Windows
Analysis Report
https://link.mail.beehiiv.com/ls/click?upn=fBLT-2BLuQl3NwiQlY-2FUB-2F7yZK63rzVbOt6SRjyVrBIqFzFDo8M-2Fg4Bo4-2BO4hpom8z7ZLuxy2QxlYMgW1Gzy6pwCm23aez0vVyhBm7eCGwE0WdMbo1BXh-2BFRtbcaklbKh26FDy0n-2FdQ9t7RCwaH39WupxeBlLns-2FCYgl5f1ctJEhM-3DLmFo_AmeWD5ZsKC-2B3ZheZjnDpbUkAKgKl5WpTuOJCpyDqXRc8K-2FlFlJ4-2Bn1zD
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 5764 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 1800 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2528 --fi eld-trial- handle=249 2,i,507010 1363910953 062,990078 2759702370 279,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6544 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://link.m ail.beehii v.com/ls/c lick?upn=f BLT-2BLuQl 3NwiQlY-2F UB-2F7yZK6 3rzVbOt6SR jyVrBIqFzF Do8M-2Fg4B o4-2BO4hpo m8z7ZLuxy2 QxlYMgW1Gz y6pwCm23ae z0vVyhBm7e CGwE0WdMbo 1BXh-2BFRt bcaklbKh26 FDy0n-2FdQ 9t7RCwaH39 WupxeBlLns -2FCYgl5f1 ctJEhM-3DL mFo_AmeWD5 ZsKC-2B3Zh eZjnDpbUkA KgKl5WpTuO JCpyDqXRc8 K-2FlFlJ4- 2Bn1zDfmQE 1bOIB5-2Bm aBYS52bqAM uImdaBWt-2 B7NcvDjHLS jDEqun4F40 VGOju6f5er aMm-2BmA2c I4TwN5m-2F dXmsuh3AvB 8I3hqCf5Su 72C52AB82b XT78OFaGhL dykrKPYdzA mNePbUMkJf eZ1o1xXkpY 533PpjggEu fwqS96U2lH FtuM0AF0Xz njCWvz2-2F AJxdv2yOU4 Rja8sE1aVz AzUItssHkU W9tujzTKsH ooxa0T1wqU -2BXsNw6IZ YMBuNd2XQD 3BPavL2FyK wgqOl-2BNl CpAsuRQyxx qbQ0sxmCsv EzI2nw166v YROKCjGmPP QtR1NyNiLp j317EtiqLr lvsktdS8N6 bgTfK0t-2F A2HLcAR1cl K9xdGWlVko BfmmnRGIBb oAePQ8ToZa gwj4auB1Pm TKZ9aQMtFd h-2FNJV17V PUH2ibgU2d 8MV21fLKU- 3D#/?/#/?/ bfariss@on edigital.c om MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | SlashNext: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Sample URL: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
3% | Virustotal | Browse | ||
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
1% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing | ||
1% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
3% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
95mc5.zal0.com | 104.21.42.31 | true | false |
| unknown |
djdhde.mypi.co | 23.237.26.135 | true | false | unknown | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
accounts.google.com | 173.194.219.84 | true | false | high | |
link.mail.beehiiv.com | 104.18.68.40 | true | false |
| unknown |
www.google.com | 74.125.138.99 | true | false | high | |
clients.l.google.com | 142.250.105.138 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false |
| unknown |
windowsupdatebg.s.llnwi.net | 69.164.42.0 | true | false |
| unknown |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | high | ||
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.42.31 | 95mc5.zal0.com | United States | 13335 | CLOUDFLARENETUS | false | |
74.125.138.99 | www.google.com | United States | 15169 | GOOGLEUS | false | |
23.237.26.135 | djdhde.mypi.co | United States | 174 | COGENT-174US | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
104.18.68.40 | link.mail.beehiiv.com | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.105.138 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
173.194.219.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1388791 |
Start date and time: | 2024-02-08 04:11:21 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://link.mail.beehiiv.com/ls/click?upn=fBLT-2BLuQl3NwiQlY-2FUB-2F7yZK63rzVbOt6SRjyVrBIqFzFDo8M-2Fg4Bo4-2BO4hpom8z7ZLuxy2QxlYMgW1Gzy6pwCm23aez0vVyhBm7eCGwE0WdMbo1BXh-2BFRtbcaklbKh26FDy0n-2FdQ9t7RCwaH39WupxeBlLns-2FCYgl5f1ctJEhM-3DLmFo_AmeWD5ZsKC-2B3ZheZjnDpbUkAKgKl5WpTuOJCpyDqXRc8K-2FlFlJ4-2Bn1zDfmQE1bOIB5-2BmaBYS52bqAMuImdaBWt-2B7NcvDjHLSjDEqun4F40VGOju6f5eraMm-2BmA2cI4TwN5m-2FdXmsuh3AvB8I3hqCf5Su72C52AB82bXT78OFaGhLdykrKPYdzAmNePbUMkJfeZ1o1xXkpY533PpjggEufwqS96U2lHFtuM0AF0XznjCWvz2-2FAJxdv2yOU4Rja8sE1aVzAzUItssHkUW9tujzTKsHooxa0T1wqU-2BXsNw6IZYMBuNd2XQD3BPavL2FyKwgqOl-2BNlCpAsuRQyxxqbQ0sxmCsvEzI2nw166vYROKCjGmPPQtR1NyNiLpj317EtiqLrlvsktdS8N6bgTfK0t-2FA2HLcAR1clK9xdGWlVkoBfmmnRGIBboAePQ8ToZagwj4auB1PmTKZ9aQMtFdh-2FNJV17VPUH2ibgU2d8MV21fLKU-3D#/?/#/?/bfariss@onedigital.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@19/2@14/9 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 74.125.138.94, 34.104.35.123, 20.12.23.50, 69.164.42.0, 192.229.211.108, 20.3.187.198, 20.166.126.56, 13.85.23.86, 64.233.177.94, 52.165.165.26
- Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtSetInformationFile calls found.
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 232 |
Entropy (8bit): | 4.979386507392717 |
Encrypted: | false |
SSDEEP: | 6:OK7XnfIuPxm9/UAY8SYfmFr7VddQezMcGh:OEfIuZY/Ur8hfQr7VbHzMbh |
MD5: | DB43D1E8377836DCC645F300AC0C490F |
SHA1: | 9694476AA14218476EDC612069E060DCFDD87657 |
SHA-256: | 9A97CD4AA6A50586ECEB5D58FCBE19E163FA61BE60AA5D65C472C70227E8FB54 |
SHA-512: | F138AEA35636B83E3F967227F46DD570F359E23487B889F5FD8F1DA027FC5E08C4AE267E5FFD6DD922A0D069B0C359061007EAF38E84F71478FA4D95ECE4ADF3 |
Malicious: | false |
Reputation: | low |
URL: | https://djdhde.mypi.co/sss/?utm_source=capils-newsletter.beehiiv.com&utm_medium=newsletter&utm_campaign=new-post |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 8, 2024 04:12:04.103586912 CET | 49678 | 443 | 192.168.2.4 | 104.46.162.224 |
Feb 8, 2024 04:12:05.119160891 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Feb 8, 2024 04:12:09.621867895 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.621953964 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.622057915 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.622698069 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.622733116 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.623259068 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.623342991 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.623421907 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.624066114 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.624100924 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.840646029 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.840934992 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.840945959 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.841334105 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.841389894 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.842293024 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.842339993 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.843339920 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.843499899 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.843560934 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.843717098 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.843750000 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.843940020 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.843946934 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:09.845195055 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.845256090 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.846260071 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.846349001 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.846416950 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.883697987 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:09.893906116 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.899439096 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:09.899494886 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:09.946316957 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:10.051759958 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:10.052129984 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:10.052189112 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:10.052453041 CET | 49730 | 443 | 192.168.2.4 | 142.250.105.138 |
Feb 8, 2024 04:12:10.052465916 CET | 443 | 49730 | 142.250.105.138 | 192.168.2.4 |
Feb 8, 2024 04:12:10.079988956 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:10.080061913 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:10.080118895 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:10.080734015 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:10.080908060 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:10.099354029 CET | 49731 | 443 | 192.168.2.4 | 173.194.219.84 |
Feb 8, 2024 04:12:10.099416971 CET | 443 | 49731 | 173.194.219.84 | 192.168.2.4 |
Feb 8, 2024 04:12:10.991323948 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:10.991384029 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:10.991456032 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:10.992276907 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:10.992346048 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:10.992415905 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:10.994038105 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:10.994066954 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:10.994525909 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:10.994568110 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.237373114 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.237822056 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.237852097 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.238656044 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.238862038 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.238890886 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.238950968 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.239021063 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.239777088 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.239839077 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.240250111 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.240315914 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.240358114 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.240420103 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.240571976 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.240586042 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.279725075 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.279745102 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.295248985 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.325640917 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.558682919 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.558824062 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.559020042 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.564774990 CET | 49734 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:11.564800024 CET | 443 | 49734 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:11.984720945 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:11.984755039 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:11.984833002 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:11.985238075 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:11.985250950 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.283696890 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.283984900 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.284007072 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.284950018 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.285034895 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.285998106 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.286129951 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.286396980 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.286401987 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.336169004 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.564888000 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.565278053 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.565361977 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.565840960 CET | 49738 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.565862894 CET | 443 | 49738 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.571787119 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.571834087 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.571901083 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.574157953 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.574176073 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.874597073 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.874999046 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.875025988 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.875771046 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.876693964 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.876777887 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:12.877090931 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:12.921900034 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:13.170092106 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:13.170166016 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:13.170209885 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:13.192379951 CET | 49739 | 443 | 192.168.2.4 | 23.237.26.135 |
Feb 8, 2024 04:12:13.192397118 CET | 443 | 49739 | 23.237.26.135 | 192.168.2.4 |
Feb 8, 2024 04:12:13.874396086 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:13.874480009 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:13.874563932 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:13.875902891 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:13.875992060 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:13.876079082 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:13.876540899 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:13.876578093 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:13.877007008 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:13.877043009 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:13.968333006 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:13.968380928 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:13.968444109 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:13.969075918 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:13.969105959 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:14.158412933 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.158834934 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.158894062 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.159341097 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.160358906 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.160623074 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.161722898 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.161782980 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.162029982 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.162117958 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.162724972 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.162766933 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.162838936 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.164424896 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.164505005 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.201024055 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:14.201754093 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:14.201771021 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:14.202825069 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:14.202909946 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:14.204324007 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:14.204389095 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:14.205946922 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.215626001 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.215661049 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.215730906 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.215785027 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.240837097 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.240873098 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.241000891 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.243120909 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.243138075 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.244483948 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:14.244524002 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:14.259903908 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.260001898 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.290340900 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:14.487293005 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.490988016 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.496977091 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.496984005 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.497633934 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.548100948 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.671595097 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.713901043 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.732402086 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Feb 8, 2024 04:12:14.790858030 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.790971994 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.791027069 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.791059017 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.791090012 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.791098118 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.791148901 CET | 49743 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.791153908 CET | 443 | 49743 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.832453966 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.832489014 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.832809925 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.832809925 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:14.832848072 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:14.902180910 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.902256012 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:14.903300047 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:14.903301001 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:15.075807095 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.075916052 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:15.076972008 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:15.076980114 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.077305079 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.078596115 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:15.121912956 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.209304094 CET | 49741 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:15.209367990 CET | 443 | 49741 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:15.233856916 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.233937025 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.234018087 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.234988928 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.235028982 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.321034908 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.321122885 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.321177006 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:15.322710037 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:15.322725058 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.322740078 CET | 49744 | 443 | 192.168.2.4 | 23.36.173.151 |
Feb 8, 2024 04:12:15.322746992 CET | 443 | 49744 | 23.36.173.151 | 192.168.2.4 |
Feb 8, 2024 04:12:15.456152916 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.456617117 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.456674099 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.458354950 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.458436012 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.465311050 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.465405941 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.465972900 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.465991974 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.509691000 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.681377888 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.681473017 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.681546926 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.681642056 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.681680918 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.682286024 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.682306051 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.682358027 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.683443069 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.683455944 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.895258904 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.907594919 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.907605886 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.907929897 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.908838034 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.908899069 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.909315109 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:15.949903011 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:16.127616882 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:16.127795935 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:16.127867937 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:16.128238916 CET | 49746 | 443 | 192.168.2.4 | 35.190.80.1 |
Feb 8, 2024 04:12:16.128247023 CET | 443 | 49746 | 35.190.80.1 | 192.168.2.4 |
Feb 8, 2024 04:12:24.183794975 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:24.183851957 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:24.183940887 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:25.622462034 CET | 49742 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:12:25.622489929 CET | 443 | 49742 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:12:26.231906891 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:26.231976986 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:26.232070923 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:27.457456112 CET | 49735 | 443 | 192.168.2.4 | 104.18.68.40 |
Feb 8, 2024 04:12:27.457518101 CET | 443 | 49735 | 104.18.68.40 | 192.168.2.4 |
Feb 8, 2024 04:12:29.136358976 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:29.136421919 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:12:29.136619091 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:29.620898008 CET | 49740 | 443 | 192.168.2.4 | 104.21.42.31 |
Feb 8, 2024 04:12:29.620974064 CET | 443 | 49740 | 104.21.42.31 | 192.168.2.4 |
Feb 8, 2024 04:13:14.109700918 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:14.109787941 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:14.109877110 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:14.110059977 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:14.110080957 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:14.324820042 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:14.326495886 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:14.326553106 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:14.327032089 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:14.331355095 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:14.331444025 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:14.386006117 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:23.055905104 CET | 49723 | 80 | 192.168.2.4 | 23.43.243.112 |
Feb 8, 2024 04:13:23.239734888 CET | 80 | 49723 | 23.43.243.112 | 192.168.2.4 |
Feb 8, 2024 04:13:23.239859104 CET | 49723 | 80 | 192.168.2.4 | 23.43.243.112 |
Feb 8, 2024 04:13:24.331103086 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:24.331163883 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Feb 8, 2024 04:13:24.331257105 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:25.619935036 CET | 49755 | 443 | 192.168.2.4 | 74.125.138.99 |
Feb 8, 2024 04:13:25.619968891 CET | 443 | 49755 | 74.125.138.99 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 8, 2024 04:12:09.443917036 CET | 53 | 53208 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:09.502916098 CET | 64034 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:09.503159046 CET | 50621 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:09.504596949 CET | 56766 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:09.504837990 CET | 56582 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:09.620517015 CET | 53 | 64034 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:09.620563030 CET | 53 | 50621 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:09.621932983 CET | 53 | 56582 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:09.622057915 CET | 53 | 56766 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:10.231784105 CET | 53 | 54975 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:10.871884108 CET | 61893 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:10.872450113 CET | 60324 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:10.989728928 CET | 53 | 61893 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:10.990703106 CET | 53 | 60324 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:11.568206072 CET | 65394 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:11.568595886 CET | 64303 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:11.917548895 CET | 53 | 65394 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:12.165251970 CET | 53 | 64303 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:13.724823952 CET | 54415 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:13.725169897 CET | 56065 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:13.843189955 CET | 56009 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:13.843734980 CET | 51277 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:13.868684053 CET | 53 | 54415 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:13.873287916 CET | 53 | 56065 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:13.963557005 CET | 53 | 56009 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:13.965178013 CET | 53 | 51277 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.107882977 CET | 64456 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:15.108241081 CET | 60747 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 8, 2024 04:12:15.225311995 CET | 53 | 64456 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:15.225589037 CET | 53 | 60747 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:27.576915026 CET | 53 | 54439 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:12:34.626610994 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Feb 8, 2024 04:12:46.659281969 CET | 53 | 51905 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:13:09.286067963 CET | 53 | 51545 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:13:09.518475056 CET | 53 | 62854 | 1.1.1.1 | 192.168.2.4 |
Feb 8, 2024 04:13:37.299674034 CET | 53 | 56897 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Feb 8, 2024 04:12:12.165488958 CET | 192.168.2.4 | 1.1.1.1 | c221 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Feb 8, 2024 04:12:09.502916098 CET | 192.168.2.4 | 1.1.1.1 | 0xbae4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 8, 2024 04:12:09.503159046 CET | 192.168.2.4 | 1.1.1.1 | 0x132a | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 8, 2024 04:12:09.504596949 CET | 192.168.2.4 | 1.1.1.1 | 0x2d3d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 8, 2024 04:12:09.504837990 CET | 192.168.2.4 | 1.1.1.1 | 0x6138 | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 8, 2024 04:12:10.871884108 CET | 192.168.2.4 | 1.1.1.1 | 0xa0d4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 8, 2024 04:12:10.872450113 CET | 192.168.2.4 | 1.1.1.1 | 0xe84d | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 8, 2024 04:12:11.568206072 CET | 192.168.2.4 | 1.1.1.1 | 0xb2d1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 8, 2024 04:12:11.568595886 CET | 192.168.2.4 | 1.1.1.1 | 0xbccf | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 8, 2024 04:12:13.724823952 CET | 192.168.2.4 | 1.1.1.1 | 0xaa1b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 8, 2024 04:12:13.725169897 CET | 192.168.2.4 | 1.1.1.1 | 0x14ad | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 8, 2024 04:12:13.843189955 CET | 192.168.2.4 | 1.1.1.1 | 0x53a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 8, 2024 04:12:13.843734980 CET | 192.168.2.4 | 1.1.1.1 | 0x2c36 | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 8, 2024 04:12:15.107882977 CET | 192.168.2.4 | 1.1.1.1 | 0x5098 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 8, 2024 04:12:15.108241081 CET | 192.168.2.4 | 1.1.1.1 | 0xe770 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Feb 8, 2024 04:12:09.620517015 CET | 1.1.1.1 | 192.168.2.4 | 0xbae4 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.620517015 CET | 1.1.1.1 | 192.168.2.4 | 0xbae4 | No error (0) | 142.250.105.138 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.620517015 CET | 1.1.1.1 | 192.168.2.4 | 0xbae4 | No error (0) | 142.250.105.113 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.620517015 CET | 1.1.1.1 | 192.168.2.4 | 0xbae4 | No error (0) | 142.250.105.101 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.620517015 CET | 1.1.1.1 | 192.168.2.4 | 0xbae4 | No error (0) | 142.250.105.100 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.620517015 CET | 1.1.1.1 | 192.168.2.4 | 0xbae4 | No error (0) | 142.250.105.139 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.620517015 CET | 1.1.1.1 | 192.168.2.4 | 0xbae4 | No error (0) | 142.250.105.102 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.620563030 CET | 1.1.1.1 | 192.168.2.4 | 0x132a | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:09.622057915 CET | 1.1.1.1 | 192.168.2.4 | 0x2d3d | No error (0) | 173.194.219.84 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:10.989728928 CET | 1.1.1.1 | 192.168.2.4 | 0xa0d4 | No error (0) | 104.18.68.40 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:10.989728928 CET | 1.1.1.1 | 192.168.2.4 | 0xa0d4 | No error (0) | 104.18.69.40 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:10.990703106 CET | 1.1.1.1 | 192.168.2.4 | 0xe84d | No error (0) | 65 | IN (0x0001) | false | |||
Feb 8, 2024 04:12:11.917548895 CET | 1.1.1.1 | 192.168.2.4 | 0xb2d1 | No error (0) | 23.237.26.135 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.868684053 CET | 1.1.1.1 | 192.168.2.4 | 0xaa1b | No error (0) | 104.21.42.31 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.868684053 CET | 1.1.1.1 | 192.168.2.4 | 0xaa1b | No error (0) | 172.67.199.185 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.873287916 CET | 1.1.1.1 | 192.168.2.4 | 0x14ad | No error (0) | 65 | IN (0x0001) | false | |||
Feb 8, 2024 04:12:13.963557005 CET | 1.1.1.1 | 192.168.2.4 | 0x53a | No error (0) | 74.125.138.99 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.963557005 CET | 1.1.1.1 | 192.168.2.4 | 0x53a | No error (0) | 74.125.138.105 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.963557005 CET | 1.1.1.1 | 192.168.2.4 | 0x53a | No error (0) | 74.125.138.106 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.963557005 CET | 1.1.1.1 | 192.168.2.4 | 0x53a | No error (0) | 74.125.138.147 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.963557005 CET | 1.1.1.1 | 192.168.2.4 | 0x53a | No error (0) | 74.125.138.104 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.963557005 CET | 1.1.1.1 | 192.168.2.4 | 0x53a | No error (0) | 74.125.138.103 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:13.965178013 CET | 1.1.1.1 | 192.168.2.4 | 0x2c36 | No error (0) | 65 | IN (0x0001) | false | |||
Feb 8, 2024 04:12:15.225311995 CET | 1.1.1.1 | 192.168.2.4 | 0x5098 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:27.366760015 CET | 1.1.1.1 | 192.168.2.4 | 0x6125 | No error (0) | 69.164.42.0 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:27.734215021 CET | 1.1.1.1 | 192.168.2.4 | 0x9575 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:27.734215021 CET | 1.1.1.1 | 192.168.2.4 | 0x9575 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:40.643136978 CET | 1.1.1.1 | 192.168.2.4 | 0xb4a2 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 8, 2024 04:12:40.643136978 CET | 1.1.1.1 | 192.168.2.4 | 0xb4a2 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Feb 8, 2024 04:13:01.798568964 CET | 1.1.1.1 | 192.168.2.4 | 0xdd34 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 8, 2024 04:13:01.798568964 CET | 1.1.1.1 | 192.168.2.4 | 0xdd34 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 142.250.105.138 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:09 UTC | 752 | OUT | |
2024-02-08 03:12:10 UTC | 732 | IN | |
2024-02-08 03:12:10 UTC | 520 | IN | |
2024-02-08 03:12:10 UTC | 200 | IN | |
2024-02-08 03:12:10 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49731 | 173.194.219.84 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:09 UTC | 680 | OUT | |
2024-02-08 03:12:09 UTC | 1 | OUT | |
2024-02-08 03:12:10 UTC | 1798 | IN | |
2024-02-08 03:12:10 UTC | 23 | IN | |
2024-02-08 03:12:10 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49734 | 104.18.68.40 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:11 UTC | 1390 | OUT | |
2024-02-08 03:12:11 UTC | 644 | IN | |
2024-02-08 03:12:11 UTC | 148 | IN | |
2024-02-08 03:12:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49738 | 23.237.26.135 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:12 UTC | 745 | OUT | |
2024-02-08 03:12:12 UTC | 296 | IN | |
2024-02-08 03:12:12 UTC | 328 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49739 | 23.237.26.135 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:12 UTC | 746 | OUT | |
2024-02-08 03:12:13 UTC | 159 | IN | |
2024-02-08 03:12:13 UTC | 243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49741 | 104.21.42.31 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:14 UTC | 704 | OUT | |
2024-02-08 03:12:14 UTC | 593 | IN | |
2024-02-08 03:12:14 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49743 | 23.36.173.151 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:14 UTC | 161 | OUT | |
2024-02-08 03:12:14 UTC | 533 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49744 | 23.36.173.151 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:15 UTC | 239 | OUT | |
2024-02-08 03:12:15 UTC | 499 | IN | |
2024-02-08 03:12:15 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49745 | 35.190.80.1 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:15 UTC | 547 | OUT | |
2024-02-08 03:12:15 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49746 | 35.190.80.1 | 443 | 1800 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-08 03:12:15 UTC | 490 | OUT | |
2024-02-08 03:12:15 UTC | 436 | OUT | |
2024-02-08 03:12:16 UTC | 168 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 04:12:06 |
Start date: | 08/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 04:12:07 |
Start date: | 08/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 04:12:09 |
Start date: | 08/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |