Windows
Analysis Report
https://s3.us-west-1.amazonaws.com/icfpvotycoboovcrkxajhhrddjezxlx/icfpvotycoboovcrkxajhhrddjezxlx/2.html#un/25756_md/74/14867/2126/460/1158830
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 1996 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// s3.us-west -1.amazona ws.com/icf pvotycoboo vcrkxajhhr ddjezxlx/i cfpvotycob oovcrkxajh hrddjezxlx /2.html#un /25756_md/ 74/14867/2 126/460/11 58830 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 2532 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1852 --fi eld-trial- handle=197 6,i,118594 8985274113 8547,15136 6811265505 26584,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s3.us-west-1.amazonaws.com | 52.219.120.176 | true | false | high | |
www.google.com | 142.250.101.106 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.101.106 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
52.219.120.176 | s3.us-west-1.amazonaws.com | United States | 16509 | AMAZON-02US | false |
IP |
---|
192.168.2.17 |
192.168.2.16 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1406861 |
Start date and time: | 2024-03-11 17:29:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 33s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://s3.us-west-1.amazonaws.com/icfpvotycoboovcrkxajhhrddjezxlx/icfpvotycoboovcrkxajhhrddjezxlx/2.html#un/25756_md/74/14867/2126/460/1158830 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@14/10@4/5 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, SIHClient.exe, Sgr mBroker.exe, MoUsoCoreWorker.e xe, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.2.94, 142. 251.2.100, 142.251.2.139, 142. 251.2.138, 142.251.2.113, 142. 251.2.101, 142.251.2.102, 142. 251.2.84, 34.104.35.123, 23.1. 234.136, 142.250.101.102, 142. 250.101.139, 142.250.101.101, 142.250.101.100, 142.250.101.1 13, 142.250.101.138 - Excluded domains from analysis
(whitelisted): clients1.googl e.com, fs.microsoft.com, clien ts2.google.com, accounts.googl e.com, edgedl.me.gvt1.com, sls cr.update.microsoft.com, updat e.googleapis.com, ctldl.window supdate.com, clientservices.go ogleapis.com, clients.l.google .com, fe3cr.delivery.mp.micros oft.com - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: https:
//s3.us-west-1.amazonaws.com/i cfpvotycoboovcrkxajhhrddjezxlx /icfpvotycoboovcrkxajhhrddjezx lx/2.html#un/25756_md/74/14867 /2126/460/1158830
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9802778048999756 |
Encrypted: | false |
SSDEEP: | 48:8TddsTWaVH1OidAKZdA1FehwiZUklqehTy+3:8AHj8Iy |
MD5: | 814417B9A33D28C921D9C9D060AECEFD |
SHA1: | 8FC7882B0B1C4A0D4B563E136E8C1557F647E2B6 |
SHA-256: | 7D602E95E0AD80380261D96C2A67ACC2B7A879E99821DF23BFBEF79C69B96181 |
SHA-512: | 37DD45DC2EECE38D74E270D69EAABD75BE9C9B225EF7BEE42976A834C04554408E9A8A8799A0E6D7854E7D58E42E99C40985256D7191F3636315D77DE0798D47 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.999594206309279 |
Encrypted: | false |
SSDEEP: | 48:8BddsTWaVH1OidAKZdA1seh/iZUkAQkqeh4y+2:8uHjy9Q1y |
MD5: | DBB26DE057FF133EA521BA308E006946 |
SHA1: | 4CE0A7E93BB20BC4541441D7F38DECCD1F448E02 |
SHA-256: | 986ECA51B4FDFCB80050FBDCAD3BC39A09F030B16CEA40C55D0BA1B4FB4A4FCB |
SHA-512: | 95FD816CA93AE5A0B3E1776DDD2300A40A14235F425D91A338797110B0FFC52EAA3D77FE502ABFFD7FCC96A20A83F29EE7C92CBA72AF36C00D50172A2B897DF7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.006903944675847 |
Encrypted: | false |
SSDEEP: | 48:8oddsTWaAH1OidAKZdA14meh7sFiZUkmgqeh7s6y+BX:8NHgmnUy |
MD5: | 47FB0C443E57F3EA1482DC304761DB41 |
SHA1: | 639BF1F82439B29834429B41B569C6A5F68D434A |
SHA-256: | 4D3A95D83F214520B86A60BE0DA01B3280D9068E4E1B15918F2C95E7B98E2338 |
SHA-512: | 803627FCDE162DACA103CD922D8464821D078A08209FBCD52E314FE724BBF6BE2301FB309C4101F1286866A3CCE4BAF42EF3F8BFA47413E2D810AF383C3FBDBF |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.996395344014088 |
Encrypted: | false |
SSDEEP: | 48:8FddsTWaVH1OidAKZdA1TehDiZUkwqeh8y+R:8yHjpCy |
MD5: | 21ACD59D05337C3073D997759AA2FA7B |
SHA1: | 1546F725A2394843FC8120F745601509358929D3 |
SHA-256: | 084905028B37B76545D55833387BFAF34F25C5A966D2CC33B58C12533F0D645E |
SHA-512: | 3528E80CB453C4E7DAA3645AFA1A102C87AA82EFF5287AAC6D2F76FAD7C335369516568B90E7A0B7757D65CB5FC8CC2264C06831B8C7464A5EEC8FE7A4C1E78B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9848188207531643 |
Encrypted: | false |
SSDEEP: | 48:8tddsTWaVH1OidAKZdA1dehBiZUk1W1qehGy+C:8KHj59my |
MD5: | 208F267915BBC994C3631B67A32EFAA6 |
SHA1: | 3DE051E4427471FB6987B1535B56B2F8EC722713 |
SHA-256: | 1E872AA1FCA4AEC346289DB752E6934CBC1AF57C5431561A49A9BCE34A387141 |
SHA-512: | 2B57084416A6A3FF29C290F77CF1FA1D29DF974B957C3269461ACC7ED98F46F353351E9CF12D150AD4EB0DC4B681CACE71147DE7B816793DBC066B66C6F222C7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.996282593382576 |
Encrypted: | false |
SSDEEP: | 48:8IddsTWaVH1OidAKZdA1duTeehOuTbbiZUk5OjqehOuTbUy+yT+:8tHjBTfTbxWOvTbUy7T |
MD5: | A0C0D4E205B24E6165E6958CC8F090FA |
SHA1: | 88EB14A970AB180C0A6CB5FF4DB85DA569F4B985 |
SHA-256: | E7B87983F4351AEE9C508414973BDA84A256F2A6B5819ADBBEDF49CD56068A27 |
SHA-512: | 133A18F7246FE4F68A47B2F2780884703FBC8FED474AB2246FE887438076817191CB807F1C298A26512C91F719CEB2D55C95A9E2A086AE7E331DE4A35AE96310 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 278 |
Entropy (8bit): | 5.599020080745099 |
Encrypted: | false |
SSDEEP: | 6:TMVBd/ZbZjtkLRWHtouHjBWlQjhU7vRnCG8eEM8ZIJZKUan:TMHd9BtkRWHt3BWZ9Crecg0Ua |
MD5: | 75A9F96A59F1708A607D1A51DC07E818 |
SHA1: | 74FCB36E2910D0511393071BC857A7BB94AAC7B1 |
SHA-256: | 7AD9433F90ED9B2D29F390ADD91462FAA3710B45825E8C98B7F133E44E4E692E |
SHA-512: | 25433E0705017D3D723637F1B5FA9AA77B5B5F033C6660D112458F6E899A8123BF4AF1B536B2C46E51FE6F81FBB6A9303124D5D36EE3B3814C3605FF8DF1899D |
Malicious: | false |
Reputation: | low |
URL: | https://s3.us-west-1.amazonaws.com/icfpvotycoboovcrkxajhhrddjezxlx/icfpvotycoboovcrkxajhhrddjezxlx/2.html |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 243 |
Entropy (8bit): | 5.526266927761957 |
Encrypted: | false |
SSDEEP: | 6:TMVBd/ZbZjZvKtWRVzjX8SVRbsJOdh2bW8JCtan:TMHd9BZKtWR/vzgbWZta |
MD5: | 465A0B68CC504B3BDF8BBC283192291D |
SHA1: | C0B5B8559349D3DDA569BFAB04B51A7E28B1D8F0 |
SHA-256: | 2AA1A7885FCDCE75A5C0FD1CA206E87B7F1AC861915A6D52B31584005AAC8E2E |
SHA-512: | E739FCD801F384BEF76A21438C33CC9E404B770E98A5E160263143C9FC2CD8FD20E33CAB543B35C06C0F1EEA8B41B17ED789D67772B7FCD88C79B5BC73727544 |
Malicious: | false |
Reputation: | low |
URL: | https://s3.us-west-1.amazonaws.com/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 124
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 11, 2024 17:29:34.167711020 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.167733908 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.167784929 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.169064045 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.169157982 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.169255018 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.169433117 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.169449091 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.169986010 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.170037985 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.725513935 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.725811958 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.725876093 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.727034092 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.727128983 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.727207899 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.727518082 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.727531910 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.728102922 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.728195906 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.728317976 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.728339911 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.728441954 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.728507042 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.728879929 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.728933096 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.776760101 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.776813984 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.776829958 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.822726965 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.908109903 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.908252954 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.908438921 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.909285069 CET | 49700 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:34.909327030 CET | 443 | 49700 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:34.987987041 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:35.032232046 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:35.163589954 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:35.163861036 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:35.165725946 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:35.166028976 CET | 49698 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:29:35.166047096 CET | 443 | 49698 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:29:38.976756096 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:38.976793051 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:38.976867914 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:38.977240086 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:38.977264881 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:39.344417095 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:39.344713926 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:39.344727993 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:39.345737934 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:39.345817089 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:39.346932888 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:39.346993923 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:39.391721964 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:39.391730070 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:39.438711882 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:41.701323986 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 11, 2024 17:29:42.005889893 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 11, 2024 17:29:42.607748032 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 11, 2024 17:29:43.813757896 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 11, 2024 17:29:44.007390022 CET | 49688 | 443 | 192.168.2.16 | 23.43.51.134 |
Mar 11, 2024 17:29:46.224723101 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 11, 2024 17:29:48.187047005 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.187084913 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.187171936 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.189620972 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.189635038 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.533721924 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:48.533771992 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:48.533886909 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:48.536603928 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.536720991 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.536818027 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:48.536849022 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:48.541021109 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.541043997 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.541388035 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.585812092 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.601610899 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.648237944 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.860512018 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.860785007 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.860807896 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.860840082 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.860969067 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.861005068 CET | 443 | 49708 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.861074924 CET | 49708 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.909125090 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.909162998 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:48.909244061 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.909542084 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:48.909554005 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.245398045 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.245552063 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:49.246963024 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:49.246977091 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.247214079 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.248681068 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:49.296233892 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.374037027 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:49.374130964 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:49.374336004 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:49.473619938 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:49.473804951 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:49.476785898 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:49.476799965 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:49.477214098 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:49.528740883 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:49.575550079 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.586039066 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:49.624711990 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:49.624730110 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.624916077 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:49.624934912 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.624943018 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:49.625129938 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.625165939 CET | 443 | 49710 | 23.202.57.177 | 192.168.2.16 |
Mar 11, 2024 17:29:49.625219107 CET | 49710 | 443 | 192.168.2.16 | 23.202.57.177 |
Mar 11, 2024 17:29:49.628242970 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:49.865113974 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Mar 11, 2024 17:29:50.168823004 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Mar 11, 2024 17:29:50.218499899 CET | 49702 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:29:50.218530893 CET | 443 | 49702 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392476082 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392494917 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392503023 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392515898 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392522097 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392524958 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392589092 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.392615080 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392632961 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392633915 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.392673016 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.392678976 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392712116 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.392712116 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.392731905 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.392746925 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.414199114 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.414235115 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.414258003 CET | 49709 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:29:50.414267063 CET | 443 | 49709 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:29:50.774741888 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Mar 11, 2024 17:29:51.030749083 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 11, 2024 17:29:51.987739086 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Mar 11, 2024 17:29:54.335913897 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Mar 11, 2024 17:29:54.399723053 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Mar 11, 2024 17:29:54.639902115 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Mar 11, 2024 17:29:55.247767925 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Mar 11, 2024 17:29:56.461769104 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Mar 11, 2024 17:29:58.875809908 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Mar 11, 2024 17:29:59.210741043 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Mar 11, 2024 17:30:00.633764029 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 11, 2024 17:30:03.687761068 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Mar 11, 2024 17:30:08.819731951 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Mar 11, 2024 17:30:13.300753117 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Mar 11, 2024 17:30:15.879771948 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:15.879801989 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:15.879908085 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:15.880237103 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:15.880263090 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:15.880445957 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:15.880933046 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:15.880949974 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:15.881452084 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:15.881459951 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.456450939 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.456959009 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.456970930 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.457364082 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.457736969 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.457823992 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.457881927 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.458925009 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.459119081 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.459132910 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.459625959 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.459920883 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.459986925 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.500227928 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.501775026 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.635407925 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.635576963 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.635767937 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.636253119 CET | 49712 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.636272907 CET | 443 | 49712 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.658401966 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.704232931 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.832669973 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.832796097 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:16.832864046 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.833561897 CET | 49711 | 443 | 192.168.2.16 | 52.219.120.176 |
Mar 11, 2024 17:30:16.833580971 CET | 443 | 49711 | 52.219.120.176 | 192.168.2.16 |
Mar 11, 2024 17:30:26.854161978 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:26.854198933 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:26.854305983 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:26.854810953 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:26.854825020 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:27.765400887 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:27.765631914 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:27.766962051 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:27.766973019 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:27.767328978 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:27.769352913 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:27.812228918 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.654510021 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.654596090 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.654640913 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.654711962 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.654740095 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.654757977 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.654788971 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.654959917 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.655019999 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.655041933 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.655047894 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.655090094 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.655096054 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.655167103 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.655219078 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.659219980 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.659233093 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:28.659269094 CET | 49713 | 443 | 192.168.2.16 | 40.68.123.157 |
Mar 11, 2024 17:30:28.659274101 CET | 443 | 49713 | 40.68.123.157 | 192.168.2.16 |
Mar 11, 2024 17:30:38.874186993 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:38.874284029 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:38.874406099 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:38.874779940 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:38.874818087 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:39.242497921 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:39.242877007 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:39.242944956 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:39.243434906 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:39.243757010 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:39.243863106 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:39.288774967 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:49.249809980 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:49.249972105 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Mar 11, 2024 17:30:49.250155926 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:50.217736959 CET | 49715 | 443 | 192.168.2.16 | 142.250.101.106 |
Mar 11, 2024 17:30:50.217804909 CET | 443 | 49715 | 142.250.101.106 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 11, 2024 17:29:33.968429089 CET | 51160 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 11, 2024 17:29:33.968987942 CET | 60688 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 11, 2024 17:29:34.123948097 CET | 53 | 60688 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:29:34.152770042 CET | 53 | 53881 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:29:34.161465883 CET | 53 | 51160 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:29:34.165476084 CET | 53 | 55126 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:29:35.165684938 CET | 53 | 59631 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:29:38.819989920 CET | 53843 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 11, 2024 17:29:38.820247889 CET | 52711 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 11, 2024 17:29:38.975147963 CET | 53 | 52711 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:29:38.975181103 CET | 53 | 53843 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:29:52.240534067 CET | 53 | 65253 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:30:11.166006088 CET | 53 | 65294 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:30:33.487231970 CET | 53 | 59093 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:30:34.111373901 CET | 53 | 55109 | 1.1.1.1 | 192.168.2.16 |
Mar 11, 2024 17:30:46.035501003 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Mar 11, 2024 17:31:02.026192904 CET | 53 | 54714 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 11, 2024 17:29:33.968429089 CET | 192.168.2.16 | 1.1.1.1 | 0xbb33 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2024 17:29:33.968987942 CET | 192.168.2.16 | 1.1.1.1 | 0xe505 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 11, 2024 17:29:38.819989920 CET | 192.168.2.16 | 1.1.1.1 | 0x8d44 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 11, 2024 17:29:38.820247889 CET | 192.168.2.16 | 1.1.1.1 | 0xab0c | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.120.176 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.220.248 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.193.88 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.112.88 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.220.152 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.193.120 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.113.144 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:34.161465883 CET | 1.1.1.1 | 192.168.2.16 | 0xbb33 | No error (0) | 52.219.192.48 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:38.975147963 CET | 1.1.1.1 | 192.168.2.16 | 0xab0c | No error (0) | 65 | IN (0x0001) | false | |||
Mar 11, 2024 17:29:38.975181103 CET | 1.1.1.1 | 192.168.2.16 | 0x8d44 | No error (0) | 142.250.101.106 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:38.975181103 CET | 1.1.1.1 | 192.168.2.16 | 0x8d44 | No error (0) | 142.250.101.147 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:38.975181103 CET | 1.1.1.1 | 192.168.2.16 | 0x8d44 | No error (0) | 142.250.101.105 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:38.975181103 CET | 1.1.1.1 | 192.168.2.16 | 0x8d44 | No error (0) | 142.250.101.103 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:38.975181103 CET | 1.1.1.1 | 192.168.2.16 | 0x8d44 | No error (0) | 142.250.101.99 | A (IP address) | IN (0x0001) | false | ||
Mar 11, 2024 17:29:38.975181103 CET | 1.1.1.1 | 192.168.2.16 | 0x8d44 | No error (0) | 142.250.101.104 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49700 | 52.219.120.176 | 443 | 2532 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:29:34 UTC | 739 | OUT | |
2024-03-11 16:29:34 UTC | 285 | IN | |
2024-03-11 16:29:34 UTC | 290 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49698 | 52.219.120.176 | 443 | 2532 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:29:34 UTC | 678 | OUT | |
2024-03-11 16:29:35 UTC | 285 | IN | |
2024-03-11 16:29:35 UTC | 254 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49708 | 23.202.57.177 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:29:48 UTC | 161 | OUT | |
2024-03-11 16:29:48 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49710 | 23.202.57.177 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:29:49 UTC | 239 | OUT | |
2024-03-11 16:29:49 UTC | 520 | IN | |
2024-03-11 16:29:49 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49709 | 40.68.123.157 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:29:49 UTC | 306 | OUT | |
2024-03-11 16:29:50 UTC | 560 | IN | |
2024-03-11 16:29:50 UTC | 15824 | IN | |
2024-03-11 16:29:50 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49712 | 52.219.120.176 | 443 | 2532 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:30:16 UTC | 739 | OUT | |
2024-03-11 16:30:16 UTC | 285 | IN | |
2024-03-11 16:30:16 UTC | 285 | IN | |
2024-03-11 16:30:16 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49711 | 52.219.120.176 | 443 | 2532 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:30:16 UTC | 678 | OUT | |
2024-03-11 16:30:16 UTC | 285 | IN | |
2024-03-11 16:30:16 UTC | 254 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49713 | 40.68.123.157 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-11 16:30:27 UTC | 306 | OUT | |
2024-03-11 16:30:28 UTC | 560 | IN | |
2024-03-11 16:30:28 UTC | 15824 | IN | |
2024-03-11 16:30:28 UTC | 9633 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 17:29:32 |
Start date: | 11/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 17:29:32 |
Start date: | 11/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |