46:34 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49730 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-02 22:47:11 UTC | 306 | OUT | |
2024-02-02 22:47:11 UTC | 560 | IN | |
2024-02-02 22:47:11 UTC | 15824 | IN | |
2024-02-02 22:47:11 UTC | 9633 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49733 | 172.217.215.101 | 443 | 5568 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-02 22:47:51 UTC | 449 | OUT | |
2024-02-02 22:47:52 UTC | 817 | IN | |
2024-02-02 22:47:52 UTC | 220 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 23:46:20 |
Start date: | 02/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 23:46:20 |
Start date: | 02/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e7f0000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |