Windows
Analysis Report
http://apps.identrust.com/roots/dstrootcax3.p7c
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 3744 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 5740 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2112 --fi eld-trial- handle=190 4,i,760809 9570418503 841,135975 1453211891 7770,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6604 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http ://apps.id entrust.co m/roots/ds trootcax3. p7c MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
wab.exe (PID: 5840 cmdline:
C:\Program Files\Win dows Mail\ wab.exe" / certificat e "C:\User s\user\Dow nloads\dst rootcax3.p 7c MD5: DBB30349963DBF34B6A50E6A2C3F3644)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 172.253.63.84 | true | false | high | |
www.google.com | 142.250.81.228 | true | false | high | |
clients.l.google.com | 142.251.40.238 | true | false | high | |
clients1.google.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.40.238 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
172.253.63.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.81.228 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.13 |
192.168.2.4 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1397044 |
Start date and time: | 2024-02-22 16:07:03 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 22s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://apps.identrust.com/roots/dstrootcax3.p7c |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@18/5@8/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, W MIADAP.exe, SIHClient.exe, con host.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 20.42.65.92, 142.2 50.65.195, 34.104.35.123, 23.4 0.179.186, 23.40.179.172, 52.1 65.165.26, 52.165.164.15, 20.1 2.23.50, 13.95.31.18, 13.85.23 .86, 142.250.65.163, 40.127.16 9.103 - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: http:/
/apps.identrust.com/roots/dstr ootcax3.p7c
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 893 |
Entropy (8bit): | 7.366016576663508 |
Encrypted: | false |
SSDEEP: | 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x |
MD5: | D4AE187B4574036C2D76B6DF8A8C1A30 |
SHA1: | B06F409FA14BAB33CBAF4A37811B8740B624D9E5 |
SHA-256: | A2CE3A0FA7D2A833D1801E01EC48E35B70D84F3467CC9F8FAB370386E13879C7 |
SHA-512: | 1F44A360E8BB8ADA22BC5BFE001F1BABB4E72005A46BC2A94C33C4BD149FF256CCE6F35D65CA4F7FC2A5B9E15494155449830D2809C8CF218D0B9196EC646B0C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 893 |
Entropy (8bit): | 7.366016576663508 |
Encrypted: | false |
SSDEEP: | 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x |
MD5: | D4AE187B4574036C2D76B6DF8A8C1A30 |
SHA1: | B06F409FA14BAB33CBAF4A37811B8740B624D9E5 |
SHA-256: | A2CE3A0FA7D2A833D1801E01EC48E35B70D84F3467CC9F8FAB370386E13879C7 |
SHA-512: | 1F44A360E8BB8ADA22BC5BFE001F1BABB4E72005A46BC2A94C33C4BD149FF256CCE6F35D65CA4F7FC2A5B9E15494155449830D2809C8CF218D0B9196EC646B0C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 893 |
Entropy (8bit): | 7.366016576663508 |
Encrypted: | false |
SSDEEP: | 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x |
MD5: | D4AE187B4574036C2D76B6DF8A8C1A30 |
SHA1: | B06F409FA14BAB33CBAF4A37811B8740B624D9E5 |
SHA-256: | A2CE3A0FA7D2A833D1801E01EC48E35B70D84F3467CC9F8FAB370386E13879C7 |
SHA-512: | 1F44A360E8BB8ADA22BC5BFE001F1BABB4E72005A46BC2A94C33C4BD149FF256CCE6F35D65CA4F7FC2A5B9E15494155449830D2809C8CF218D0B9196EC646B0C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 893 |
Entropy (8bit): | 7.366016576663508 |
Encrypted: | false |
SSDEEP: | 24:hBntmDvKUQQDvKUr7C5fpqp8gPvXHmXvponXux:3ntmD5QQD5XC5RqHHXmXvp++x |
MD5: | D4AE187B4574036C2D76B6DF8A8C1A30 |
SHA1: | B06F409FA14BAB33CBAF4A37811B8740B624D9E5 |
SHA-256: | A2CE3A0FA7D2A833D1801E01EC48E35B70D84F3467CC9F8FAB370386E13879C7 |
SHA-512: | 1F44A360E8BB8ADA22BC5BFE001F1BABB4E72005A46BC2A94C33C4BD149FF256CCE6F35D65CA4F7FC2A5B9E15494155449830D2809C8CF218D0B9196EC646B0C |
Malicious: | false |
Reputation: | low |
URL: | http://apps.identrust.com/roots/dstrootcax3.p7c |
Preview: |
Icon Hash: | b29a8a8e86868381 |
Download Network PCAP: filtered – full
- Total Packets: 95
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 22, 2024 16:07:46.188687086 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.189436913 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.189498901 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.189954996 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.189975977 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.190021038 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.190038919 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.401962996 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.402029991 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.402089119 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.402226925 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.402246952 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.402246952 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.402318954 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.402580976 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.402626038 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:46.402658939 CET | 49738 | 443 | 192.168.2.4 | 20.190.151.9 |
Feb 22, 2024 16:07:46.402676105 CET | 443 | 49738 | 20.190.151.9 | 192.168.2.4 |
Feb 22, 2024 16:07:47.680793047 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Feb 22, 2024 16:07:57.290199041 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Feb 22, 2024 16:07:58.874008894 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:58.874052048 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:58.874126911 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:58.874891043 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:58.874927998 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:58.875001907 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:58.875185966 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:58.875205040 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:58.875443935 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:58.875459909 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.105389118 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.105977058 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:59.105994940 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.107891083 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.107956886 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:59.108989954 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:59.109074116 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.109607935 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:59.109615088 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.164038897 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:59.182734013 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.183018923 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.183036089 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.183571100 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.183633089 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.184566021 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.184617996 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.186012983 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.186094046 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.186371088 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.186378002 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.226572990 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.327677965 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.328241110 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.328301907 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:59.329005003 CET | 49742 | 443 | 192.168.2.4 | 172.253.63.84 |
Feb 22, 2024 16:07:59.329016924 CET | 443 | 49742 | 172.253.63.84 | 192.168.2.4 |
Feb 22, 2024 16:07:59.455387115 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.455580950 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:07:59.455833912 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.456105947 CET | 49741 | 443 | 192.168.2.4 | 142.251.40.238 |
Feb 22, 2024 16:07:59.456145048 CET | 443 | 49741 | 142.251.40.238 | 192.168.2.4 |
Feb 22, 2024 16:08:02.992136955 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:02.992183924 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:02.992244005 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:02.997227907 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:02.997246027 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:03.196083069 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:03.196774006 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:03.196810007 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:03.197812080 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:03.197895050 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:03.201479912 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:03.201562881 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:03.242469072 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:03.242496014 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:03.289336920 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:03.576323986 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.576365948 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.576445103 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.578958988 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.578986883 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.768570900 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.768744946 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.772353888 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.772363901 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.772614002 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.820600986 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.864960909 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.905916929 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.954755068 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.954906940 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.955079079 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.955298901 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.955298901 CET | 49750 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:03.955322981 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:03.955336094 CET | 443 | 49750 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.018364906 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.018449068 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.019059896 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.019059896 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.019113064 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.204463005 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.204688072 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.209912062 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.209964991 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.210351944 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.213862896 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.253947020 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.380398989 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.380537033 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.380711079 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.382550001 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.382591963 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:04.382632971 CET | 49751 | 443 | 192.168.2.4 | 23.51.58.94 |
Feb 22, 2024 16:08:04.382648945 CET | 443 | 49751 | 23.51.58.94 | 192.168.2.4 |
Feb 22, 2024 16:08:13.210201979 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:13.210267067 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:13.210330963 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:15.103310108 CET | 49749 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:08:15.103348017 CET | 443 | 49749 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:08:42.259247065 CET | 49733 | 80 | 192.168.2.4 | 192.229.211.108 |
Feb 22, 2024 16:08:42.259694099 CET | 49723 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:08:42.259804964 CET | 49724 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:08:42.259903908 CET | 49734 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:08:42.259911060 CET | 49731 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:08:42.346554041 CET | 80 | 49733 | 192.229.211.108 | 192.168.2.4 |
Feb 22, 2024 16:08:42.346690893 CET | 49733 | 80 | 192.168.2.4 | 192.229.211.108 |
Feb 22, 2024 16:08:42.346977949 CET | 80 | 49724 | 72.21.81.240 | 192.168.2.4 |
Feb 22, 2024 16:08:42.347074032 CET | 80 | 49731 | 72.21.81.240 | 192.168.2.4 |
Feb 22, 2024 16:08:42.347124100 CET | 49724 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:08:42.347781897 CET | 49731 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:08:42.347788095 CET | 80 | 49723 | 72.21.81.240 | 192.168.2.4 |
Feb 22, 2024 16:08:42.347954035 CET | 80 | 49734 | 72.21.81.240 | 192.168.2.4 |
Feb 22, 2024 16:08:42.347958088 CET | 49723 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:08:42.348077059 CET | 49734 | 80 | 192.168.2.4 | 72.21.81.240 |
Feb 22, 2024 16:09:00.595432043 CET | 49730 | 80 | 192.168.2.4 | 192.229.211.108 |
Feb 22, 2024 16:09:00.683557987 CET | 80 | 49730 | 192.229.211.108 | 192.168.2.4 |
Feb 22, 2024 16:09:00.683624983 CET | 49730 | 80 | 192.168.2.4 | 192.229.211.108 |
Feb 22, 2024 16:09:02.963129997 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:02.963217974 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:02.963320017 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:02.963810921 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:02.963845015 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:03.155962944 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:03.156339884 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:03.156361103 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:03.156821012 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:03.157192945 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:03.157269955 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:03.210925102 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:13.192975998 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:13.193141937 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:13.193223000 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:15.104065895 CET | 49755 | 443 | 192.168.2.4 | 142.250.81.228 |
Feb 22, 2024 16:09:15.104120016 CET | 443 | 49755 | 142.250.81.228 | 192.168.2.4 |
Feb 22, 2024 16:09:28.039376020 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.039411068 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.039468050 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.039843082 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.039854050 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.232084990 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.232336044 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.232352018 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.232857943 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.232922077 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.233855963 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.233911037 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.235816002 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.235898018 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.235981941 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.235986948 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.289973974 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.451455116 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.451965094 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Feb 22, 2024 16:09:28.452011108 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.452389956 CET | 49756 | 443 | 192.168.2.4 | 142.251.41.14 |
Feb 22, 2024 16:09:28.452404022 CET | 443 | 49756 | 142.251.41.14 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 22, 2024 16:07:58.784301996 CET | 56085 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:07:58.784734964 CET | 59150 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:07:58.785339117 CET | 60778 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:07:58.785536051 CET | 53870 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:07:58.820487976 CET | 53 | 57187 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:07:58.872256994 CET | 53 | 56085 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:07:58.872857094 CET | 53 | 59150 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:07:58.873529911 CET | 53 | 60778 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:07:58.873670101 CET | 53 | 53870 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:07:59.590643883 CET | 53 | 56372 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:08:02.900799990 CET | 57962 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:08:02.901832104 CET | 58044 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:08:02.989171028 CET | 53 | 57962 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:08:02.990427971 CET | 53 | 58044 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:08:16.219357967 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Feb 22, 2024 16:08:16.895304918 CET | 53 | 65387 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:08:35.721836090 CET | 53 | 58627 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:08:58.492789030 CET | 53 | 53675 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:08:58.646106958 CET | 53 | 63163 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:09:26.814368010 CET | 53 | 60314 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:09:27.933893919 CET | 52557 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:09:27.934381008 CET | 57001 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 22, 2024 16:09:28.021945000 CET | 53 | 52557 | 1.1.1.1 | 192.168.2.4 |
Feb 22, 2024 16:09:28.024238110 CET | 53 | 57001 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Feb 22, 2024 16:07:58.784301996 CET | 192.168.2.4 | 1.1.1.1 | 0xa828 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 22, 2024 16:07:58.784734964 CET | 192.168.2.4 | 1.1.1.1 | 0x9ab0 | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 22, 2024 16:07:58.785339117 CET | 192.168.2.4 | 1.1.1.1 | 0x6621 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 22, 2024 16:07:58.785536051 CET | 192.168.2.4 | 1.1.1.1 | 0x355a | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 22, 2024 16:08:02.900799990 CET | 192.168.2.4 | 1.1.1.1 | 0x55ea | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 22, 2024 16:08:02.901832104 CET | 192.168.2.4 | 1.1.1.1 | 0xa6c5 | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 22, 2024 16:09:27.933893919 CET | 192.168.2.4 | 1.1.1.1 | 0x818b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 22, 2024 16:09:27.934381008 CET | 192.168.2.4 | 1.1.1.1 | 0x6310 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Feb 22, 2024 16:07:58.872256994 CET | 1.1.1.1 | 192.168.2.4 | 0xa828 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 22, 2024 16:07:58.872256994 CET | 1.1.1.1 | 192.168.2.4 | 0xa828 | No error (0) | 142.251.40.238 | A (IP address) | IN (0x0001) | false | ||
Feb 22, 2024 16:07:58.872857094 CET | 1.1.1.1 | 192.168.2.4 | 0x9ab0 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 22, 2024 16:07:58.873529911 CET | 1.1.1.1 | 192.168.2.4 | 0x6621 | No error (0) | 172.253.63.84 | A (IP address) | IN (0x0001) | false | ||
Feb 22, 2024 16:08:02.989171028 CET | 1.1.1.1 | 192.168.2.4 | 0x55ea | No error (0) | 142.250.81.228 | A (IP address) | IN (0x0001) | false | ||
Feb 22, 2024 16:08:02.990427971 CET | 1.1.1.1 | 192.168.2.4 | 0xa6c5 | No error (0) | 65 | IN (0x0001) | false | |||
Feb 22, 2024 16:09:28.021945000 CET | 1.1.1.1 | 192.168.2.4 | 0x818b | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 22, 2024 16:09:28.021945000 CET | 1.1.1.1 | 192.168.2.4 | 0x818b | No error (0) | 142.251.41.14 | A (IP address) | IN (0x0001) | false | ||
Feb 22, 2024 16:09:28.024238110 CET | 1.1.1.1 | 192.168.2.4 | 0x6310 | No error (0) | clients.l.google.com | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.4 | 49737 | 20.190.151.9 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-22 15:07:45 UTC | 422 | OUT | |
2024-02-22 15:07:45 UTC | 4751 | OUT | |
2024-02-22 15:07:45 UTC | 569 | IN | |
2024-02-22 15:07:45 UTC | 11388 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.4 | 49738 | 20.190.151.9 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-22 15:07:46 UTC | 422 | OUT | |
2024-02-22 15:07:46 UTC | 4751 | OUT | |
2024-02-22 15:07:46 UTC | 569 | IN | |
2024-02-22 15:07:46 UTC | 11368 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49742 | 172.253.63.84 | 443 | 5740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-22 15:07:59 UTC | 680 | OUT | |
2024-02-22 15:07:59 UTC | 1 | OUT | |
2024-02-22 15:07:59 UTC | 1799 | IN | |
2024-02-22 15:07:59 UTC | 23 | IN | |
2024-02-22 15:07:59 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49741 | 142.251.40.238 | 443 | 5740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-22 15:07:59 UTC | 752 | OUT | |
2024-02-22 15:07:59 UTC | 732 | IN | |
2024-02-22 15:07:59 UTC | 520 | IN | |
2024-02-22 15:07:59 UTC | 200 | IN | |
2024-02-22 15:07:59 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49750 | 23.51.58.94 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-22 15:08:03 UTC | 161 | OUT | |
2024-02-22 15:08:03 UTC | 494 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49751 | 23.51.58.94 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-22 15:08:04 UTC | 239 | OUT | |
2024-02-22 15:08:04 UTC | 455 | IN | |
2024-02-22 15:08:04 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
6 | 192.168.2.4 | 49756 | 142.251.41.14 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-22 15:09:28 UTC | 449 | OUT | |
2024-02-22 15:09:28 UTC | 817 | IN | |
2024-02-22 15:09:28 UTC | 220 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 16:07:50 |
Start date: | 22/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 16:07:57 |
Start date: | 22/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 16:07:59 |
Start date: | 22/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 16:09:17 |
Start date: | 22/02/2024 |
Path: | C:\Program Files\Windows Mail\wab.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f270000 |
File size: | 518'656 bytes |
MD5 hash: | DBB30349963DBF34B6A50E6A2C3F3644 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |