Windows
Analysis Report
https://a11ybar.com/ok6.js
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1448 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) chrome.exe (PID: 1072 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2388 --fi eld-trial- handle=220 0,i,243169 4887396778 904,174620 0962983611 7578,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
chrome.exe (PID: 6600 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://a11yba r.com/ok6. js MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 172.253.62.106 | true | false | high | |
a11ybar.com | 104.21.56.218 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown | |
time.windows.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.67.136.238 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.253.62.106 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.21.56.218 | a11ybar.com | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.102 |
192.168.2.7 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1400288 |
Start date and time: | 2024-02-28 16:02:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://a11ybar.com/ok6.js |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@16/5@7/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, SIHClient.exe, Sgr mBroker.exe, MoUsoCoreWorker.e xe, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.167.94, 17 2.253.63.102, 172.253.63.139, 172.253.63.113, 172.253.63.100 , 172.253.63.138, 172.253.63.1 01, 172.253.63.84, 34.104.35.1 23, 168.61.215.74, 20.114.59.1 83, 23.207.202.25, 192.229.211 .108, 104.96.220.107, 104.96.2 20.104, 20.166.126.56, 72.21.8 1.240, 13.95.31.18, 23.207.202 .42, 23.207.202.6, 23.207.202. 13, 23.207.202.12, 23.207.202. 7, 23.207.202.9, 23.207.202.10 , 23.207.202.5, 23.207.202.41, 23.207.202.38, 23.207.202.37, 23.207.202.40, 172.253.62.94, 23.207.202.15, 23.207.202.22, 23.207.202.21, 23.207.202.20, 23.207.202.14, 23.207.202.16 - Excluded domains from analysis
(whitelisted): slscr.update.m icrosoft.com, twc.trafficmanag er.net, clientservices.googlea pis.com, a767.dspw65.akamai.ne t, wu.azureedge.net, clients2. google.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.c ws.prod.dcat.dsp.trafficmanage r.net, bg.apr-52dd2-0503.edgec astdns.net, cs11.wpc.v0cdn.net , sls.update.microsoft.com, hl b.apr-52dd2-0.edgecastdns.net, update.googleapis.com, glb.sl s.prod.dcat.dsp.trafficmanager .net, fs.microsoft.com, accoun ts.google.com, wu.ec.azureedge .net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net , download.windowsupdate.com.e dgesuite.net, fe3cr.delivery.m p.microsoft.com, fe3.delivery. mp.microsoft.com, edgedl.me.gv t1.com, clients.l.google.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: https:
//a11ybar.com/ok6.js
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 141 |
Entropy (8bit): | 4.784373198763856 |
Encrypted: | false |
SSDEEP: | 3:q0oBiRyRmgO9lNHWAUafRAU6/GY+ovEEkjX2DGZ9LRzlLBFTvn:qM8mgO9lVhnZXm+ov6jX2DGZ9L1lLBJv |
MD5: | 83CB13AF83103C0462F2887B9E2E59FC |
SHA1: | BBA2C6F03A513588A6001980E7E11CFDA068D2A2 |
SHA-256: | AE723359F13E5593E4C492C99A8D4751A3349EFC137FB3EA701A991C4867B242 |
SHA-512: | DCC8381FACF78E829897B4CF3868D284139AFD54C834B86CC3A1EA11E9E9110D4552B4AA26F135EDD72B4E40DDE853531861050F017605EA0D977FA075EC950E |
Malicious: | false |
Reputation: | low |
URL: | https://a11ybar.com/ok6.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 5.043197498357468 |
Encrypted: | false |
SSDEEP: | 3:IuFADyM6IdFKsWTDfiSA+qQOuaM/FUtWf4GpvIbzWEo4G6v2lqXtPL:IUA2oNZSA+noFIs6bvI9 |
MD5: | 1F784A903271104AB6B9B0FBFF7762B5 |
SHA1: | 773E1082DCEAAECDA85E2618DBAE749A69312C03 |
SHA-256: | 781669358DE6B6B1E627C1FFBB3584268A3FA7359AEF1FDC2C7B6D7D562C63F5 |
SHA-512: | 717C7BA90FF0B9E276D04A0D44183711BE763CC161E16F312528BB3D9441A4E031E7D327EA506FDC33E2795579FE447D038343D49CF4D2D1BA6988C3F15CECCB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 165 |
Entropy (8bit): | 5.043197498357468 |
Encrypted: | false |
SSDEEP: | 3:IuFADyM6IdFKsWTDfiSA+qQOuaM/FUtWf4GpvIbzWEo4G6v2lqXtPL:IUA2oNZSA+noFIs6bvI9 |
MD5: | 1F784A903271104AB6B9B0FBFF7762B5 |
SHA1: | 773E1082DCEAAECDA85E2618DBAE749A69312C03 |
SHA-256: | 781669358DE6B6B1E627C1FFBB3584268A3FA7359AEF1FDC2C7B6D7D562C63F5 |
SHA-512: | 717C7BA90FF0B9E276D04A0D44183711BE763CC161E16F312528BB3D9441A4E031E7D327EA506FDC33E2795579FE447D038343D49CF4D2D1BA6988C3F15CECCB |
Malicious: | false |
Reputation: | low |
URL: | https://a11ybar.com/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 97
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 28, 2024 16:02:57.758265018 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Feb 28, 2024 16:02:58.070430994 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Feb 28, 2024 16:02:58.679810047 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Feb 28, 2024 16:02:59.039180994 CET | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Feb 28, 2024 16:02:59.041929007 CET | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Feb 28, 2024 16:02:59.132924080 CET | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Feb 28, 2024 16:02:59.882972002 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Feb 28, 2024 16:03:02.304821014 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Feb 28, 2024 16:03:04.563122034 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.563162088 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.563235998 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.563982010 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.564016104 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.564071894 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.564219952 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.564234018 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.564572096 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.564585924 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.841583967 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.841970921 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.841995955 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.843183994 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.843290091 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.844317913 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.844410896 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.844549894 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.844558001 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.845558882 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.847403049 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.847419024 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.848910093 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.849071980 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.849421978 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.849498987 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.922497034 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.922497034 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:04.922512054 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:04.968002081 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:05.257307053 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:05.257433891 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:05.257587910 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:05.259150982 CET | 49706 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:05.259167910 CET | 443 | 49706 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:05.304760933 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:05.345932007 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:05.530801058 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:05.531033993 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:05.531092882 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:05.534015894 CET | 49707 | 443 | 192.168.2.7 | 104.21.56.218 |
Feb 28, 2024 16:03:05.534038067 CET | 443 | 49707 | 104.21.56.218 | 192.168.2.7 |
Feb 28, 2024 16:03:05.685022116 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:05.685051918 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:05.685112000 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:05.685499907 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:05.685513973 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:05.938925028 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:05.939268112 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:05.939280987 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:05.940329075 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:05.940413952 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:05.940880060 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:05.940942049 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:05.941029072 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:05.941050053 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:05.992568970 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:06.305727005 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Feb 28, 2024 16:03:06.429327965 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:06.429424047 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:06.429478884 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:06.466682911 CET | 49709 | 443 | 192.168.2.7 | 172.67.136.238 |
Feb 28, 2024 16:03:06.466707945 CET | 443 | 49709 | 172.67.136.238 | 192.168.2.7 |
Feb 28, 2024 16:03:06.681798935 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Feb 28, 2024 16:03:06.848093033 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:06.848128080 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:06.848191977 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:06.849404097 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:06.849419117 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:07.043622017 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:07.087749958 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:07.119008064 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Feb 28, 2024 16:03:07.158684015 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:07.158700943 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:07.159967899 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:07.160048008 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:07.162942886 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:07.163017988 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:07.212748051 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:07.212766886 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:07.255986929 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:07.429708958 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Feb 28, 2024 16:03:08.648456097 CET | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Feb 28, 2024 16:03:08.648472071 CET | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Feb 28, 2024 16:03:08.742217064 CET | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Feb 28, 2024 16:03:08.929734945 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Feb 28, 2024 16:03:09.043054104 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.043081999 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.043203115 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.045691967 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.045706987 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.247222900 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.247293949 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.254935980 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.254942894 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.255224943 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.320616007 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.797557116 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.841901064 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.890607119 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.891135931 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.891171932 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.891184092 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.891376972 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.891415119 CET | 443 | 49712 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.891474009 CET | 49712 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.937848091 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.937882900 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:09.938249111 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.938249111 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:09.938286066 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.122514009 CET | 443 | 49699 | 104.98.116.138 | 192.168.2.7 |
Feb 28, 2024 16:03:10.122664928 CET | 49699 | 443 | 192.168.2.7 | 104.98.116.138 |
Feb 28, 2024 16:03:10.136506081 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.136668921 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:10.139185905 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:10.139193058 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.139535904 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.140952110 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:10.181907892 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.318022966 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.341701984 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.341811895 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:10.341912031 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:10.341912031 CET | 49713 | 443 | 192.168.2.7 | 23.221.242.90 |
Feb 28, 2024 16:03:10.341932058 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:10.341941118 CET | 443 | 49713 | 23.221.242.90 | 192.168.2.7 |
Feb 28, 2024 16:03:11.914397001 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Feb 28, 2024 16:03:16.727421999 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Feb 28, 2024 16:03:17.061928034 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:17.062011957 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:17.062079906 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:17.698482037 CET | 49711 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:03:17.698514938 CET | 443 | 49711 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:03:17.868052006 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Feb 28, 2024 16:03:29.774413109 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Feb 28, 2024 16:04:06.772077084 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:06.772119999 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:06.772192955 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:06.773422956 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:06.773448944 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:06.964473009 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:06.965960026 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:06.965993881 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:06.966371059 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:06.970107079 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:06.970244884 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:07.024260044 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:16.961129904 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:16.961296082 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Feb 28, 2024 16:04:16.961378098 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:17.912266016 CET | 49722 | 443 | 192.168.2.7 | 172.253.62.106 |
Feb 28, 2024 16:04:17.912297010 CET | 443 | 49722 | 172.253.62.106 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 28, 2024 16:03:03.578444004 CET | 53 | 62326 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:03.589318991 CET | 53 | 54833 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:04.183542013 CET | 53 | 61980 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:04.436116934 CET | 56178 | 53 | 192.168.2.7 | 1.1.1.1 |
Feb 28, 2024 16:03:04.436327934 CET | 59900 | 53 | 192.168.2.7 | 1.1.1.1 |
Feb 28, 2024 16:03:04.560394049 CET | 53 | 59900 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:04.562324047 CET | 53 | 56178 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:05.557485104 CET | 57942 | 53 | 192.168.2.7 | 1.1.1.1 |
Feb 28, 2024 16:03:05.557796001 CET | 63020 | 53 | 192.168.2.7 | 1.1.1.1 |
Feb 28, 2024 16:03:05.682384014 CET | 53 | 57942 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:05.684429884 CET | 53 | 63020 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:06.720782995 CET | 56201 | 53 | 192.168.2.7 | 1.1.1.1 |
Feb 28, 2024 16:03:06.721401930 CET | 62083 | 53 | 192.168.2.7 | 1.1.1.1 |
Feb 28, 2024 16:03:06.845514059 CET | 53 | 62083 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:06.845935106 CET | 53 | 56201 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:11.064604998 CET | 51960 | 53 | 192.168.2.7 | 1.1.1.1 |
Feb 28, 2024 16:03:21.260376930 CET | 53 | 55304 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:03:40.243258953 CET | 53 | 53305 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:04:03.022202969 CET | 53 | 51180 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:04:03.300601959 CET | 53 | 60161 | 1.1.1.1 | 192.168.2.7 |
Feb 28, 2024 16:04:06.834117889 CET | 138 | 138 | 192.168.2.7 | 192.168.2.255 |
Feb 28, 2024 16:04:31.445214033 CET | 53 | 50307 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Feb 28, 2024 16:03:04.436116934 CET | 192.168.2.7 | 1.1.1.1 | 0x9845 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 28, 2024 16:03:04.436327934 CET | 192.168.2.7 | 1.1.1.1 | 0x137d | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 28, 2024 16:03:05.557485104 CET | 192.168.2.7 | 1.1.1.1 | 0xdfa7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 28, 2024 16:03:05.557796001 CET | 192.168.2.7 | 1.1.1.1 | 0x457a | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 28, 2024 16:03:06.720782995 CET | 192.168.2.7 | 1.1.1.1 | 0xa894 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Feb 28, 2024 16:03:06.721401930 CET | 192.168.2.7 | 1.1.1.1 | 0xe3a | Standard query (0) | 65 | IN (0x0001) | false | |
Feb 28, 2024 16:03:11.064604998 CET | 192.168.2.7 | 1.1.1.1 | 0x1b9a | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Feb 28, 2024 16:03:04.560394049 CET | 1.1.1.1 | 192.168.2.7 | 0x137d | No error (0) | 65 | IN (0x0001) | false | |||
Feb 28, 2024 16:03:04.562324047 CET | 1.1.1.1 | 192.168.2.7 | 0x9845 | No error (0) | 104.21.56.218 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:04.562324047 CET | 1.1.1.1 | 192.168.2.7 | 0x9845 | No error (0) | 172.67.136.238 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:05.682384014 CET | 1.1.1.1 | 192.168.2.7 | 0xdfa7 | No error (0) | 172.67.136.238 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:05.682384014 CET | 1.1.1.1 | 192.168.2.7 | 0xdfa7 | No error (0) | 104.21.56.218 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:05.684429884 CET | 1.1.1.1 | 192.168.2.7 | 0x457a | No error (0) | 65 | IN (0x0001) | false | |||
Feb 28, 2024 16:03:06.845514059 CET | 1.1.1.1 | 192.168.2.7 | 0xe3a | No error (0) | 65 | IN (0x0001) | false | |||
Feb 28, 2024 16:03:06.845935106 CET | 1.1.1.1 | 192.168.2.7 | 0xa894 | No error (0) | 172.253.62.106 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:06.845935106 CET | 1.1.1.1 | 192.168.2.7 | 0xa894 | No error (0) | 172.253.62.105 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:06.845935106 CET | 1.1.1.1 | 192.168.2.7 | 0xa894 | No error (0) | 172.253.62.104 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:06.845935106 CET | 1.1.1.1 | 192.168.2.7 | 0xa894 | No error (0) | 172.253.62.147 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:06.845935106 CET | 1.1.1.1 | 192.168.2.7 | 0xa894 | No error (0) | 172.253.62.99 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:06.845935106 CET | 1.1.1.1 | 192.168.2.7 | 0xa894 | No error (0) | 172.253.62.103 | A (IP address) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:11.187345028 CET | 1.1.1.1 | 192.168.2.7 | 0x1b9a | No error (0) | twc.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:19.932934046 CET | 1.1.1.1 | 192.168.2.7 | 0x9e5b | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Feb 28, 2024 16:03:19.932934046 CET | 1.1.1.1 | 192.168.2.7 | 0x9e5b | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49706 | 104.21.56.218 | 443 | 1072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-28 15:03:04 UTC | 660 | OUT | |
2024-02-28 15:03:05 UTC | 678 | IN | |
2024-02-28 15:03:05 UTC | 147 | IN | |
2024-02-28 15:03:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49707 | 104.21.56.218 | 443 | 1072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-28 15:03:05 UTC | 584 | OUT | |
2024-02-28 15:03:05 UTC | 625 | IN | |
2024-02-28 15:03:05 UTC | 171 | IN | |
2024-02-28 15:03:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49709 | 172.67.136.238 | 443 | 1072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-28 15:03:05 UTC | 346 | OUT | |
2024-02-28 15:03:06 UTC | 627 | IN | |
2024-02-28 15:03:06 UTC | 171 | IN | |
2024-02-28 15:03:06 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49712 | 23.221.242.90 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-28 15:03:09 UTC | 161 | OUT | |
2024-02-28 15:03:09 UTC | 494 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49713 | 23.221.242.90 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-02-28 15:03:10 UTC | 239 | OUT | |
2024-02-28 15:03:10 UTC | 773 | IN | |
2024-02-28 15:03:10 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 16:02:58 |
Start date: | 28/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 16:03:01 |
Start date: | 28/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 16:03:03 |
Start date: | 28/02/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |