Windows
Analysis Report
https://manage.kmail-lists.com/subscriΡtions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6292 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) chrome.exe (PID: 5876 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2208 --fi eld-trial- handle=202 0,i,715856 5139567169 839,164958 2541672778 7881,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
chrome.exe (PID: 2420 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://manag e.kmail-li sts.com/su bscription s/subscrib e/update?c =01H0G3BVA 5P4WT38NKH 3DY6QEB&a= WkVYqE&p=e yJUaWNrZXR fb3B0IGluI jogIlllcyJ 9&k=53b9cf 0c5602fbaf f2d592c0e9 b9058a&r=h ttps%3A%2F %2Ftopfloo rlightands ound.com/c ho/amJ1cmt oYXJkdEBoa Wdod29vZG1 nbXQuY29t" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
topfloorlightandsound.com | 50.87.132.174 | true | false | unknown | |
www.google.com | 142.251.16.106 | true | false | high | |
manage.kmail-lists.com | 54.243.145.247 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
54.243.145.247 | manage.kmail-lists.com | United States | 14618 | AMAZON-AESUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
50.87.132.174 | topfloorlightandsound.com | United States | 46606 | UNIFIEDLAYER-AS-1US | false | |
142.251.16.106 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.6 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1416073 |
Start date and time: | 2024-03-26 20:33:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://manage.kmail-lists.com/subscriΡtions/subscribe/update?c=01H0G3BVA5P4WT38NKH3DY6QEB&a=WkVYqE&p=eyJUaWNrZXRfb3B0IGluIjogIlllcyJ9&k=53b9cf0c5602fbaff2d592c0e9b9058a&r=https%3A%2F%2Ftopfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | UNKNOWN |
Classification: | unknown0.win@17/4@6/5 |
EGA Information: | Failed |
HCA Information: |
|
- URL not reachable
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe, SIHClient.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 172.253.62.94, 142 .251.163.102, 142.251.163.139, 142.251.163.100, 142.251.163. 138, 142.251.163.101, 142.251. 163.113, 142.251.179.84, 34.10 4.35.123, 20.114.59.183, 72.21 .81.240, 192.229.211.108, 52.1 65.164.15, 13.85.23.206, 172.2 53.122.94 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, wu.ec.a zureedge.net, clientservices.g oogleapis.com, ctldl.windowsup date.com, wu-bg-shim.trafficma nager.net, wu.azureedge.net, f e3cr.delivery.mp.microsoft.com , fe3.delivery.mp.microsoft.co m, clients2.google.com, edgedl .me.gvt1.com, ocsp.digicert.co m, bg.apr-52dd2-0503.edgecastd ns.net, cs11.wpc.v0cdn.net, oc sp.edge.digicert.com, glb.cws. prod.dcat.dsp.trafficmanager.n et, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.ne t, update.googleapis.com, clie nts.l.google.com, glb.sls.prod .dcat.dsp.trafficmanager.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: https:
//manage.kmail-lists.com/subsc riptions/subscribe/update?c=01 H0G3BVA5P4WT38NKH3DY6QEB&a =WkVYqE&p=eyJUaWNrZXRfb3B0 IGluIjogIlllcyJ9&k=53b9cf0 c5602fbaff2d592c0e9b9058a& r=https%3A%2F%2Ftopfloorlighta ndsound.com/cho/amJ1cmtoYXJkdE BoaWdod29vZG1nbXQuY29t
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1539 |
Entropy (8bit): | 5.258450314188654 |
Encrypted: | false |
SSDEEP: | 24:aq5qwA0Sq5dyVrWum/MNYG+TcXTb2J6ciOg/y/b/T/noTMaA0tf3D:aeqh0h5dQKu7+TySarejLoFDf3D |
MD5: | 0A7DBE91D13815D631A35BCE7CD37500 |
SHA1: | 8DF4EC1687DEDDD602DA8F1BFB384967E9D7D1FA |
SHA-256: | 4394B97C6F9434F92221E19029FFBAD800B7CD8545BC9A0D50D0D156A0A114D1 |
SHA-512: | 3381798344DA9D3978701FC325A90957470EA476DA249BF185D2CCA96EFA7415319BA6EB6B9F724CDB72A2133B19194109B4DF2703FFA45E3D794C1D44BF9565 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1539 |
Entropy (8bit): | 5.258450314188654 |
Encrypted: | false |
SSDEEP: | 24:aq5qwA0Sq5dyVrWum/MNYG+TcXTb2J6ciOg/y/b/T/noTMaA0tf3D:aeqh0h5dQKu7+TySarejLoFDf3D |
MD5: | 0A7DBE91D13815D631A35BCE7CD37500 |
SHA1: | 8DF4EC1687DEDDD602DA8F1BFB384967E9D7D1FA |
SHA-256: | 4394B97C6F9434F92221E19029FFBAD800B7CD8545BC9A0D50D0D156A0A114D1 |
SHA-512: | 3381798344DA9D3978701FC325A90957470EA476DA249BF185D2CCA96EFA7415319BA6EB6B9F724CDB72A2133B19194109B4DF2703FFA45E3D794C1D44BF9565 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1539 |
Entropy (8bit): | 5.258450314188654 |
Encrypted: | false |
SSDEEP: | 24:aq5qwA0Sq5dyVrWum/MNYG+TcXTb2J6ciOg/y/b/T/noTMaA0tf3D:aeqh0h5dQKu7+TySarejLoFDf3D |
MD5: | 0A7DBE91D13815D631A35BCE7CD37500 |
SHA1: | 8DF4EC1687DEDDD602DA8F1BFB384967E9D7D1FA |
SHA-256: | 4394B97C6F9434F92221E19029FFBAD800B7CD8545BC9A0D50D0D156A0A114D1 |
SHA-512: | 3381798344DA9D3978701FC325A90957470EA476DA249BF185D2CCA96EFA7415319BA6EB6B9F724CDB72A2133B19194109B4DF2703FFA45E3D794C1D44BF9565 |
Malicious: | false |
Reputation: | low |
URL: | https://topfloorlightandsound.com/cho/amJ1cmtoYXJkdEBoaWdod29vZG1nbXQuY29t |
Preview: |
Icon Hash: | 00b29a8e86828200 |
Download Network PCAP: filtered – full
- Total Packets: 84
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2024 20:33:46.932794094 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Mar 26, 2024 20:33:46.932801962 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Mar 26, 2024 20:33:47.260936022 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Mar 26, 2024 20:33:52.830485106 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:52.830485106 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:52.830508947 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:52.830509901 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:52.830615044 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:52.830636978 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:52.830988884 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:52.830993891 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:52.831038952 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:52.831043959 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.139692068 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.139990091 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.140002012 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.141083002 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.141231060 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.142184019 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.142236948 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.142302990 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.142432928 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.142668009 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.142673969 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.143721104 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.143836021 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.144691944 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.144738913 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.184246063 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.184286118 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.184293985 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.230314970 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.230314970 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.230323076 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.260603905 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.260704041 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.260752916 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.261282921 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.261292934 CET | 443 | 49705 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:33:53.261302948 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.261332989 CET | 49705 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.277036905 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:33:53.402718067 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:53.402729034 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:53.402780056 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:53.403103113 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:53.403115034 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:53.774946928 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:53.775572062 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:53.775580883 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:53.776664972 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:53.776750088 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:53.778023005 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:53.778085947 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:53.778469086 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:53.778479099 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:53.819884062 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:54.137471914 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:54.137490988 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:54.137548923 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:54.137561083 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:54.137573004 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:54.137623072 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:54.186587095 CET | 49706 | 443 | 192.168.2.6 | 50.87.132.174 |
Mar 26, 2024 20:33:54.186595917 CET | 443 | 49706 | 50.87.132.174 | 192.168.2.6 |
Mar 26, 2024 20:33:55.498197079 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:55.498219013 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:33:55.498287916 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:55.498651981 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:55.498661995 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:33:55.719331980 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:33:55.719686985 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:55.719696999 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:33:55.720732927 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:33:55.720792055 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:55.723428011 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:55.723495007 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:33:55.775115967 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:55.775121927 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:33:55.821985960 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:33:56.089385986 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.089406013 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.089623928 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.091597080 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.091609955 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.291438103 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.291518927 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.301887989 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.301892996 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.302153111 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.353233099 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.540524960 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.540724993 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Mar 26, 2024 20:33:56.540747881 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Mar 26, 2024 20:33:56.584239006 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.637366056 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.637433052 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.637532949 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.657617092 CET | 49710 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.657629967 CET | 443 | 49710 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.741986036 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.742013931 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.742100000 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.742850065 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.742862940 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.868861914 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Mar 26, 2024 20:33:56.944840908 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.944920063 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.948368073 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.948375940 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.948636055 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:56.951613903 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:56.992242098 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:57.140558958 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:57.140641928 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:57.140706062 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:57.143316031 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:57.143336058 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:57.143346071 CET | 49711 | 443 | 192.168.2.6 | 23.221.242.90 |
Mar 26, 2024 20:33:57.143352985 CET | 443 | 49711 | 23.221.242.90 | 192.168.2.6 |
Mar 26, 2024 20:33:58.306359053 CET | 443 | 49698 | 173.222.162.64 | 192.168.2.6 |
Mar 26, 2024 20:33:58.306463003 CET | 49698 | 443 | 192.168.2.6 | 173.222.162.64 |
Mar 26, 2024 20:34:05.749423027 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:05.749491930 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:05.749604940 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:34:07.668122053 CET | 49709 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:34:07.668140888 CET | 443 | 49709 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:38.236355066 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:34:38.236365080 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:34:53.678793907 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:34:53.678888083 CET | 443 | 49704 | 54.243.145.247 | 192.168.2.6 |
Mar 26, 2024 20:34:53.679053068 CET | 49704 | 443 | 192.168.2.6 | 54.243.145.247 |
Mar 26, 2024 20:34:55.449345112 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:34:55.449385881 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:55.449460030 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:34:55.449765921 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:34:55.449781895 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:55.656337976 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:55.658194065 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:34:55.658224106 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:55.658575058 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:55.658953905 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:34:55.659022093 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:34:55.703691959 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:35:05.656207085 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:35:05.656284094 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Mar 26, 2024 20:35:05.656402111 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:35:05.678910017 CET | 49721 | 443 | 192.168.2.6 | 142.251.16.106 |
Mar 26, 2024 20:35:05.678930044 CET | 443 | 49721 | 142.251.16.106 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2024 20:33:51.525468111 CET | 53 | 60664 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:51.530858040 CET | 53 | 53689 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:52.718739033 CET | 55376 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 26, 2024 20:33:52.718969107 CET | 58671 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 26, 2024 20:33:52.814480066 CET | 53 | 55376 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:52.829386950 CET | 53 | 58671 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:53.049422026 CET | 53 | 53274 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:53.265662909 CET | 52852 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 26, 2024 20:33:53.265999079 CET | 62604 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 26, 2024 20:33:53.384975910 CET | 53 | 52852 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:53.402180910 CET | 53 | 62604 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:55.391053915 CET | 50646 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 26, 2024 20:33:55.391551971 CET | 50807 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 26, 2024 20:33:55.485965967 CET | 53 | 50646 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:33:55.486519098 CET | 53 | 50807 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:34:10.192095041 CET | 53 | 63737 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:34:29.052376986 CET | 53 | 50468 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:34:51.048151016 CET | 53 | 62729 | 1.1.1.1 | 192.168.2.6 |
Mar 26, 2024 20:34:51.904627085 CET | 53 | 56258 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 26, 2024 20:33:52.718739033 CET | 192.168.2.6 | 1.1.1.1 | 0x2f4e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2024 20:33:52.718969107 CET | 192.168.2.6 | 1.1.1.1 | 0x39cf | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2024 20:33:53.265662909 CET | 192.168.2.6 | 1.1.1.1 | 0xc0f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2024 20:33:53.265999079 CET | 192.168.2.6 | 1.1.1.1 | 0x3815 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2024 20:33:55.391053915 CET | 192.168.2.6 | 1.1.1.1 | 0xa7fe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2024 20:33:55.391551971 CET | 192.168.2.6 | 1.1.1.1 | 0xe981 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 26, 2024 20:33:52.814480066 CET | 1.1.1.1 | 192.168.2.6 | 0x2f4e | No error (0) | 54.243.145.247 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:52.814480066 CET | 1.1.1.1 | 192.168.2.6 | 0x2f4e | No error (0) | 54.205.206.182 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:52.814480066 CET | 1.1.1.1 | 192.168.2.6 | 0x2f4e | No error (0) | 54.157.61.255 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:52.814480066 CET | 1.1.1.1 | 192.168.2.6 | 0x2f4e | No error (0) | 52.54.202.246 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:53.384975910 CET | 1.1.1.1 | 192.168.2.6 | 0xc0f4 | No error (0) | 50.87.132.174 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:55.485965967 CET | 1.1.1.1 | 192.168.2.6 | 0xa7fe | No error (0) | 142.251.16.106 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:55.485965967 CET | 1.1.1.1 | 192.168.2.6 | 0xa7fe | No error (0) | 142.251.16.99 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:55.485965967 CET | 1.1.1.1 | 192.168.2.6 | 0xa7fe | No error (0) | 142.251.16.103 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:55.485965967 CET | 1.1.1.1 | 192.168.2.6 | 0xa7fe | No error (0) | 142.251.16.104 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:55.485965967 CET | 1.1.1.1 | 192.168.2.6 | 0xa7fe | No error (0) | 142.251.16.105 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:55.485965967 CET | 1.1.1.1 | 192.168.2.6 | 0xa7fe | No error (0) | 142.251.16.147 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:33:55.486519098 CET | 1.1.1.1 | 192.168.2.6 | 0xe981 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 26, 2024 20:34:08.014354944 CET | 1.1.1.1 | 192.168.2.6 | 0x1fb1 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 26, 2024 20:34:08.014354944 CET | 1.1.1.1 | 192.168.2.6 | 0x1fb1 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:34:20.856930017 CET | 1.1.1.1 | 192.168.2.6 | 0xaf3b | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 26, 2024 20:34:20.856930017 CET | 1.1.1.1 | 192.168.2.6 | 0xaf3b | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:34:44.198652029 CET | 1.1.1.1 | 192.168.2.6 | 0x49cd | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 26, 2024 20:34:44.198652029 CET | 1.1.1.1 | 192.168.2.6 | 0x49cd | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2024 20:35:03.704185963 CET | 1.1.1.1 | 192.168.2.6 | 0x8f80 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 26, 2024 20:35:03.704185963 CET | 1.1.1.1 | 192.168.2.6 | 0x8f80 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49705 | 54.243.145.247 | 443 | 5876 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-26 19:33:53 UTC | 886 | OUT | |
2024-03-26 19:33:53 UTC | 487 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49706 | 50.87.132.174 | 443 | 5876 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-26 19:33:53 UTC | 708 | OUT | |
2024-03-26 19:33:54 UTC | 335 | IN | |
2024-03-26 19:33:54 UTC | 1539 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49710 | 23.221.242.90 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-26 19:33:56 UTC | 161 | OUT | |
2024-03-26 19:33:56 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49711 | 23.221.242.90 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-26 19:33:56 UTC | 239 | OUT | |
2024-03-26 19:33:57 UTC | 774 | IN | |
2024-03-26 19:33:57 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 20:33:46 |
Start date: | 26/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 20:33:49 |
Start date: | 26/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 20:33:51 |
Start date: | 26/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |