Windows
Analysis Report
https://www.uspnuh.top/
Overview
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 4668 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 5420 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2588 --fi eld-trial- handle=238 0,i,487354 6443396332 843,395681 1281058347 117,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 1628 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://www.u spnuh.top/ " MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
2% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cs1799.wpc.upsiloncdn.net | 152.195.33.23 | true | false | unknown | |
www.google.com | 142.250.72.164 | true | false | high | |
usps.com | 56.0.134.100 | true | false | high | |
www.uspnuh.top | 170.106.108.129 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false | unknown | |
www.usps.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
170.106.108.129 | www.uspnuh.top | Singapore | 132203 | TENCENT-NET-AP-CNTencentBuildingKejizhongyiAvenueCN | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
56.0.134.100 | usps.com | United States | 5774 | USPS-001US | false | |
142.250.72.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
152.195.33.23 | cs1799.wpc.upsiloncdn.net | United States | 15133 | EDGECASTUS | false |
IP |
---|
192.168.2.8 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1438909 |
Start date and time: | 2024-05-09 13:49:05 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 22s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://www.uspnuh.top/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@17/6@8/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.14.67, 142.250.68.110, 142.250.141.84, 34.104.35.123, 40.127.169.103, 192.229.211.108, 13.85.23.206, 20.3.187.198, 142.250.72.227
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
Input | Output |
---|---|
URL: https://www.usps.com/ | { "riskscore": 0, "reasons": "The text does not contain any suspicious links or phrases that urge users to click. It is related to access permission and mentions a reference number. There is no indication of phishing or malicious intent." }" |
You do not have permission to access this page If you have found this page in error: please contact supp01t Reference:9629401969202505916924097535545197174820034968299102359 | |
URL: https://www.usps.com/ | ```json { "riskscore": 0, "reasons": "The URL 'https://www.usps.com/' and the title 'usps.com' correctly match the official domain of the United States Postal Service without any alterations or typos." } |
URL: https://www.usps.com/ Title: usps.com |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9845693645625793 |
Encrypted: | false |
SSDEEP: | 48:8TJ0dHTfbTHVidAKZdA1oehwiZUklqehVy+3:8FMPy2y |
MD5: | 2B9EB57302DE10996D632E717E7C15D4 |
SHA1: | BCF3BFFFE10A58A6AE47E504EF98B50289EEF418 |
SHA-256: | F591578FC2D459413FD6A2619430D57A812038D0DC3E11A924EEB5C84F782925 |
SHA-512: | 8517D619A2A7E4C910473EDA6AC4144E945D2B743CC04789A96BDCA5FFC158897E84CFBFCDA882DFB32287EBCF50607B09E7BB44E4C565371FF9E1E6DF7FA29B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.0012938788943995 |
Encrypted: | false |
SSDEEP: | 48:8/0dHTfbTHVidAKZdA1leh/iZUkAQkqehmy+2:8/MPI9Qry |
MD5: | 1A236D2E33A5CBEB1E916196BF58197A |
SHA1: | 9DD121C731D51B1837C3F1E7F03C853B8C26F52E |
SHA-256: | A2562190505B9E266EB18F21A1E8CE29035AC9B5C41F185E0BCE748DAE19CF61 |
SHA-512: | 7F5155776FA2BF20993EC7B12FFDA4D8CE41F9B33C88CC0585519A94434D97875D472E028271918702BEFF793523DFEB4E25711127FCE19FCE44493783441020 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.0102453061498124 |
Encrypted: | false |
SSDEEP: | 48:8y0dHTfbbHVidAKZdA14t5eh7sFiZUkmgqeh7sMy+BX:8yMPYnyy |
MD5: | 1CA7C6D44308B2A8227E6A4CD6DEF140 |
SHA1: | 4A3B7D30D5F1910F6F37E0C9D37F797AADB12DB8 |
SHA-256: | 773D591254B67BBDF62200C55FCFA64F6647095DEEBD068B144A2D2FD2B441D0 |
SHA-512: | DAEF855B3536E0AFD889BDA52A2A37F2513EF4F1C5031081259159B7062B4412D905C644AA1686B7B7514A7BF2DFA079E363675C7DC0A98DA4B267109DE37F6A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.996579974986947 |
Encrypted: | false |
SSDEEP: | 48:82y0dHTfbTHVidAKZdA16ehDiZUkwqeh6y+R:8BMPjUy |
MD5: | 56921DB7053479AC385D8AB209A98F0C |
SHA1: | C81B4F53C0B4458554BAE2498971A33AE3CFD006 |
SHA-256: | 85E51F2A5E4F1383A0C1A4B2A29D861788C3BAB6CC6398D734E1AB7F1F2AD9B5 |
SHA-512: | B52624B73DC75B588A28088B9BB003314A7FA35B7A69730ADDAB06F5806694B8AA7625461410D0A5442F5B31512D3666D4568F87C2E01A938C6602ACBAD4DB5F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9895320269140346 |
Encrypted: | false |
SSDEEP: | 48:8H0dHTfbTHVidAKZdA1UehBiZUk1W1qeh4y+C:8HMPT9Yy |
MD5: | 2D89EAF1D874B9E7F3BB4B578DB34C16 |
SHA1: | D1B6FDF1156D3B724F89C1728141F413D6F34F2C |
SHA-256: | 92120754089380C1CFDB023BB826F828489E798DD4214F936FBED471ED97DBD3 |
SHA-512: | A88C47161B776EA4386CD872694692A4369B34F9A8FEBF808E2CA4BE48C56DD25938F8547AC8DDA979A474AFF03E5C092DDBD6D0995D40FAA33A3434FF5615B4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 4.0011665341862575 |
Encrypted: | false |
SSDEEP: | 48:8ET0dHTfbTHVidAKZdA1duTrehOuTbbiZUk5OjqehOuTbyy+yT+:8SMPcTYTbxWOvTbyy7T |
MD5: | 313936DBD767F93F00AEBB321850DC81 |
SHA1: | F78B42E867907AD9882C9DB53ED3E20C3A35E43C |
SHA-256: | FCB627994CA818803A87C0C49F20B9F144C080DF20DDF71EF333172B02640299 |
SHA-512: | BB6E60621360B6FC3512E738B8B0C53DB37DC276CA7C4688FCADB8D5151B3331B7860696F9113334987BF5B91BAEB5D036C8A2E0D771F2A30B7B95BE0384BBB7 |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 9, 2024 13:49:50.470884085 CEST | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
May 9, 2024 13:49:52.658400059 CEST | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:49:52.783364058 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:49:55.283382893 CEST | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
May 9, 2024 13:49:56.540957928 CEST | 49671 | 443 | 192.168.2.8 | 204.79.197.203 |
May 9, 2024 13:49:58.568754911 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.568804979 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.568883896 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.569370985 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.569400072 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.569457054 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.569644928 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.569657087 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.569822073 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.569837093 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.909729958 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.910167933 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.910180092 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.910315990 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.910593033 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.910604000 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.911242962 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.911326885 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.911669970 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.911732912 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.913201094 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.913263083 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.913460970 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.913466930 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.913695097 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.913757086 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.963593006 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:58.963604927 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:58.963663101 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:59.012306929 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:59.240021944 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:59.240120888 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:59.240175009 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:59.438590050 CEST | 49712 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:49:59.438616991 CEST | 443 | 49712 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:49:59.683902025 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:49:59.683938980 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:49:59.683995008 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:49:59.684561968 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:49:59.684576035 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.328697920 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.355323076 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:50:00.355334997 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.356512070 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.356606960 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:50:00.363893032 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:50:00.363957882 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.364403009 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:50:00.364408970 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.419717073 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:50:00.576107979 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.576175928 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.576495886 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:50:00.595412016 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:00.595448017 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:00.595527887 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:00.595720053 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:00.595735073 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:00.616641998 CEST | 49714 | 443 | 192.168.2.8 | 56.0.134.100 |
May 9, 2024 13:50:00.616676092 CEST | 443 | 49714 | 56.0.134.100 | 192.168.2.8 |
May 9, 2024 13:50:00.778472900 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:00.778511047 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:00.778582096 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:00.778793097 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:00.778804064 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:00.914674044 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:00.951941013 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:00.951951027 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:00.953131914 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:00.953269958 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:00.956470966 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:00.956537008 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:01.010693073 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:01.010701895 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:01.057431936 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:01.247104883 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.248003006 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:01.248018980 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.249025106 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.249082088 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:01.250864029 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:01.250922918 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.251351118 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:01.251358032 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.291913986 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:01.377341032 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:01.377373934 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.377449036 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:01.380450010 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:01.380465031 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.548608065 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.548732996 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.548832893 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:01.549295902 CEST | 49716 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:01.549314022 CEST | 443 | 49716 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:01.697220087 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.697309971 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:01.701453924 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:01.701462984 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.701750040 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.743424892 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:01.746505022 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:01.788130999 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.996489048 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.996557951 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:01.996722937 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.063570976 CEST | 49717 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.063592911 CEST | 443 | 49717 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.065943003 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.065985918 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.066046953 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.066602945 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.066621065 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.264271021 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.264302015 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.264494896 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.265616894 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.265633106 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.384130001 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:02.527981043 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.535847902 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.535897970 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.536350012 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.551994085 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.552108049 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.553070068 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.575932980 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.576035976 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.579355001 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.579361916 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.579659939 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.581176996 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.600121975 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.628123999 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.833462000 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.833563089 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.833770990 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.879491091 CEST | 49718 | 443 | 192.168.2.8 | 152.195.33.23 |
May 9, 2024 13:50:02.879527092 CEST | 443 | 49718 | 152.195.33.23 | 192.168.2.8 |
May 9, 2024 13:50:02.881489992 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.881584883 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:02.881900072 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.890594006 CEST | 49719 | 443 | 192.168.2.8 | 96.7.232.109 |
May 9, 2024 13:50:02.890605927 CEST | 443 | 49719 | 96.7.232.109 | 192.168.2.8 |
May 9, 2024 13:50:03.755170107 CEST | 443 | 49703 | 23.206.229.226 | 192.168.2.8 |
May 9, 2024 13:50:03.755770922 CEST | 49703 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:04.884979010 CEST | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
May 9, 2024 13:50:10.939385891 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:10.939455032 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:10.940735102 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:12.452526093 CEST | 49715 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:50:12.452550888 CEST | 443 | 49715 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:50:14.747935057 CEST | 49703 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:14.748122931 CEST | 49703 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:14.748379946 CEST | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:14.748416901 CEST | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
May 9, 2024 13:50:14.748661041 CEST | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:14.748895884 CEST | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:14.748908043 CEST | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
May 9, 2024 13:50:14.900682926 CEST | 443 | 49703 | 23.206.229.226 | 192.168.2.8 |
May 9, 2024 13:50:14.900701046 CEST | 443 | 49703 | 23.206.229.226 | 192.168.2.8 |
May 9, 2024 13:50:15.064158916 CEST | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
May 9, 2024 13:50:15.064301014 CEST | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:34.256282091 CEST | 443 | 49722 | 23.206.229.226 | 192.168.2.8 |
May 9, 2024 13:50:34.256388903 CEST | 49722 | 443 | 192.168.2.8 | 23.206.229.226 |
May 9, 2024 13:50:43.978890896 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:50:43.978902102 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:50:45.885312080 CEST | 49704 | 80 | 192.168.2.8 | 199.232.210.172 |
May 9, 2024 13:50:46.038779020 CEST | 80 | 49704 | 199.232.210.172 | 192.168.2.8 |
May 9, 2024 13:50:46.038798094 CEST | 80 | 49704 | 199.232.210.172 | 192.168.2.8 |
May 9, 2024 13:50:46.038857937 CEST | 49704 | 80 | 192.168.2.8 | 199.232.210.172 |
May 9, 2024 13:50:58.955604076 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:50:58.955693960 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:50:58.955981016 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:51:00.449407101 CEST | 49713 | 443 | 192.168.2.8 | 170.106.108.129 |
May 9, 2024 13:51:00.449425936 CEST | 443 | 49713 | 170.106.108.129 | 192.168.2.8 |
May 9, 2024 13:51:00.480062962 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:00.480108023 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:00.480179071 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:00.480447054 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:00.480468035 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:00.794246912 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:00.794524908 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:00.794549942 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:00.794883013 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:00.795661926 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:00.795727968 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:00.838200092 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:10.799947977 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:10.800019979 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
May 9, 2024 13:51:10.800383091 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:12.451123953 CEST | 49725 | 443 | 192.168.2.8 | 142.250.72.164 |
May 9, 2024 13:51:12.451160908 CEST | 443 | 49725 | 142.250.72.164 | 192.168.2.8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 9, 2024 13:49:56.026861906 CEST | 53 | 64020 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:49:56.316404104 CEST | 53 | 52927 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:49:57.325794935 CEST | 53 | 57585 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:49:57.879967928 CEST | 61266 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:49:57.880207062 CEST | 52651 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:49:58.451083899 CEST | 53 | 52651 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:49:58.567840099 CEST | 53 | 61266 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:49:59.491146088 CEST | 50111 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:49:59.491727114 CEST | 59613 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:49:59.646256924 CEST | 53 | 50111 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:49:59.705852032 CEST | 53 | 59613 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:00.430587053 CEST | 57270 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:50:00.439342022 CEST | 52673 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:50:00.583861113 CEST | 53 | 57270 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:00.592564106 CEST | 53 | 52673 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:00.622642040 CEST | 61294 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:50:00.623200893 CEST | 51804 | 53 | 192.168.2.8 | 1.1.1.1 |
May 9, 2024 13:50:00.776612997 CEST | 53 | 61294 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:00.777049065 CEST | 53 | 51804 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:15.180519104 CEST | 53 | 58132 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:34.014897108 CEST | 53 | 60241 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:45.704056978 CEST | 138 | 138 | 192.168.2.8 | 192.168.2.255 |
May 9, 2024 13:50:55.800131083 CEST | 53 | 51205 | 1.1.1.1 | 192.168.2.8 |
May 9, 2024 13:50:56.902398109 CEST | 53 | 57496 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
May 9, 2024 13:49:59.705923080 CEST | 192.168.2.8 | 1.1.1.1 | c227 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
May 9, 2024 13:49:57.879967928 CEST | 192.168.2.8 | 1.1.1.1 | 0x1e75 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 9, 2024 13:49:57.880207062 CEST | 192.168.2.8 | 1.1.1.1 | 0x7bad | Standard query (0) | 65 | IN (0x0001) | false | |
May 9, 2024 13:49:59.491146088 CEST | 192.168.2.8 | 1.1.1.1 | 0x8cda | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 9, 2024 13:49:59.491727114 CEST | 192.168.2.8 | 1.1.1.1 | 0x732a | Standard query (0) | 65 | IN (0x0001) | false | |
May 9, 2024 13:50:00.430587053 CEST | 192.168.2.8 | 1.1.1.1 | 0x4023 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 9, 2024 13:50:00.439342022 CEST | 192.168.2.8 | 1.1.1.1 | 0x6a91 | Standard query (0) | 65 | IN (0x0001) | false | |
May 9, 2024 13:50:00.622642040 CEST | 192.168.2.8 | 1.1.1.1 | 0x9759 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 9, 2024 13:50:00.623200893 CEST | 192.168.2.8 | 1.1.1.1 | 0x5913 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
May 9, 2024 13:49:58.567840099 CEST | 1.1.1.1 | 192.168.2.8 | 0x1e75 | No error (0) | 170.106.108.129 | A (IP address) | IN (0x0001) | false | ||
May 9, 2024 13:49:59.646256924 CEST | 1.1.1.1 | 192.168.2.8 | 0x8cda | No error (0) | 56.0.134.100 | A (IP address) | IN (0x0001) | false | ||
May 9, 2024 13:50:00.583861113 CEST | 1.1.1.1 | 192.168.2.8 | 0x4023 | No error (0) | 142.250.72.164 | A (IP address) | IN (0x0001) | false | ||
May 9, 2024 13:50:00.592564106 CEST | 1.1.1.1 | 192.168.2.8 | 0x6a91 | No error (0) | 65 | IN (0x0001) | false | |||
May 9, 2024 13:50:00.776612997 CEST | 1.1.1.1 | 192.168.2.8 | 0x9759 | No error (0) | cs1799.wpc.upsiloncdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
May 9, 2024 13:50:00.776612997 CEST | 1.1.1.1 | 192.168.2.8 | 0x9759 | No error (0) | 152.195.33.23 | A (IP address) | IN (0x0001) | false | ||
May 9, 2024 13:50:00.777049065 CEST | 1.1.1.1 | 192.168.2.8 | 0x5913 | No error (0) | cs1799.wpc.upsiloncdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
May 9, 2024 13:50:13.264095068 CEST | 1.1.1.1 | 192.168.2.8 | 0xeb10 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
May 9, 2024 13:50:13.264095068 CEST | 1.1.1.1 | 192.168.2.8 | 0xeb10 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
May 9, 2024 13:50:27.632087946 CEST | 1.1.1.1 | 192.168.2.8 | 0x1d50 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
May 9, 2024 13:50:27.632087946 CEST | 1.1.1.1 | 192.168.2.8 | 0x1d50 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
May 9, 2024 13:50:49.116628885 CEST | 1.1.1.1 | 192.168.2.8 | 0x59fa | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
May 9, 2024 13:50:49.116628885 CEST | 1.1.1.1 | 192.168.2.8 | 0x59fa | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
May 9, 2024 13:51:08.980696917 CEST | 1.1.1.1 | 192.168.2.8 | 0x161e | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
May 9, 2024 13:51:08.980696917 CEST | 1.1.1.1 | 192.168.2.8 | 0x161e | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49712 | 170.106.108.129 | 443 | 5420 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-09 11:49:58 UTC | 657 | OUT | |
2024-05-09 11:49:59 UTC | 403 | IN | |
2024-05-09 11:49:59 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49714 | 56.0.134.100 | 443 | 5420 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-09 11:50:00 UTC | 651 | OUT | |
2024-05-09 11:50:00 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49716 | 152.195.33.23 | 443 | 5420 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-09 11:50:01 UTC | 655 | OUT | |
2024-05-09 11:50:01 UTC | 473 | IN | |
2024-05-09 11:50:01 UTC | 155 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49717 | 96.7.232.109 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-09 11:50:01 UTC | 161 | OUT | |
2024-05-09 11:50:01 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49718 | 152.195.33.23 | 443 | 5420 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-09 11:50:02 UTC | 580 | OUT | |
2024-05-09 11:50:02 UTC | 486 | IN | |
2024-05-09 11:50:02 UTC | 157 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.8 | 49719 | 96.7.232.109 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-09 11:50:02 UTC | 239 | OUT | |
2024-05-09 11:50:02 UTC | 531 | IN | |
2024-05-09 11:50:02 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 13:49:51 |
Start date: | 09/05/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 13:49:54 |
Start date: | 09/05/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 13:49:56 |
Start date: | 09/05/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |