Windows
Analysis Report
http://149.154.167.41
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1440 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 2140 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2512 --fi eld-trial- handle=220 4,i,748906 4456424810 634,799509 4544846090 831,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 4128 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http ://149.154 .167.41 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.250.31.84 | true | false | high | |
www.google.com | 142.251.40.228 | true | false | high | |
clients.l.google.com | 142.251.40.238 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown | |
windowsupdatebg.s.llnwi.net | 69.164.46.0 | true | false | unknown | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | unknown | ||
false | high | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.41 | unknown | United Kingdom | 62041 | TELEGRAMRU | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.40.238 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
142.251.40.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.31.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1393633 |
Start date and time: | 2024-02-16 19:21:01 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://149.154.167.41 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@16/10@6/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe, SIHClient.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.80.67, 34. 104.35.123, 40.68.123.157, 23. 206.121.32, 192.229.211.108, 6 9.164.46.0, 20.242.39.171, 72. 21.81.240, 13.85.23.206, 23.20 6.121.5, 23.206.121.13, 23.206 .121.15, 23.206.121.7, 23.206. 121.10, 23.206.121.11, 23.206. 121.61, 23.206.121.60, 23.206. 121.8, 142.250.65.227, 104.102 .251.17, 104.102.251.80, 104.1 02.251.73, 23.206.121.35, 23.2 06.121.29, 23.206.121.28, 23.2 06.121.30, 23.206.121.27, 23.2 06.121.46, 23.206.121.34, 23.2 06.121.31 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, slscr.update.microsoft.com , wu.ec.azureedge.net, clients ervices.googleapis.com, ctldl. windowsupdate.com, a767.dspw65 .akamai.net, wu-bg-shim.traffi cmanager.net, wu.azureedge.net , fe3cr.delivery.mp.microsoft. com, download.windowsupdate.co m.edgesuite.net, fe3.delivery. mp.microsoft.com, edgedl.me.gv t1.com, ocsp.digicert.com, ocs p.edge.digicert.com, glb.cws.p rod.dcat.dsp.trafficmanager.ne t, bg.apr-52dd2-0503.edgecastd ns.net, cs11.wpc.v0cdn.net, sl s.update.microsoft.com, hlb.ap r-52dd2-0.edgecastdns.net, upd ate.googleapis.com, glb.sls.pr od.dcat.dsp.trafficmanager.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: http:/
/149.154.167.41
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.978058406552975 |
Encrypted: | false |
SSDEEP: | 48:8rj2dtOTNKqR8HOsidAKZdA19ehwiZUklqehBy+3:8rhPouy |
MD5: | B7D57AA9AD4EE0BDF4B31589F6444195 |
SHA1: | FB3FEA974694E3BFFC03982C2326EAD80BC7D1DF |
SHA-256: | 22AABFBAF037030E801ED01F2C5A2EB48DFF066F41380579B483883A62C46B0B |
SHA-512: | 5E97B92393341B685F4B6890F7A1061AFF80FC3F887E3EAE713E72DE9C926DEFD9ADCF4F3FBA1DCCCB31C764CE8675727DA4740F73483BF7FD17D7C7403620E6 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9934171356667725 |
Encrypted: | false |
SSDEEP: | 48:8i2dtOTNKqR8HOsidAKZdA1weh/iZUkAQkqehey+2:88Pi9QHy |
MD5: | 675F18DEB808E491E302EF3B875EE214 |
SHA1: | ACB180C23CABE169C8D76EFDAC0449249F1F41DC |
SHA-256: | 565EE8A73D6D1317228E5CC9093FEFCA909097FF7A42FF38770DF949B22270CD |
SHA-512: | 2FC665F5DEFA56F0B400CC89D7D57C97B17D8E37939C2E50B673EA285AE3782D7EEE4E4E6E2622A6A43A97F3A54DD37934B047CC170D26DB1A177455FE8BCAA3 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.003531366802204 |
Encrypted: | false |
SSDEEP: | 48:8x+2dtOTNKqRsHOsidAKZdA14tseh7sFiZUkmgqeh7sEy+BX:8x4P6nCy |
MD5: | 1BCE4545FC9FA8A5B3CCAE87F7B72269 |
SHA1: | CA77DFCE3ECFD4093CCAE0DB7D2D92EC312A6E99 |
SHA-256: | 7B460DE4434C8FF60FBEA232A54485EBC6ACD3A4029285ECB973152AC00DCFE1 |
SHA-512: | E015FDFBC0A780E4423E520204FD1C51B15FB7CF050A3ACE031D9DEADD606239F1B47E0D5302AC9C7A4C830DD4F5E2CD054109F930D603ABCBAB0300634225AA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9903102868592524 |
Encrypted: | false |
SSDEEP: | 48:8i2dtOTNKqR8HOsidAKZdA1vehDiZUkwqeh6y+R:88Ppcy |
MD5: | BA5BF73C0AC37F039D9F58C8214923A4 |
SHA1: | 8A13A8D5AB00604FD69E537D47D7B7CF925DDF8D |
SHA-256: | 12FF2B4C085DB476B1A1441A77224A9BBD637A04B9548FA184576B3B7205926D |
SHA-512: | 68D1798C9A2DADA8F4995E77098472320A448C6033AAF40D189B1297665CF0EE8125B1209E72C98FB40DC8255910884A611C50831E282B4C6C28135572C93A9B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9809299611761184 |
Encrypted: | false |
SSDEEP: | 48:842dtOTNKqR8HOsidAKZdA1hehBiZUk1W1qehYy+C:8ePZ94y |
MD5: | 52107C203E6C9143C5456C1CB1C3F5C0 |
SHA1: | B0E3B9FB687FB8338C540B8F6F0FE7C4BCC4E47E |
SHA-256: | 10670AF0BE76D63ECFE90929F3D55E9FE4A2F654FE4CA1B2808AADC0C111C3ED |
SHA-512: | FB987EFCF329FBF79A8C26D41379DD22E42EF7023E1C5281EF89EE9A00C24FAB4B817E5F9A5FEA7842A57DFEF96077E3200EA5216E3161DC952B2D72D886A496 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.991784669074659 |
Encrypted: | false |
SSDEEP: | 48:8y2dtOTNKqR8HOsidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbCy+yT+:8MPlT/TbxWOvTbCy7T |
MD5: | 0416DDA144CC29ADFACB8B8F0CC2F503 |
SHA1: | 567D9E37A33C15D09A794370E77D4B1804F82C82 |
SHA-256: | 854CB261BA803AE4DE75651C375A3B66B92473C43F557EE23780690F85D1A747 |
SHA-512: | 82CE2596DE5FF9C512710D84B31522A603BC8FF45B85234BF686DE2943FEC3F3FC5D22EE5105181EDDB64E35B28AFF3623C8838684C159B651B90D0F1016E6D0 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 169 |
Entropy (8bit): | 4.65038089552961 |
Encrypted: | false |
SSDEEP: | 3:qVoB3tURObOb0qHXboAc9FKEIHiHby4AqWrKb0GklIVLLP9iVawcWWGu:q43tIkObRHXiWHiHuwWObtklI5LPoapJ |
MD5: | C2A982D42F89274763EEF2A44FE01030 |
SHA1: | 86E6D53F6478CDD0C05611093D9C55A953454AF7 |
SHA-256: | D8B55DE3A4D5331F3B450A86BB907AFE17DC964ADCA30F39D101A3D55A4A9D6A |
SHA-512: | C1E2F30DB797583EC9EAE6755DAB939A2D71F902B557B069EFC510E51127DB6781456116CBFD764C8B9FC397791DF492DF52D200AFD9E46734B0845912C76E24 |
Malicious: | false |
Reputation: | low |
URL: | http://149.154.167.41/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 169 |
Entropy (8bit): | 4.65038089552961 |
Encrypted: | false |
SSDEEP: | 3:qVoB3tURObOb0qHXboAc9FKEIHiHby4AqWrKb0GklIVLLP9iVawcWWGu:q43tIkObRHXiWHiHuwWObtklI5LPoapJ |
MD5: | C2A982D42F89274763EEF2A44FE01030 |
SHA1: | 86E6D53F6478CDD0C05611093D9C55A953454AF7 |
SHA-256: | D8B55DE3A4D5331F3B450A86BB907AFE17DC964ADCA30F39D101A3D55A4A9D6A |
SHA-512: | C1E2F30DB797583EC9EAE6755DAB939A2D71F902B557B069EFC510E51127DB6781456116CBFD764C8B9FC397791DF492DF52D200AFD9E46734B0845912C76E24 |
Malicious: | false |
Reputation: | low |
URL: | http://149.154.167.41/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 98
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 16, 2024 19:21:48.511322021 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:21:48.511331081 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:21:48.620735884 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:21:57.087954998 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.087996960 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.088056087 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.090506077 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.090533972 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.090584993 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.090792894 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.090821981 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.090996027 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.091006994 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.318655014 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.319499016 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.319508076 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.321372986 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.321458101 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.324139118 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.324214935 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.324958086 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.324961901 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.399843931 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.400135040 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.400170088 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.400660992 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.400728941 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.401654959 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.401705027 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.402832985 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.403023005 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.403033018 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.403078079 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.444169044 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.444176912 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.444211006 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.542789936 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.542898893 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.542910099 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.542959929 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.543097973 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.543807030 CET | 49707 | 443 | 192.168.2.5 | 142.250.31.84 |
Feb 16, 2024 19:21:57.543816090 CET | 443 | 49707 | 142.250.31.84 | 192.168.2.5 |
Feb 16, 2024 19:21:57.546344042 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.676018953 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.676192045 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:57.676345110 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.676683903 CET | 49706 | 443 | 192.168.2.5 | 142.251.40.238 |
Feb 16, 2024 19:21:57.676727057 CET | 443 | 49706 | 142.251.40.238 | 192.168.2.5 |
Feb 16, 2024 19:21:58.131313086 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:21:58.146822929 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:21:58.256208897 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:21:58.466872931 CET | 49710 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:58.467058897 CET | 49711 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:58.629046917 CET | 80 | 49710 | 149.154.167.41 | 192.168.2.5 |
Feb 16, 2024 19:21:58.629189968 CET | 49710 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:58.629429102 CET | 49710 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:58.630656958 CET | 80 | 49711 | 149.154.167.41 | 192.168.2.5 |
Feb 16, 2024 19:21:58.631052971 CET | 49711 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:58.791642904 CET | 80 | 49710 | 149.154.167.41 | 192.168.2.5 |
Feb 16, 2024 19:21:58.856018066 CET | 49710 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:58.860934973 CET | 49710 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:59.023080111 CET | 80 | 49710 | 149.154.167.41 | 192.168.2.5 |
Feb 16, 2024 19:21:59.070692062 CET | 49710 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:21:59.347171068 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:21:59.347223043 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:21:59.347296000 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:21:59.347666979 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:21:59.347681999 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:21:59.591862917 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:21:59.591979980 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:21:59.614346027 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:21:59.614619017 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:21:59.614641905 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:21:59.615525007 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:21:59.615581989 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:21:59.617188931 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:21:59.617250919 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:21:59.663275003 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:21:59.663291931 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:21:59.710154057 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:01.814667940 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:01.814701080 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:01.814868927 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:01.818310022 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:01.818325043 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.007466078 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.007611036 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.011148930 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.011157036 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.011558056 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.053608894 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.112047911 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.153914928 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.200742960 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.204437971 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.204467058 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.204484940 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.204665899 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.204718113 CET | 443 | 49715 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.204849005 CET | 49715 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.271044970 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.271080017 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.271152973 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.272229910 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.272247076 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.462282896 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.462368011 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.465343952 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.465351105 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.465666056 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.467108011 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.513914108 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.636220932 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.636337996 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.636390924 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.637903929 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.637919903 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:02.637928963 CET | 49716 | 443 | 192.168.2.5 | 23.199.50.2 |
Feb 16, 2024 19:22:02.637936115 CET | 443 | 49716 | 23.199.50.2 | 192.168.2.5 |
Feb 16, 2024 19:22:09.612010002 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:09.612087965 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:09.612520933 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:09.824727058 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:09.824873924 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:09.825419903 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:09.825474977 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:09.825686932 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:09.826208115 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:09.826252937 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:09.977396965 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:09.977475882 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.146456003 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.146536112 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:10.180701971 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:10.180746078 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.181191921 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.181251049 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:10.181708097 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:10.181746006 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.181958914 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:10.181972027 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.483391047 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.483458042 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:10.483911991 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:10.483963013 CET | 443 | 49721 | 23.1.237.91 | 192.168.2.5 |
Feb 16, 2024 19:22:10.484025002 CET | 49721 | 443 | 192.168.2.5 | 23.1.237.91 |
Feb 16, 2024 19:22:11.247833014 CET | 49713 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:11.247873068 CET | 443 | 49713 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:43.632761955 CET | 49711 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:22:43.797039986 CET | 80 | 49711 | 149.154.167.41 | 192.168.2.5 |
Feb 16, 2024 19:22:44.038121939 CET | 49710 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:22:44.200344086 CET | 80 | 49710 | 149.154.167.41 | 192.168.2.5 |
Feb 16, 2024 19:22:59.224570036 CET | 49711 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:22:59.308304071 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:59.308341026 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:59.308409929 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:59.309024096 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:59.309040070 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:59.388283968 CET | 80 | 49711 | 149.154.167.41 | 192.168.2.5 |
Feb 16, 2024 19:22:59.388365984 CET | 49711 | 80 | 192.168.2.5 | 149.154.167.41 |
Feb 16, 2024 19:22:59.580476999 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:59.582683086 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:59.582709074 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:59.583309889 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:59.584021091 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:22:59.584119081 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:22:59.627423048 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:23:09.567066908 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:23:09.567219019 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Feb 16, 2024 19:23:09.567277908 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:23:11.211747885 CET | 49726 | 443 | 192.168.2.5 | 142.251.40.228 |
Feb 16, 2024 19:23:11.211776018 CET | 443 | 49726 | 142.251.40.228 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 16, 2024 19:21:56.998533010 CET | 49682 | 53 | 192.168.2.5 | 1.1.1.1 |
Feb 16, 2024 19:21:56.998863935 CET | 61554 | 53 | 192.168.2.5 | 1.1.1.1 |
Feb 16, 2024 19:21:56.999577045 CET | 64912 | 53 | 192.168.2.5 | 1.1.1.1 |
Feb 16, 2024 19:21:56.999880075 CET | 64184 | 53 | 192.168.2.5 | 1.1.1.1 |
Feb 16, 2024 19:21:57.076947927 CET | 53 | 61956 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:21:57.086235046 CET | 53 | 49682 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:21:57.087110996 CET | 53 | 61554 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:21:57.088124037 CET | 53 | 64912 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:21:57.088270903 CET | 53 | 64184 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:21:57.835912943 CET | 53 | 62716 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:21:59.257183075 CET | 59586 | 53 | 192.168.2.5 | 1.1.1.1 |
Feb 16, 2024 19:21:59.257437944 CET | 54226 | 53 | 192.168.2.5 | 1.1.1.1 |
Feb 16, 2024 19:21:59.345247030 CET | 53 | 59586 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:21:59.346182108 CET | 53 | 54226 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:22:14.862035990 CET | 53 | 62670 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:22:33.785712957 CET | 53 | 57242 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:22:56.269793034 CET | 53 | 55488 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:22:56.409121990 CET | 53 | 55756 | 1.1.1.1 | 192.168.2.5 |
Feb 16, 2024 19:23:23.580241919 CET | 53 | 64194 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Feb 16, 2024 19:21:56.998533010 CET | 192.168.2.5 | 1.1.1.1 | 0x3533 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 16, 2024 19:21:56.998863935 CET | 192.168.2.5 | 1.1.1.1 | 0xd61e | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 16, 2024 19:21:56.999577045 CET | 192.168.2.5 | 1.1.1.1 | 0xa2be | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 16, 2024 19:21:56.999880075 CET | 192.168.2.5 | 1.1.1.1 | 0xcf9b | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 16, 2024 19:21:59.257183075 CET | 192.168.2.5 | 1.1.1.1 | 0xe4dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 16, 2024 19:21:59.257437944 CET | 192.168.2.5 | 1.1.1.1 | 0xafa3 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Feb 16, 2024 19:21:57.086235046 CET | 1.1.1.1 | 192.168.2.5 | 0x3533 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 16, 2024 19:21:57.086235046 CET | 1.1.1.1 | 192.168.2.5 | 0x3533 | No error (0) | 142.251.40.238 | A (IP address) | IN (0x0001) | false | ||
Feb 16, 2024 19:21:57.087110996 CET | 1.1.1.1 | 192.168.2.5 | 0xd61e | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 16, 2024 19:21:57.088124037 CET | 1.1.1.1 | 192.168.2.5 | 0xa2be | No error (0) | 142.250.31.84 | A (IP address) | IN (0x0001) | false | ||
Feb 16, 2024 19:21:59.345247030 CET | 1.1.1.1 | 192.168.2.5 | 0xe4dc | No error (0) | 142.251.40.228 | A (IP address) | IN (0x0001) | false | ||
Feb 16, 2024 19:21:59.346182108 CET | 1.1.1.1 | 192.168.2.5 | 0xafa3 | No error (0) | 65 | IN (0x0001) | false | |||
Feb 16, 2024 19:22:09.500641108 CET | 1.1.1.1 | 192.168.2.5 | 0x59f1 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 16, 2024 19:22:09.500641108 CET | 1.1.1.1 | 192.168.2.5 | 0x59f1 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Feb 16, 2024 19:22:09.555535078 CET | 1.1.1.1 | 192.168.2.5 | 0xe204 | No error (0) | 69.164.46.0 | A (IP address) | IN (0x0001) | false | ||
Feb 16, 2024 19:22:09.555535078 CET | 1.1.1.1 | 192.168.2.5 | 0xe204 | No error (0) | 69.164.46.128 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49710 | 149.154.167.41 | 80 | 2140 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 16, 2024 19:21:58.629429102 CET | 429 | OUT | |
Feb 16, 2024 19:21:58.791642904 CET | 324 | IN | |
Feb 16, 2024 19:21:58.860934973 CET | 372 | OUT | |
Feb 16, 2024 19:21:59.023080111 CET | 324 | IN | |
Feb 16, 2024 19:22:44.038121939 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49711 | 149.154.167.41 | 80 | 2140 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 16, 2024 19:22:43.632761955 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49707 | 142.250.31.84 | 443 | 2140 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-16 18:21:57 UTC | 680 | OUT | |
2024-02-16 18:21:57 UTC | 1 | OUT | |
2024-02-16 18:21:57 UTC | 1799 | IN | |
2024-02-16 18:21:57 UTC | 23 | IN | |
2024-02-16 18:21:57 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49706 | 142.251.40.238 | 443 | 2140 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-16 18:21:57 UTC | 752 | OUT | |
2024-02-16 18:21:57 UTC | 732 | IN | |
2024-02-16 18:21:57 UTC | 520 | IN | |
2024-02-16 18:21:57 UTC | 200 | IN | |
2024-02-16 18:21:57 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49715 | 23.199.50.2 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-16 18:22:02 UTC | 161 | OUT | |
2024-02-16 18:22:02 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49716 | 23.199.50.2 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-16 18:22:02 UTC | 239 | OUT | |
2024-02-16 18:22:02 UTC | 658 | IN | |
2024-02-16 18:22:02 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
4 | 192.168.2.5 | 49721 | 23.1.237.91 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-16 18:22:10 UTC | 2148 | OUT | |
2024-02-16 18:22:10 UTC | 1 | OUT | |
2024-02-16 18:22:10 UTC | 2483 | OUT | |
2024-02-16 18:22:10 UTC | 475 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 19:21:50 |
Start date: | 16/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 19:21:54 |
Start date: | 16/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 19:21:57 |
Start date: | 16/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |