Windows
Analysis Report
https://na4.docusign.net/member/Images/email/docComplete-white.png
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 2924 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 2656 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2552 --fi eld-trial- handle=252 0,i,100911 7621075861 2625,83013 7809836549 5936,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6592 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://na4.d ocusign.ne t/member/I mages/emai l/docCompl ete-white. png" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 172.253.115.105 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown | |
na4.docusign.net | unknown | unknown | false | high | |
docucdn-a.akamaihd.net | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.253.115.105 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1416606 |
Start date and time: | 2024-03-27 17:00:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 26s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://na4.docusign.net/member/Images/email/docComplete-white.png |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@16/11@8/3 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe, SIHClient.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 172.253.62.94, 142 .251.167.84, 172.253.122.100, 172.253.122.101, 172.253.122.1 38, 172.253.122.139, 172.253.1 22.102, 172.253.122.113, 34.10 4.35.123, 162.248.184.189, 23. 62.230.95, 23.62.230.107, 23.2 21.227.106, 23.221.227.114, 72 .21.81.240, 52.165.165.26, 192 .229.211.108, 20.3.187.198, 52 .165.164.15, 23.207.202.57, 23 .207.202.49, 23.207.202.52, 23 .207.202.54, 23.207.202.47, 23 .207.202.51, 23.207.202.53, 23 .207.202.48, 23.207.202.46, 20 .114.59.183, 142.251.16.94, 40 .68.123.157 - Excluded domains from analysis
(whitelisted): slscr.update.m icrosoft.com, clientservices.g oogleapis.com, a767.dspw65.aka mai.net, wu.azureedge.net, a17 37.b.akamai.net, clients2.goog le.com, ocsp.digicert.com, ocs p.edge.digicert.com, bg.apr-52 dd2-0503.edgecastdns.net, cs11 .wpc.v0cdn.net, glb.cws.prod.d cat.dsp.trafficmanager.net, sl s.update.microsoft.com, hlb.ap r-52dd2-0.edgecastdns.net, upd ate.googleapis.com, glb.sls.pr od.dcat.dsp.trafficmanager.net , na4-se.docusign.net.akadns.n et, fs.microsoft.com, accounts .google.com, wu.ec.azureedge.n et, ctldl.windowsupdate.com, n a4.docusign.net.akadns.net, do cucdn-a.akamaihd.net.edgesuite .net, wu-bg-shim.trafficmanage r.net, fe3cr.delivery.mp.micro soft.com, download.windowsupda te.com.edgesuite.net, fe3.deli very.mp.microsoft.com, edgedl. me.gvt1.com, clients.l.google. com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: https:
//na4.docusign.net/member/Imag es/email/docComplete-white.png
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9867167542743527 |
Encrypted: | false |
SSDEEP: | 48:87d3lcTXlA6mHYidAKZdA19ehwiZUklqehQy+3:807Vvy |
MD5: | 72DF246C4433F34CDFF0FAAC6DC0BFD4 |
SHA1: | D91C5501112D93A7B41C26A2F8A8E38D7A3AA752 |
SHA-256: | E1BFE724755CC4230625EB5253A556B5E22454A0970049E01E4946AF372FDB90 |
SHA-512: | D61F78EADE1F1CA3353AFE70FE36DBAC93BFA52F001805FE2AD7D3C4023ED858E2E4A3D71B7DD1D537A87A77B08645CB1D73EC97F15B83AA12C7D1C554D9F3AA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.997580656550462 |
Encrypted: | false |
SSDEEP: | 48:8Nd3lcTXlA6mHYidAKZdA1weh/iZUkAQkqehfy+2:8K7P9QWy |
MD5: | 8EC3A4645C959533DAC16A0662ABD51D |
SHA1: | 33F8DEB9780C3F6085B87CC4FC8E993437D39204 |
SHA-256: | 3837AE21AA86E8484D76FC3B963BB89B5C38EDED1DD390F9A471296DE5A83E04 |
SHA-512: | 78956D73D8D0ADBEB016DAB94DB5233F88E4D551033C8D7B7108BD38FCA18C33BF327FB25C2914BA4F85A4C01B3EAD51290B557718A5B15C4ABB4DCBD0646016 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.012890493392665 |
Encrypted: | false |
SSDEEP: | 48:8xrd3lcTXlA6sHYidAKZdA14tseh7sFiZUkmgqeh7sVy+BX:8xk7Fnjy |
MD5: | 29469AC053DAE6535DA630B46EEA9E51 |
SHA1: | 584BAFCE78CB70E664ECEC8B1BBB3C87CC0986C8 |
SHA-256: | 6B296D0B5E0AE9C9A2DDA51ABEFD0F8ABDA2385CDF2F6038B60353D564985D3D |
SHA-512: | 6940A53D22F5DAA3BB83E874758CA9CC564AA7C4E81CD20C1E391360F18C6616E2BD595AC4C7179A9DAD956936601F4B915FCB761EB962BCF3DF7404FE7B7DE1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.999936983824267 |
Encrypted: | false |
SSDEEP: | 48:8Kd3lcTXlA6mHYidAKZdA1vehDiZUkwqehLy+R:877sdy |
MD5: | A07CC358D6C966FF057407D2FD3A2DF6 |
SHA1: | F1D61A3E6A7025F0C17AC3A27BB81B18637E3F8F |
SHA-256: | 46E240BEB3D19D2AA443565DA565118B34E1F9F14C5E8BE848920120B7993FAA |
SHA-512: | 46D058057ACFD2D812CC28086DA6D2C11BEC7082AD32383D793C0CCBDB3483EAFDA1A890ADE324D823A5A63F13339756528E664E0A82B91FDB517EC0F86333D0 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.98830887279278 |
Encrypted: | false |
SSDEEP: | 48:8Id3lcTXlA6mHYidAKZdA1hehBiZUk1W1qehJy+C:8N7c9py |
MD5: | 8FAD55C3F1990578ADD81102B2E73F6E |
SHA1: | 0963EB156B1D615057889423E8DC234803ADB2F1 |
SHA-256: | 1FBC3FE57C133F9F9994B826568EAA8B856E73AACBC55CA6C57351596E9BC654 |
SHA-512: | 959807D2E92A6C24919DB65CF77F3FA4523D2CE2BE78061F552F59E23ECEF31D75AE8A209112754E33A0BFD53F05128BBF4E93DADF317E9E3310A83F71B152B1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.997251512094763 |
Encrypted: | false |
SSDEEP: | 48:8xd3lcTXlA6mHYidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbjy+yT+:8G7yT/TbxWOvTbjy7T |
MD5: | 393D61A6CCBFFAF5320B181055297010 |
SHA1: | E4847A465F61B4FDEB86BD07DCDE173CB1F4E0B4 |
SHA-256: | C9D18A6F02D0BD20919D406AB936990440B04680A74FCE63791B3CBD88FEBF0F |
SHA-512: | 8A50C83B11B36EA3870799DB8A47FABB71585252D32378F030DCD656C43DF7BD9C0A6E392A02189C97AA70DAC8338AD54C906F6D3806DDECC59091FB2E2C4AAE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2402 |
Entropy (8bit): | 7.862596835662172 |
Encrypted: | false |
SSDEEP: | 48:iHXsMD3arszLQVAnhdp/GTQmHH/uN1K+KFS7V/opxSt:i8MT8mn+Qmn/VBI7VexSt |
MD5: | 8849EE4036C2DCF4950D1D8362EA8472 |
SHA1: | 8EE7F3E3421694CC08001B7ECF82A8D042D88ECA |
SHA-256: | 2908BAA07113961678495A0E34DDE17FDF5E3899BC49BF38B09195486DC5491D |
SHA-512: | 83C4F41AA30A45884B040779C044136AFA56615E1486DB4A61A589CA8AFF301E54CCE84E1C2D324FE49190A27792D1B101E9E349031B45B6D39B99F266AFBDD4 |
Malicious: | false |
Reputation: | low |
URL: | https://na4.docusign.net/member/Images/email/docComplete-white.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7405 |
Entropy (8bit): | 2.037697524051661 |
Encrypted: | false |
SSDEEP: | 24:J/EFEXke6Ivyxpl3GCHKlJgY29Y8GEpx5Bh60G3Z2D7GStiv:miXhFvyxpxqQ1hpx5Bojm |
MD5: | 888E04D5D5FF290D47BF73787F1E0BFC |
SHA1: | C8EDC4B60BB909C025B908F4ADBEEA557581687C |
SHA-256: | 387483B8C9FB9F677E0D72D066945675540FE417E6E6C70BAA9C013CB8FC88CD |
SHA-512: | 0662402C7EBC3D670D40EC55E5DC25C4360E54743517B783151F088A23FDCBE70803B4ED43BCE87D5B50908AC52AF4DEEDE6311445086E5CCFF98E2A82C0CB7A |
Malicious: | false |
Reputation: | low |
URL: | https://docucdn-a.akamaihd.net/olive/images/2.15.0/favicons/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7405 |
Entropy (8bit): | 2.037697524051661 |
Encrypted: | false |
SSDEEP: | 24:J/EFEXke6Ivyxpl3GCHKlJgY29Y8GEpx5Bh60G3Z2D7GStiv:miXhFvyxpxqQ1hpx5Bojm |
MD5: | 888E04D5D5FF290D47BF73787F1E0BFC |
SHA1: | C8EDC4B60BB909C025B908F4ADBEEA557581687C |
SHA-256: | 387483B8C9FB9F677E0D72D066945675540FE417E6E6C70BAA9C013CB8FC88CD |
SHA-512: | 0662402C7EBC3D670D40EC55E5DC25C4360E54743517B783151F088A23FDCBE70803B4ED43BCE87D5B50908AC52AF4DEEDE6311445086E5CCFF98E2A82C0CB7A |
Malicious: | false |
Reputation: | low |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 67
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 27, 2024 17:01:03.910341978 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:03.910342932 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:04.019721985 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:13.511102915 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:13.511104107 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:13.632015944 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:13.922575951 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:13.922615051 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:13.922732115 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:13.936559916 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:13.936580896 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:14.158148050 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:14.166101933 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:14.166120052 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:14.167185068 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:14.167325974 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:14.169523954 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:14.169588089 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:14.223670006 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:14.223691940 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:14.274102926 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:14.562016964 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:14.562048912 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:14.566211939 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:14.594022036 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:14.594037056 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:14.920939922 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:14.921046019 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:14.923592091 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:14.923604012 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:14.923862934 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:14.973658085 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:14.998742104 CET | 443 | 49705 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:14.998842955 CET | 49705 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:15.022079945 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.068245888 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.240716934 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.240787983 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.240849018 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.241065025 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.241080999 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.241102934 CET | 49721 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.241108894 CET | 443 | 49721 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.341006994 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.341058969 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.341137886 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.342112064 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.342133045 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.662966967 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.663036108 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.676035881 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.676049948 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.676335096 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.680929899 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:15.724239111 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.978327036 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.978399992 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:15.982680082 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:16.014252901 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:16.014296055 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:16.014328003 CET | 49722 | 443 | 192.168.2.5 | 23.56.8.114 |
Mar 27, 2024 17:01:16.014338970 CET | 443 | 49722 | 23.56.8.114 | 192.168.2.5 |
Mar 27, 2024 17:01:24.160093069 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:24.160161018 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:24.160257101 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:25.150755882 CET | 49705 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.150755882 CET | 49705 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.151571989 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.151618958 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.151829958 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.154133081 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.154154062 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.308546066 CET | 443 | 49705 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.308588028 CET | 443 | 49705 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.481374025 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.481504917 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.521868944 CET | 49719 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:01:25.521895885 CET | 443 | 49719 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:01:25.576009035 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.576030970 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.576494932 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.576769114 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.579660892 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.579660892 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.579699039 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.808936119 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.809221983 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.809237003 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.809454918 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.809585094 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.809648037 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:01:25.809712887 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.812470913 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.828013897 CET | 49725 | 443 | 192.168.2.5 | 23.1.237.91 |
Mar 27, 2024 17:01:25.828041077 CET | 443 | 49725 | 23.1.237.91 | 192.168.2.5 |
Mar 27, 2024 17:02:13.878668070 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:13.878696918 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:13.878815889 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:13.890662909 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:13.890676022 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:14.108803034 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:14.109402895 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:14.109416008 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:14.109762907 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:14.110384941 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:14.110455036 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:14.162498951 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:24.130791903 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:24.130867004 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Mar 27, 2024 17:02:24.130925894 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:25.511940002 CET | 49731 | 443 | 192.168.2.5 | 172.253.115.105 |
Mar 27, 2024 17:02:25.511960983 CET | 443 | 49731 | 172.253.115.105 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 27, 2024 17:01:09.434675932 CET | 53 | 63226 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:01:09.444544077 CET | 53 | 53375 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:01:10.056615114 CET | 53 | 59955 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:01:11.204161882 CET | 54591 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:11.204500914 CET | 49332 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:12.343403101 CET | 49326 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:12.343987942 CET | 56165 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:12.855660915 CET | 57884 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:12.856271982 CET | 61801 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:13.812159061 CET | 64039 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:13.812315941 CET | 52061 | 53 | 192.168.2.5 | 1.1.1.1 |
Mar 27, 2024 17:01:13.907176018 CET | 53 | 52061 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:01:13.907747984 CET | 53 | 64039 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:01:27.482450962 CET | 53 | 49990 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:01:46.603025913 CET | 53 | 59812 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:02:09.393852949 CET | 53 | 65199 | 1.1.1.1 | 192.168.2.5 |
Mar 27, 2024 17:02:09.402415037 CET | 53 | 56257 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Mar 27, 2024 17:01:11.338170052 CET | 192.168.2.5 | 1.1.1.1 | c264 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 27, 2024 17:01:11.204161882 CET | 192.168.2.5 | 1.1.1.1 | 0xbe17 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2024 17:01:11.204500914 CET | 192.168.2.5 | 1.1.1.1 | 0x6547 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 27, 2024 17:01:12.343403101 CET | 192.168.2.5 | 1.1.1.1 | 0xac8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2024 17:01:12.343987942 CET | 192.168.2.5 | 1.1.1.1 | 0x9b67 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 27, 2024 17:01:12.855660915 CET | 192.168.2.5 | 1.1.1.1 | 0x7ce7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2024 17:01:12.856271982 CET | 192.168.2.5 | 1.1.1.1 | 0xff69 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 27, 2024 17:01:13.812159061 CET | 192.168.2.5 | 1.1.1.1 | 0xe1b5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2024 17:01:13.812315941 CET | 192.168.2.5 | 1.1.1.1 | 0xddfd | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 27, 2024 17:01:11.302340031 CET | 1.1.1.1 | 192.168.2.5 | 0xbe17 | No error (0) | na4.docusign.net.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:11.338114023 CET | 1.1.1.1 | 192.168.2.5 | 0x6547 | No error (0) | na4.docusign.net.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:12.440392971 CET | 1.1.1.1 | 192.168.2.5 | 0xac8 | No error (0) | docucdn-a.akamaihd.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:12.440419912 CET | 1.1.1.1 | 192.168.2.5 | 0x9b67 | No error (0) | docucdn-a.akamaihd.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:12.951703072 CET | 1.1.1.1 | 192.168.2.5 | 0x7ce7 | No error (0) | docucdn-a.akamaihd.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:12.952105045 CET | 1.1.1.1 | 192.168.2.5 | 0xff69 | No error (0) | docucdn-a.akamaihd.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:13.907176018 CET | 1.1.1.1 | 192.168.2.5 | 0xddfd | No error (0) | 65 | IN (0x0001) | false | |||
Mar 27, 2024 17:01:13.907747984 CET | 1.1.1.1 | 192.168.2.5 | 0xe1b5 | No error (0) | 172.253.115.105 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:13.907747984 CET | 1.1.1.1 | 192.168.2.5 | 0xe1b5 | No error (0) | 172.253.115.103 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:13.907747984 CET | 1.1.1.1 | 192.168.2.5 | 0xe1b5 | No error (0) | 172.253.115.99 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:13.907747984 CET | 1.1.1.1 | 192.168.2.5 | 0xe1b5 | No error (0) | 172.253.115.104 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:13.907747984 CET | 1.1.1.1 | 192.168.2.5 | 0xe1b5 | No error (0) | 172.253.115.147 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:13.907747984 CET | 1.1.1.1 | 192.168.2.5 | 0xe1b5 | No error (0) | 172.253.115.106 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:24.871265888 CET | 1.1.1.1 | 192.168.2.5 | 0xd917 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 27, 2024 17:01:24.871265888 CET | 1.1.1.1 | 192.168.2.5 | 0xd917 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49721 | 23.56.8.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-27 16:01:15 UTC | 161 | OUT | |
2024-03-27 16:01:15 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49722 | 23.56.8.114 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-27 16:01:15 UTC | 239 | OUT | |
2024-03-27 16:01:15 UTC | 530 | IN | |
2024-03-27 16:01:15 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
2 | 192.168.2.5 | 49725 | 23.1.237.91 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-03-27 16:01:25 UTC | 2148 | OUT | |
2024-03-27 16:01:25 UTC | 1 | OUT | |
2024-03-27 16:01:25 UTC | 2483 | OUT | |
2024-03-27 16:01:25 UTC | 279 | IN | |
2024-03-27 16:01:25 UTC | 875 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 17:01:04 |
Start date: | 27/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 17:01:07 |
Start date: | 27/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 17:01:10 |
Start date: | 27/03/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |