Windows
Analysis Report
https://tgbot.cyb3r.army/700975049/Instagram.com.html
Overview
General Information
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 4236 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) chrome.exe (PID: 4532 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2352 --fi eld-trial- handle=230 0,i,183932 8935745239 7223,95615 9246699364 5301,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
chrome.exe (PID: 4360 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://tgbot .cyb3r.arm y/70097504 9/Instagra m.com.html " MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
- • AV Detection
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: |
Source: | Virustotal: | Perma Link |
Source: | Virustotal: | Perma Link |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
16% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
tgbot.cyb3r.army | 66.29.146.75 | true | false |
| unknown |
www.google.com | 142.250.185.132 | true | false |
| unknown |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
66.29.146.75 | tgbot.cyb3r.army | United States | 19538 | ADVANTAGECOMUS | false | |
142.250.185.132 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.7 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1461165 |
Start date and time: | 2024-06-23 00:34:33 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://tgbot.cyb3r.army/700975049/Instagram.com.html |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal72.win@21/0@4/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, SIHClient.exe, Sgr mBroker.exe, MoUsoCoreWorker.e xe, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.185.131, 1 42.250.181.238, 142.251.168.84 , 34.104.35.123, 20.12.23.50, 93.184.221.240, 192.229.221.95 , 52.165.164.15, 20.166.126.56 , 13.85.23.206, 142.250.184.22 7, 131.107.255.255 - Excluded domains from analysis
(whitelisted): slscr.update.m icrosoft.com, clientservices.g oogleapis.com, time.windows.co m, wu.azureedge.net, dns.msftn csi.com, clients2.google.com, ocsp.digicert.com, bg.apr-52dd 2-0503.edgecastdns.net, cs11.w pc.v0cdn.net, ocsp.edge.digice rt.com, glb.cws.prod.dcat.dsp. trafficmanager.net, sls.update .microsoft.com, hlb.apr-52dd2- 0.edgecastdns.net, update.goog leapis.com, wu-b-net.trafficma nager.net, glb.sls.prod.dcat.d sp.trafficmanager.net, fs.micr osoft.com, accounts.google.com , ctldl.windowsupdate.com.deli very.microsoft.com, wu.ec.azur eedge.net, ctldl.windowsupdate .com, fe3cr.delivery.mp.micros oft.com, fe3.delivery.mp.micro soft.com, edgedl.me.gvt1.com, clients.l.google.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found.
Input | Output |
---|---|
URL: https://tgbot.cyb3r.army/700975049/Instagram.com.html Model: Perplexity: mixtral-8x7b-instruct | {"loginform": false,"urgency": false,"captcha": false,"reasons": ["The title and text of the webpage do not contain a login form, as there are no explicit requests for sensitive information such as passwords, email addresses, usernames, phone numbers, or credit card numbers.","The title and text of the webpage do not create a sense of urgency or interest, as there are no phrases that encourage the user to click a link or view a document.","The title and text of the webpage do not contain a CAPTCHA or any other anti-robot detection mechanism."]} |
Title: 404 Not Found OCR: 404 Not Found The resource requested could not be tound on this server' Proudly 1K)wered by LiteS'Eed Web Server Please advised that LiteSgE-ed Technologies Inc. is not a web hosting cornpany and, as such, has no contr(l over found on this site. |
Download Network PCAP: filtered – full
- Total Packets: 89
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 23, 2024 00:35:21.108740091 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Jun 23, 2024 00:35:21.429658890 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Jun 23, 2024 00:35:22.030347109 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Jun 23, 2024 00:35:23.233550072 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Jun 23, 2024 00:35:23.983443975 CEST | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Jun 23, 2024 00:35:23.983606100 CEST | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Jun 23, 2024 00:35:24.077291012 CEST | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Jun 23, 2024 00:35:25.639682055 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Jun 23, 2024 00:35:29.932148933 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Jun 23, 2024 00:35:30.365065098 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Jun 23, 2024 00:35:30.458265066 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Jun 23, 2024 00:35:31.171155930 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Jun 23, 2024 00:35:32.349463940 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:32.349493980 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:32.349546909 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:32.349728107 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:32.349817038 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:32.349883080 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:32.349921942 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:32.349939108 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:32.350147963 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:32.350188971 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:32.761607885 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Jun 23, 2024 00:35:33.023220062 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.023459911 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.023485899 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.024537086 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.024677992 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.025897980 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.025965929 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.026087046 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.026098967 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.030085087 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.030297041 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.030329943 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.031974077 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.032040119 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.032938957 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.033021927 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.170418978 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.170516968 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.170564890 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.248255014 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.248343945 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.248729944 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.250197887 CEST | 49706 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.250227928 CEST | 443 | 49706 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.370361090 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.383840084 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.424500942 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.544578075 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.544749975 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.545039892 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.596290112 CEST | 49707 | 443 | 192.168.2.7 | 66.29.146.75 |
Jun 23, 2024 00:35:33.596330881 CEST | 443 | 49707 | 66.29.146.75 | 192.168.2.7 |
Jun 23, 2024 00:35:33.671770096 CEST | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Jun 23, 2024 00:35:33.671807051 CEST | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Jun 23, 2024 00:35:33.764143944 CEST | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Jun 23, 2024 00:35:33.818752050 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:33.818794966 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:33.818864107 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:33.819194078 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:33.819215059 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:34.455389977 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:34.455676079 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:34.455707073 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:34.456975937 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:34.457050085 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:34.507280111 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:34.507464886 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:34.561636925 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:34.561680079 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:34.732312918 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:35.342252016 CEST | 443 | 49698 | 104.98.116.138 | 192.168.2.7 |
Jun 23, 2024 00:35:35.342369080 CEST | 49698 | 443 | 192.168.2.7 | 104.98.116.138 |
Jun 23, 2024 00:35:35.732476950 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:35.732537031 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:35.736273050 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:35.738481998 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:35.738498926 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:35.874089956 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Jun 23, 2024 00:35:36.550196886 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:36.550296068 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:36.581954956 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:36.581980944 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:36.582353115 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:36.624111891 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:36.755268097 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:36.800510883 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.096396923 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.096607924 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.096678972 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.096744061 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.096765041 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.096802950 CEST | 49711 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.096808910 CEST | 443 | 49711 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.164182901 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.164247036 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.164333105 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.165338993 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.165364027 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.798778057 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.798907042 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.801701069 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.801722050 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.802169085 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:37.804088116 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:37.844506979 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:38.064173937 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:38.064291000 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:38.064347982 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:38.065171003 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:38.065186977 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:38.065407991 CEST | 49712 | 443 | 192.168.2.7 | 2.19.244.127 |
Jun 23, 2024 00:35:38.065416098 CEST | 443 | 49712 | 2.19.244.127 | 192.168.2.7 |
Jun 23, 2024 00:35:40.061546087 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Jun 23, 2024 00:35:41.827162027 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Jun 23, 2024 00:35:44.354039907 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:44.354123116 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:44.354202032 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:45.058192968 CEST | 49710 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:35:45.058223963 CEST | 443 | 49710 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:35:52.742573023 CEST | 57532 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:52.747313023 CEST | 53 | 57532 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:52.747386932 CEST | 57532 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:52.748740911 CEST | 57532 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:52.753468037 CEST | 53 | 57532 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:53.220382929 CEST | 53 | 57532 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:53.221467972 CEST | 57532 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:53.226494074 CEST | 53 | 57532 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:53.226602077 CEST | 57532 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:53.734066010 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Jun 23, 2024 00:36:33.861231089 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:33.861284971 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:33.861356974 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:33.861792088 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:33.861809015 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:34.500003099 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:34.516158104 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:34.516179085 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:34.517384052 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:34.520757914 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:34.520981073 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:34.562273979 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:44.485165119 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:44.485239983 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Jun 23, 2024 00:36:44.485297918 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:45.510927916 CEST | 57537 | 443 | 192.168.2.7 | 142.250.185.132 |
Jun 23, 2024 00:36:45.510960102 CEST | 443 | 57537 | 142.250.185.132 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 23, 2024 00:35:29.999289036 CEST | 53 | 62684 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:30.582777023 CEST | 53 | 53402 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:31.617805958 CEST | 53 | 57886 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:32.338629007 CEST | 58606 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:32.338751078 CEST | 64416 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:32.347763062 CEST | 53 | 64416 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:32.348577976 CEST | 53 | 58606 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:33.804086924 CEST | 52590 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:33.804349899 CEST | 54951 | 53 | 192.168.2.7 | 1.1.1.1 |
Jun 23, 2024 00:35:33.810889006 CEST | 53 | 52590 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:33.811770916 CEST | 53 | 54951 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:35.906558037 CEST | 123 | 123 | 192.168.2.7 | 20.101.57.9 |
Jun 23, 2024 00:35:36.077714920 CEST | 123 | 123 | 20.101.57.9 | 192.168.2.7 |
Jun 23, 2024 00:35:48.696064949 CEST | 53 | 52473 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:35:52.741756916 CEST | 53 | 62683 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:36:29.574891090 CEST | 53 | 59064 | 1.1.1.1 | 192.168.2.7 |
Jun 23, 2024 00:36:30.154280901 CEST | 138 | 138 | 192.168.2.7 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jun 23, 2024 00:35:32.338629007 CEST | 192.168.2.7 | 1.1.1.1 | 0xdbf7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 23, 2024 00:35:32.338751078 CEST | 192.168.2.7 | 1.1.1.1 | 0xcada | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 23, 2024 00:35:33.804086924 CEST | 192.168.2.7 | 1.1.1.1 | 0x770a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 23, 2024 00:35:33.804349899 CEST | 192.168.2.7 | 1.1.1.1 | 0x312 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jun 23, 2024 00:35:32.348577976 CEST | 1.1.1.1 | 192.168.2.7 | 0xdbf7 | No error (0) | 66.29.146.75 | A (IP address) | IN (0x0001) | false | ||
Jun 23, 2024 00:35:33.810889006 CEST | 1.1.1.1 | 192.168.2.7 | 0x770a | No error (0) | 142.250.185.132 | A (IP address) | IN (0x0001) | false | ||
Jun 23, 2024 00:35:33.811770916 CEST | 1.1.1.1 | 192.168.2.7 | 0x312 | No error (0) | 65 | IN (0x0001) | false | |||
Jun 23, 2024 00:35:45.390578985 CEST | 1.1.1.1 | 192.168.2.7 | 0xf5f6 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 23, 2024 00:35:45.390578985 CEST | 1.1.1.1 | 192.168.2.7 | 0xf5f6 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.7 | 49699 | 34.117.186.192 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-22 22:35:20 UTC | 59 | OUT | |
2024-06-22 22:35:20 UTC | 513 | IN | |
2024-06-22 22:35:20 UTC | 319 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49706 | 66.29.146.75 | 443 | 4532 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-22 22:35:33 UTC | 687 | OUT | |
2024-06-22 22:35:33 UTC | 301 | IN | |
2024-06-22 22:35:33 UTC | 1251 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49707 | 66.29.146.75 | 443 | 4532 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-22 22:35:33 UTC | 616 | OUT | |
2024-06-22 22:35:33 UTC | 301 | IN | |
2024-06-22 22:35:33 UTC | 1251 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49711 | 2.19.244.127 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-22 22:35:36 UTC | 161 | OUT | |
2024-06-22 22:35:37 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49712 | 2.19.244.127 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-22 22:35:37 UTC | 239 | OUT | |
2024-06-22 22:35:38 UTC | 535 | IN | |
2024-06-22 22:35:38 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 18:35:25 |
Start date: | 22/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 18:35:28 |
Start date: | 22/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 11 |
Start time: | 18:35:31 |
Start date: | 22/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |