Windows
Analysis Report
http://nitehawk.hearst.io
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6188 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 1400 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2068 --fi eld-trial- handle=170 8,i,867525 0586546259 330,104204 5146891285 6152,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 4080 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://niteha wk.hearst. io" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
hearst-hdm.map.fastly.net | 151.101.192.155 | true | false | unknown | |
active.kubeprod.hearstapps.com | 44.195.126.102 | true | false | unknown | |
www.google.com | 216.58.206.36 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown | |
nitehawk.hearst.io | unknown | unknown | false | unknown | |
nitehawk.kubeprod.hearstapps.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | unknown | ||
false |
| unknown | |
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
151.101.192.155 | hearst-hdm.map.fastly.net | United States | 54113 | FASTLYUS | false | |
44.195.126.102 | active.kubeprod.hearstapps.com | United States | 14618 | AMAZON-AESUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1461728 |
Start date and time: | 2024-06-24 16:14:46 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://nitehawk.hearst.io |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@17/10@6/5 |
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe, SIHClient.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.74.195, 14 2.250.184.238, 74.125.206.84, 34.104.35.123, 40.127.169.103, 93.184.221.240, 192.229.221.9 5, 20.166.126.56, 20.3.187.198 , 142.250.185.67 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com.delivery.micr osoft.com, wu.ec.azureedge.net , clientservices.googleapis.co m, ctldl.windowsupdate.com, wu .azureedge.net, fe3cr.delivery .mp.microsoft.com, fe3.deliver y.mp.microsoft.com, clients2.g oogle.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52d d2-0503.edgecastdns.net, cs11. wpc.v0cdn.net, ocsp.edge.digic ert.com, glb.cws.prod.dcat.dsp .trafficmanager.net, sls.updat e.microsoft.com, hlb.apr-52dd2 -0.edgecastdns.net, update.goo gleapis.com, clients.l.google. com, wu-b-net.trafficmanager.n et, glb.sls.prod.dcat.dsp.traf ficmanager.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: http:/
/nitehawk.hearst.io
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9755188591924626 |
Encrypted: | false |
SSDEEP: | 48:8ld6TGmhHPidAKZdA19ehwiZUklqehNy+3:8C/vKy |
MD5: | F0E1867FC64052BA6C40C62D5A7C8A38 |
SHA1: | 05185504D5B8182EC4BCD2BA683258C3A38BEFDE |
SHA-256: | 3CB47BC26F93D89AFC27C66E3BCAC1210C9C04E832A61363BE063E3A86410413 |
SHA-512: | 6A891CEEFED84163E6A34EE3AA9E5624AA7F4C4C7FCD0A65CE7FF42FC8A7B91A128C461634DD3E48574CA09EA8F9156C3ADABF188D72E0DF4A0D93783C735F49 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9914934507469724 |
Encrypted: | false |
SSDEEP: | 48:84d6TGmhHPidAKZdA1weh/iZUkAQkqeh6y+2:8h/V9Q/y |
MD5: | 05CBB9F625944F2A6AEA29628197CF1D |
SHA1: | 29D84E15E9A819DC757C1521ED689DB21E7379E8 |
SHA-256: | B5A4A70E5CC0F97AB70EA0318A1433D4785A0F0B612E70DA5539AE504FE09CB9 |
SHA-512: | 704A3C61974C1EED5056E3CBCEF796312B869899D448BE3482C61B669129A7EACB608C999174DA68BC22A64D8DD8CD58EEAE5D587754C08A64BB29A54EFE8748 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.007708387170096 |
Encrypted: | false |
SSDEEP: | 48:8xnd6TGmsHPidAKZdA14tseh7sFiZUkmgqeh7s8y+BX:8xk/Cn2y |
MD5: | 0FA645E5621B3B6FAB4BFB5F5BC20CF4 |
SHA1: | 870C57B20DFD462AEFF5B8D71295E841F4906099 |
SHA-256: | 92E5FD638ADF8958A9CB1B9DFD35F19EA828104548996E377DCFAF1D7B0FF30B |
SHA-512: | ACB78A5E469167A57F48E05D3CF59FC6EA8C53A4355F80EF329E4ED0263EE31F564C98C1ECBEEFCDAA3540B526C46D0AF0ED5D48C385EEFAD2C36E339B436383 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9931937855599315 |
Encrypted: | false |
SSDEEP: | 48:8fnd6TGmhHPidAKZdA1vehDiZUkwqehOy+R:8c/20y |
MD5: | 13033390B6B3B249750F70420F59DBFE |
SHA1: | 85A24D0AEF3C0B177AACBBF9A01671F8553C7F5E |
SHA-256: | AEBCB29F45C407AAE7E9B5159296FDC0ECB72C087D977FD205D5361D6FC9F741 |
SHA-512: | D9628EBFDCE6E211E421AFBD1B14AC6349371FA3C460B86C1F04FE103810E591E4EAAF45B7C54845EAA4EAB1AE3C47B1F8CA2D26B2F29F64066E2AF42A69B76D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.982273984038782 |
Encrypted: | false |
SSDEEP: | 48:8Qd6TGmhHPidAKZdA1hehBiZUk1W1qehYy+C:8J/W94y |
MD5: | 07818BEB8CBADC42D3352B24B1084142 |
SHA1: | 53617B2673EFE165F84ACB012C95EDF9A17164C5 |
SHA-256: | C15BF9138F15F550B9BE5717B66B46ABC8AE6434A27B3B22082CD7221B929576 |
SHA-512: | DB971A351939226F6492645639BB8F65652A599BD9EDA8DA391C4436B74F8A1FA8F620022160CC448FEE57CD487846E27E1B4AB9D5ECD628F226D233E943F8BA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9933326992346005 |
Encrypted: | false |
SSDEEP: | 48:80d6TGmhHPidAKZdA1duT+ehOuTbbiZUk5OjqehOuTb2y+yT+:81/oT/TbxWOvTb2y7T |
MD5: | 4BBDF2CB657EABEE17DB109BAA78043F |
SHA1: | D2F267381200E0F13A57D09D497B98BD74F5BBDB |
SHA-256: | C8927B2AF0F9AFC5EC2A4BDAFD388568E44731AD8E91BD87CD6C207A84E3C680 |
SHA-512: | 3A22403B21DBAF3BF1B925E2B8FCE6001366285EBAD3BDC800029FF04AB90E8BB1001810D867CC61AB06BDC5198AE6FACC1FB81858F0FFAADC46A1EA9A651D3C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 26 |
Entropy (8bit): | 3.8731406795131327 |
Encrypted: | false |
SSDEEP: | 3:YRMMHRBOb4:YRxsb4 |
MD5: | 0524A55BABCA86072CB958F6D439458E |
SHA1: | E1204200556FA2866134BCBF852FD3B97C7BE3E1 |
SHA-256: | 086650F1F98ACC74306206F2F32FE38F6101711B9FFBAA8664559ED92931418D |
SHA-512: | 5476BF64CCBFE0D3ADE315EC4D151E65707EBEC711CA2D7C6251373BD2AA2443ADBBE0E1E369F7EDDF16D36A8E6399A746793ED8EE63B739A21CA560B1DFB900 |
Malicious: | false |
Reputation: | low |
URL: | https://nitehawk.kubeprod.hearstapps.com/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 26 |
Entropy (8bit): | 3.8731406795131327 |
Encrypted: | false |
SSDEEP: | 3:YRMMHRBOb4:YRxsb4 |
MD5: | 0524A55BABCA86072CB958F6D439458E |
SHA1: | E1204200556FA2866134BCBF852FD3B97C7BE3E1 |
SHA-256: | 086650F1F98ACC74306206F2F32FE38F6101711B9FFBAA8664559ED92931418D |
SHA-512: | 5476BF64CCBFE0D3ADE315EC4D151E65707EBEC711CA2D7C6251373BD2AA2443ADBBE0E1E369F7EDDF16D36A8E6399A746793ED8EE63B739A21CA560B1DFB900 |
Malicious: | false |
Reputation: | low |
URL: | https://nitehawk.kubeprod.hearstapps.com/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 69
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 24, 2024 16:15:36.303556919 CEST | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jun 24, 2024 16:15:36.319165945 CEST | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jun 24, 2024 16:15:36.397298098 CEST | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jun 24, 2024 16:15:44.752499104 CEST | 49710 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:15:44.752643108 CEST | 49711 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:15:44.760075092 CEST | 80 | 49710 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:15:44.760092974 CEST | 80 | 49711 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:15:44.760186911 CEST | 49710 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:15:44.760406971 CEST | 49711 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:15:44.760406971 CEST | 49711 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:15:44.767287016 CEST | 80 | 49711 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:15:45.218729019 CEST | 80 | 49711 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:15:45.219086885 CEST | 80 | 49711 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:15:45.219232082 CEST | 49711 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:15:45.219269991 CEST | 49711 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:15:45.224313021 CEST | 80 | 49711 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:15:45.254292965 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:45.254318953 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:45.254393101 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:45.254650116 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:45.254662991 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:45.915136099 CEST | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jun 24, 2024 16:15:45.932405949 CEST | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jun 24, 2024 16:15:45.945425034 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:45.962488890 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:45.962503910 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:45.966574907 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:45.966650009 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:45.971041918 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:45.971219063 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:45.971339941 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:45.971347094 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:45.997874022 CEST | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jun 24, 2024 16:15:46.018786907 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:46.321360111 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:46.321440935 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:46.321526051 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:46.323786020 CEST | 49712 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:46.323807955 CEST | 443 | 49712 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:46.434570074 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:46.434602976 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:46.434843063 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:46.434967041 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:46.434972048 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:46.929251909 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:46.975563049 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:47.274152994 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:47.274175882 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:47.274638891 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:47.275609970 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:47.275662899 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:47.277853012 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:47.308185101 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:47.308233023 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:47.308304071 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:47.308954954 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:47.308973074 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:47.320499897 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:47.389684916 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:47.389794111 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:47.390003920 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:47.402035952 CEST | 49715 | 443 | 192.168.2.5 | 44.195.126.102 |
Jun 24, 2024 16:15:47.402061939 CEST | 443 | 49715 | 44.195.126.102 | 192.168.2.5 |
Jun 24, 2024 16:15:47.702955961 CEST | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jun 24, 2024 16:15:47.703069925 CEST | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jun 24, 2024 16:15:47.955670118 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:47.958564997 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:47.958591938 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:47.959686041 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:47.959774017 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:47.968903065 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:47.969136000 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:48.023102045 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:48.023130894 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:48.070023060 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:48.382622004 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:48.382664919 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:48.382827044 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:48.463037968 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:48.463053942 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.103846073 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.103940964 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.107286930 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.107336998 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.107639074 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.148098946 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.152100086 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.192540884 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.377850056 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.377998114 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.378082037 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.391227961 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.391283989 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.391314983 CEST | 49717 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.391334057 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.517318964 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.517379045 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:49.517474890 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.518052101 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:49.518064976 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.252276897 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.252367020 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:50.254357100 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:50.254368067 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.254559040 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.257059097 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:50.300497055 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.530250072 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.530317068 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.530407906 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:50.531299114 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:50.531299114 CEST | 49718 | 443 | 192.168.2.5 | 184.28.90.27 |
Jun 24, 2024 16:15:50.531353951 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:50.531368971 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.5 |
Jun 24, 2024 16:15:57.877645016 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:57.877717972 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:15:57.877795935 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:59.701210022 CEST | 49716 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:15:59.701245070 CEST | 443 | 49716 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:29.773499966 CEST | 49710 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:16:29.780075073 CEST | 80 | 49710 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:16:45.701733112 CEST | 49710 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:16:45.707321882 CEST | 80 | 49710 | 151.101.192.155 | 192.168.2.5 |
Jun 24, 2024 16:16:45.707421064 CEST | 49710 | 80 | 192.168.2.5 | 151.101.192.155 |
Jun 24, 2024 16:16:47.091320038 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:47.091355085 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:47.091418028 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:47.092017889 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:47.092031956 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:47.748632908 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:47.748997927 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:47.749013901 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:47.750138044 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:47.750480890 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:47.750659943 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:47.805151939 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:57.647205114 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:57.647274017 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Jun 24, 2024 16:16:57.647332907 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:58.000695944 CEST | 49728 | 443 | 192.168.2.5 | 216.58.206.36 |
Jun 24, 2024 16:16:58.000726938 CEST | 443 | 49728 | 216.58.206.36 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 24, 2024 16:15:43.524121046 CEST | 53 | 54676 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:43.528377056 CEST | 53 | 51704 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:44.508158922 CEST | 53 | 59253 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:44.738449097 CEST | 60776 | 53 | 192.168.2.5 | 1.1.1.1 |
Jun 24, 2024 16:15:44.738625050 CEST | 50658 | 53 | 192.168.2.5 | 1.1.1.1 |
Jun 24, 2024 16:15:44.749250889 CEST | 53 | 60776 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:44.751491070 CEST | 53 | 50658 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:45.221234083 CEST | 61807 | 53 | 192.168.2.5 | 1.1.1.1 |
Jun 24, 2024 16:15:45.221376896 CEST | 53893 | 53 | 192.168.2.5 | 1.1.1.1 |
Jun 24, 2024 16:15:45.252815962 CEST | 53 | 53893 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:45.253501892 CEST | 53 | 61807 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:47.276741028 CEST | 60117 | 53 | 192.168.2.5 | 1.1.1.1 |
Jun 24, 2024 16:15:47.277085066 CEST | 59283 | 53 | 192.168.2.5 | 1.1.1.1 |
Jun 24, 2024 16:15:47.284291983 CEST | 53 | 60117 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:15:47.288853884 CEST | 53 | 59283 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:16:01.659128904 CEST | 53 | 59986 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:16:20.755568981 CEST | 53 | 56210 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:16:42.991791964 CEST | 53 | 54438 | 1.1.1.1 | 192.168.2.5 |
Jun 24, 2024 16:16:43.252811909 CEST | 53 | 64031 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jun 24, 2024 16:15:44.738449097 CEST | 192.168.2.5 | 1.1.1.1 | 0x602d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 24, 2024 16:15:44.738625050 CEST | 192.168.2.5 | 1.1.1.1 | 0x9089 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 24, 2024 16:15:45.221234083 CEST | 192.168.2.5 | 1.1.1.1 | 0xd8e2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 24, 2024 16:15:45.221376896 CEST | 192.168.2.5 | 1.1.1.1 | 0x620d | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 24, 2024 16:15:47.276741028 CEST | 192.168.2.5 | 1.1.1.1 | 0xd93a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 24, 2024 16:15:47.277085066 CEST | 192.168.2.5 | 1.1.1.1 | 0x99c3 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jun 24, 2024 16:15:44.749250889 CEST | 1.1.1.1 | 192.168.2.5 | 0x602d | No error (0) | hearst-hdm.map.fastly.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:44.749250889 CEST | 1.1.1.1 | 192.168.2.5 | 0x602d | No error (0) | 151.101.192.155 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:44.749250889 CEST | 1.1.1.1 | 192.168.2.5 | 0x602d | No error (0) | 151.101.0.155 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:44.749250889 CEST | 1.1.1.1 | 192.168.2.5 | 0x602d | No error (0) | 151.101.128.155 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:44.749250889 CEST | 1.1.1.1 | 192.168.2.5 | 0x602d | No error (0) | 151.101.64.155 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:44.751491070 CEST | 1.1.1.1 | 192.168.2.5 | 0x9089 | No error (0) | hearst-hdm.map.fastly.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:45.252815962 CEST | 1.1.1.1 | 192.168.2.5 | 0x620d | No error (0) | active.kubeprod.hearstapps.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:45.253501892 CEST | 1.1.1.1 | 192.168.2.5 | 0xd8e2 | No error (0) | active.kubeprod.hearstapps.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:45.253501892 CEST | 1.1.1.1 | 192.168.2.5 | 0xd8e2 | No error (0) | 44.195.126.102 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:45.253501892 CEST | 1.1.1.1 | 192.168.2.5 | 0xd8e2 | No error (0) | 52.4.25.6 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:45.253501892 CEST | 1.1.1.1 | 192.168.2.5 | 0xd8e2 | No error (0) | 54.165.188.248 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:47.284291983 CEST | 1.1.1.1 | 192.168.2.5 | 0xd93a | No error (0) | 216.58.206.36 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:47.288853884 CEST | 1.1.1.1 | 192.168.2.5 | 0x99c3 | No error (0) | 65 | IN (0x0001) | false | |||
Jun 24, 2024 16:15:58.285186052 CEST | 1.1.1.1 | 192.168.2.5 | 0xe7f0 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:15:58.285186052 CEST | 1.1.1.1 | 192.168.2.5 | 0xe7f0 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:16:11.752170086 CEST | 1.1.1.1 | 192.168.2.5 | 0xd6aa | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:16:11.752170086 CEST | 1.1.1.1 | 192.168.2.5 | 0xd6aa | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:16:35.906918049 CEST | 1.1.1.1 | 192.168.2.5 | 0xdd33 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:16:35.906918049 CEST | 1.1.1.1 | 192.168.2.5 | 0xdd33 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Jun 24, 2024 16:16:56.096399069 CEST | 1.1.1.1 | 192.168.2.5 | 0xab9b | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 24, 2024 16:16:56.096399069 CEST | 1.1.1.1 | 192.168.2.5 | 0xab9b | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49711 | 151.101.192.155 | 80 | 1400 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jun 24, 2024 16:15:44.760406971 CEST | 433 | OUT | |
Jun 24, 2024 16:15:45.218729019 CEST | 343 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49710 | 151.101.192.155 | 80 | 1400 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jun 24, 2024 16:16:29.773499966 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.5 | 49704 | 34.117.186.192 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-24 14:15:32 UTC | 59 | OUT | |
2024-06-24 14:15:32 UTC | 513 | IN | |
2024-06-24 14:15:32 UTC | 319 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49712 | 44.195.126.102 | 443 | 1400 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-24 14:15:45 UTC | 675 | OUT | |
2024-06-24 14:15:46 UTC | 149 | IN | |
2024-06-24 14:15:46 UTC | 26 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49715 | 44.195.126.102 | 443 | 1400 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-24 14:15:47 UTC | 620 | OUT | |
2024-06-24 14:15:47 UTC | 149 | IN | |
2024-06-24 14:15:47 UTC | 26 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49717 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-24 14:15:49 UTC | 161 | OUT | |
2024-06-24 14:15:49 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49718 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-24 14:15:50 UTC | 239 | OUT | |
2024-06-24 14:15:50 UTC | 514 | IN | |
2024-06-24 14:15:50 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 10:15:36 |
Start date: | 24/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 10:15:41 |
Start date: | 24/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 10:15:43 |
Start date: | 24/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |