Windows
Analysis Report
https://us-east-2.protection.sophos.com/?d=beehiiv.com&u=aHR0cHM6Ly9saW5rLm1haWwuYmVlaGlpdi5jb20vbHMvY2xpY2s_dXBuPXUwMDEublhka2JOSUpSeEZBS3VJWUJaMjU1N3l4Ujd6TmpDcFhIYW5SQnlyQXY3ZHMzMDZEQ091c3dBUU0yYzhiZFN4b1BudElFVWpoUzJhdzI1aDJUcWNiZVVCdXQ3WEhqcHZMejN4aS0yRnBZN2NYb3RNbXNIRlVyUkd5RDAzTGhIZms2a2E1ZGZ
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 6188 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3628 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2504 --fi eld-trial- handle=244 0,i,267577 6248829222 074,166979 2618325897 4734,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 3664 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://us-ea st-2.prote ction.soph os.com/?d= beehiiv.co m&u=aHR0cH M6Ly9saW5r Lm1haWwuYm VlaGlpdi5j b20vbHMvY2 xpY2s_dXBu PXUwMDEubl hka2JOSUpS eEZBS3VJWU JaMjU1N3l4 Ujd6TmpDcF hIYW5SQnly QXY3ZHMzMD ZEQ091c3dB UU0yYzhiZF N4b1BudElF VWpoUzJhdz I1aDJUcWNi ZVVCdXQ3WE hqcHZMejN4 aS0yRnBZN2 NYb3RNbXNI RlVyUkd5RD AzTGhIZms2 a2E1ZGZEVF pCSlVkWnpO andHYUJsR0 x3U1B4MlN1 TVNIWEl5Zl I3YVdDNW1a eFNQLTJCUW FOUmpzMlpw blRwbmxpLT JGX245c19s ZUtscWNRUn JvOGtNTXJo cHFZOENpeT Q4MnhLUmJT M1NZcE16TV UtMkY5c0Vv djNqMExCNE 1kOVZ3WUJv OEY2bEhJTl lZbE90LTJG cjRQd1FwOX dCVmFuUXpm Ry0yQnZlaF F5WVBjamlV bFpSN3VSaH JFbWFrLTJC YXY5T2RyYl dyREphTmo3 ck1iNmlhck R2Rjh1d2xP eDZ5VFY5OD FHLTJGejZi RDczakVOVH k4M0pXa2kz VzNTSzRBRU RwQjd3dEg4 blRyZ203Zj YxaEg2enlz YjFLYVl0S0 pyWUJjU2Qx NTN2SDQ5eD lTeW5acVZ0 TGdqN2RrWU 1FRkE1NzV6 WWF6b2UwQm w2UnVUM1RH TkJiU2JpOH hUNUFnRGJM UjY4TlU1ay 0yRmtDVFJt OHJrWWRMSD BNRGgtMkY3 c1J6dVE4TE JxeDBvQzZ6 WXVFQk0xRV FBdGI3eGxM ZVEtMkJ5SE tiOE4yVHV0 TFdpVEk4am c4b3U5MTkx RlM5SDEyLT JCbnJpT0hE SVo2Nk1yd3 pIeTRScFBQ WlAtMkJ0Y1 NscGt2Z01H T2F5Nmx6UG lCdE1MeGRr ODI5eGU3TT hFT1VLRDR2 UHIxZFdYZ3 c3MjFQQjFN a3k=&i=NWN iNGNiOGY1N WZlOGIxMTA wZmUxN2Uy& t=YUVvbWN0 aDQzMW4yV2 9uam9nK2tU NmU1dStvM2 VicUNJeENi WDR5Zk1nTT 0=&h=ddfea 45e1610491 898abc824d 1dabad5&s= AVNPUEhUT0 NFTkNSWVBU SVaKXvCVdm aYUeJ4sMCG gh9xhnT0RF 3qCfPvI6ci aUbnMg" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Phishing |
---|
Source: | LLM: |
Source: | Matcher: |
Source: | Matcher: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | HTTP traffic: | ||
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
d1nhsro6ypf0az.cloudfront.net | 18.172.153.4 | true | false | unknown | |
link.mail.beehiiv.com | 104.18.68.40 | true | false | unknown | |
www.google.com | 216.58.206.36 | true | false | unknown | |
aatfinancialservices.com | 66.70.176.204 | true | true | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown | |
us-east-2.protection.sophos.com | unknown | unknown | false | unknown | |
www.aatfinancialservices.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
true | unknown | ||
false |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
66.70.176.204 | aatfinancialservices.com | Canada | 16276 | OVHFR | true | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
18.172.153.4 | d1nhsro6ypf0az.cloudfront.net | United States | 3 | MIT-GATEWAYSUS | false | |
104.18.68.40 | link.mail.beehiiv.com | United States | 13335 | CLOUDFLARENETUS | false | |
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1466847 |
Start date and time: | 2024-07-03 14:04:00 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://us-east-2.protection.sophos.com/?d=beehiiv.com&u=aHR0cHM6Ly9saW5rLm1haWwuYmVlaGlpdi5jb20vbHMvY2xpY2s_dXBuPXUwMDEublhka2JOSUpSeEZBS3VJWUJaMjU1N3l4Ujd6TmpDcFhIYW5SQnlyQXY3ZHMzMDZEQ091c3dBUU0yYzhiZFN4b1BudElFVWpoUzJhdzI1aDJUcWNiZVVCdXQ3WEhqcHZMejN4aS0yRnBZN2NYb3RNbXNIRlVyUkd5RDAzTGhIZms2a2E1ZGZEVFpCSlVkWnpOandHYUJsR0x3U1B4MlN1TVNIWEl5ZlI3YVdDNW1aeFNQLTJCUWFOUmpzMlpwblRwbmxpLTJGX245c19sZUtscWNRUnJvOGtNTXJocHFZOENpeTQ4MnhLUmJTM1NZcE16TVUtMkY5c0VvdjNqMExCNE1kOVZ3WUJvOEY2bEhJTllZbE90LTJGcjRQd1FwOXdCVmFuUXpmRy0yQnZlaFF5WVBjamlVbFpSN3VSaHJFbWFrLTJCYXY5T2RyYldyREphTmo3ck1iNmlhckR2Rjh1d2xPeDZ5VFY5ODFHLTJGejZiRDczakVOVHk4M0pXa2kzVzNTSzRBRURwQjd3dEg4blRyZ203ZjYxaEg2enlzYjFLYVl0S0pyWUJjU2QxNTN2SDQ5eDlTeW5acVZ0TGdqN2RrWU1FRkE1NzV6WWF6b2UwQmw2UnVUM1RHTkJiU2JpOHhUNUFnRGJMUjY4TlU1ay0yRmtDVFJtOHJrWWRMSDBNRGgtMkY3c1J6dVE4TEJxeDBvQzZ6WXVFQk0xRVFBdGI3eGxMZVEtMkJ5SEtiOE4yVHV0TFdpVEk4amc4b3U5MTkxRlM5SDEyLTJCbnJpT0hESVo2Nk1yd3pIeTRScFBQWlAtMkJ0Y1NscGt2Z01HT2F5Nmx6UGlCdE1MeGRrODI5eGU3TThFT1VLRDR2UHIxZFdYZ3c3MjFQQjFNa3k=&i=NWNiNGNiOGY1NWZlOGIxMTAwZmUxN2Uy&t=YUVvbWN0aDQzMW4yV29uam9nK2tUNmU1dStvM2VicUNJeENiWDR5Zk1nTT0=&h=ddfea45e1610491898abc824d1dabad5&s=AVNPUEhUT0NFTkNSWVBUSVaKXvCVdmaYUeJ4sMCGgh9xhnT0RF3qCfPvI6ciaUbnMg |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal64.phis.win@17/11@12/6 |
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 216.58.212.142, 64.233.167.84, 172.217.18.99, 34.104.35.123, 40.68.123.157, 93.184.221.240, 192.229.221.95, 52.165.164.15, 20.166.126.56, 13.85.23.206, 13.95.31.18, 131.107.255.255, 142.250.185.195
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://us-east-2.protection.sophos.com/?d=beehiiv.com&u=aHR0cHM6Ly9saW5rLm1haWwuYmVlaGlpdi5jb20vbHMvY2xpY2s_dXBuPXUwMDEublhka2JOSUpSeEZBS3VJWUJaMjU1N3l4Ujd6TmpDcFhIYW5SQnlyQXY3ZHMzMDZEQ091c3dBUU0yYzhiZFN4b1BudElFVWpoUzJhdzI1aDJUcWNiZVVCdXQ3WEhqcHZMejN4aS0yRnBZN2NYb3RNbXNIRlVyUkd5RDAzTGhIZms2a2E1ZGZEVFpCSlVkWnpOandHYUJsR0x3U1B4MlN1TVNIWEl5ZlI3YVdDNW1aeFNQLTJCUWFOUmpzMlpwblRwbmxpLTJGX245c19sZUtscWNRUnJvOGtNTXJocHFZOENpeTQ4MnhLUmJTM1NZcE16TVUtMkY5c0VvdjNqMExCNE1kOVZ3WUJvOEY2bEhJTllZbE90LTJGcjRQd1FwOXdCVmFuUXpmRy0yQnZlaFF5WVBjamlVbFpSN3VSaHJFbWFrLTJCYXY5T2RyYldyREphTmo3ck1iNmlhckR2Rjh1d2xPeDZ5VFY5ODFHLTJGejZiRDczakVOVHk4M0pXa2kzVzNTSzRBRURwQjd3dEg4blRyZ203ZjYxaEg2enlzYjFLYVl0S0pyWUJjU2QxNTN2SDQ5eDlTeW5acVZ0TGdqN2RrWU1FRkE1NzV6WWF6b2UwQmw2UnVUM1RHTkJiU2JpOHhUNUFnRGJMUjY4TlU1ay0yRmtDVFJtOHJrWWRMSDBNRGgtMkY3c1J6dVE4TEJxeDBvQzZ6WXVFQk0xRVFBdGI3eGxMZVEtMkJ5SEtiOE4yVHV0TFdpVEk4amc4b3U5MTkxRlM5SDEyLTJCbnJpT0hESVo2Nk1yd3pIeTRScFBQWlAtMkJ0Y1NscGt2Z01HT2F5Nmx6UGlCdE1MeGRrODI5eGU3TThFT1VLRDR2UHIxZFd
Input | Output |
---|---|
URL: https://aatfinancialservices.com/ghan01122/?utm_source=hins-newsletter-3552d1.beehiiv.com&utm_medium=newsletter&utm_campaign=iuyi Model: Perplexity: mixtral-8x7b-instruct | {"loginform": false,"urgency": false,"captcha": true,"reasons": ["The webpage contains a CAPTCHA mechanism, which is a form of anti-robot detection.","The text does not create a sense of urgency, as it is related to a robot verification.","No login form was found on the webpage."]} |
Title: Security Verification OCR: Microsoft I am not a robot C) | |
URL: https://aatfinancialservices.com Model: gpt-4o | ```json{ "phishing_score": 9, "brands": "Microsoft", "phishing": true, "suspicious_domain": true, "has_prominent_loginform": false, "has_captcha": true, "setechniques": true, "has_suspicious_link": true, "legitmate_domain": "microsoft.com", "reasons": "The URL 'https://aatfinancialservices.com' does not match the legitimate domain for Microsoft, which is 'microsoft.com'. The page displays a CAPTCHA with the Microsoft logo, which is a common social engineering technique used in phishing attacks to gain user trust. The domain name 'aatfinancialservices.com' is unrelated to Microsoft, raising suspicion. The presence of a CAPTCHA alone is not inherently suspicious, but in this context, it appears to be used to mislead users. The combination of these factors strongly indicates that this is a phishing site."} |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9808738118741944 |
Encrypted: | false |
SSDEEP: | 48:8jd9Tlt8HRidAKZdA19ehwiZUklqehHy+3:8/vmoy |
MD5: | E1FFBC4484D4E635F5A9C60018F54E90 |
SHA1: | E7B9CFCB9AF8A959757ABDA397E59C796DEFE9B6 |
SHA-256: | 89741F5ABF8C8943E5C6ED1165521D99DDF76774F1F785DD68D3F77F6024A5DE |
SHA-512: | 3D5990B26E78AAD1FAA9FE6B9DBA5C0A54564A118EB81D16D652824734B9A35E34FDB444B3B49AC22C9544DDC504CE6461A0E490BBB091DB238271D97A22638F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9988047567929934 |
Encrypted: | false |
SSDEEP: | 48:8ud9Tlt8HRidAKZdA1weh/iZUkAQkqehYy+2:8kvk9Qdy |
MD5: | DB8F61DCF9BC7F90C6DDBEC629724E44 |
SHA1: | 9C29929B6803FA9031EA0B671FD649369F7608A7 |
SHA-256: | 021CC84A38057C5D2A0056A13DA057F9E00329735281C46DB9C9F47356FA29D1 |
SHA-512: | D4F958BB54D64FF93333AD82DB9208B493C070C453C411A76B2184507EF9FC6AE96019A2B6E0E9D34DB08397C73E7528EF0D6D8EE69861264754586ACD3CDA3B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.0080902257066375 |
Encrypted: | false |
SSDEEP: | 48:8x2d9TltsHRidAKZdA14tseh7sFiZUkmgqeh7s2y+BX:8x8vsnky |
MD5: | E32733ACB7351CDA57349DE2489492BB |
SHA1: | B6953300DF3F491ED43D51A314E19BABCFC5C69B |
SHA-256: | C806B7553E909587840486526F3111C0198E37D4BAB97A9D4A7EAAE94FD45101 |
SHA-512: | B233C00D5BACFC101F332DA9AD3BA66A17ABB474860E2D9F52208032E11F3C5DA9CC672402F466F384A05050110313EA4DEC327C2FA801BBFE210B777C8945B0 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.99578656667626 |
Encrypted: | false |
SSDEEP: | 48:8Hd9Tlt8HRidAKZdA1vehDiZUkwqehcy+R:8Tvvuy |
MD5: | 9D8C9AE41951ECEA4D357F25167CF2B4 |
SHA1: | C63F42524FDFE5A69BA5180A48D0ABE78C944965 |
SHA-256: | 6EBB5FD7FCEA49B39360CAE8BB950CEC50A057E858DD9FE8391991657A7F8739 |
SHA-512: | 6F7E51FD94916265B405839CB0E6D04D0FE49649DB91B626C3257145562704847364BF214AE33CC00C387098662980D2FA8CE68D433460C3691222E70675FA81 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9844499069332215 |
Encrypted: | false |
SSDEEP: | 48:85d9Tlt8HRidAKZdA1hehBiZUk1W1qehyy+C:8JvP9Sy |
MD5: | 5C68AC9838B0578B2BC767D273FDABE2 |
SHA1: | F9DA05C0BAD7CBCED2F063D3F989DDD1794384B2 |
SHA-256: | 66311C1A9DAA708C841DD7CBC3F21FB06178981C92E15AFCBECE332CA16F8B08 |
SHA-512: | 3262D8D8D5DAC80E29E5A6024E74FA0ABD4DE882A3DFA1870B8243491EDEABAED60A64CB145BCF8C9AD3B180E2B4FDEF98421C9ACB71F1F9E2F4D87609843306 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9950320590453408 |
Encrypted: | false |
SSDEEP: | 48:80d9Tlt8HRidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbky+yT+:8mvHT/TbxWOvTbky7T |
MD5: | FE5B89DBE079278A324715FD925E1505 |
SHA1: | 0D82FADD639DAB019ADB22234B249151868C8C2B |
SHA-256: | A9D9874680A0B2EE56DE9F408B78B6A326CC61EB0E80830FDD6F779200B023B2 |
SHA-512: | 62AB21D48A9E9D808DC16E722C1BC1A2667045B064C648BFB3FAA4D512E4F895AF0F72E431DC82937D609B2A49AA7082CE8416C1E94119059684ECB649F4B7AB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 809 |
Entropy (8bit): | 7.663299837754997 |
Encrypted: | false |
SSDEEP: | 24:2ne/Kw02Xir4MoizAhCXTYuBg9F6pFSFgPMCD1:2GzMoizAQt9bSFgV1 |
MD5: | 671FBA9A8BD618E3A78BA795ED8DDABA |
SHA1: | 067638A901F28A90CEE1D95599558CED0692C45A |
SHA-256: | 879565E64A6D2DC0DEDEF5E923FA2C6F4728C4081DA9CBECA2B20B3F36742C82 |
SHA-512: | FEE0322A7723F61AD6DE85F1317E8515BD11E330F6AAAE5E83C337F8D910ABAF1076D47241D60874CA86B6B78B33C29A2191A3CAD28C7BDEBC6E8ACF5311E7FA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 560212 |
Entropy (8bit): | 6.010281504487722 |
Encrypted: | false |
SSDEEP: | 12288:FVn3uQcb0NOJhrBnCyAbTlRT1nqZoT2eDKOrj3mjx7mbxwu/AXcXM:kba8+TlnV6It2jx7E7//M |
MD5: | 259E87A5DD21890E707257A577C6AEA1 |
SHA1: | C771FB39D260C727CBEC797E20C363A7024F2226 |
SHA-256: | 7703C9EE1F33F6DAFD36D8FC6FF491C05B396FC1F696036055176B128137AFF0 |
SHA-512: | 15A1983E07EE6C8E150DA0B65C952FD98F35BF0DB63580C64B3805BF03ED490B7E4F234BBDEF032B96D501B65D8D57717C6A400000824F8B9539ED3A430C465C |
Malicious: | false |
Reputation: | low |
URL: | https://aatfinancialservices.com/ghan01122/?utm_source=hins-newsletter-3552d1.beehiiv.com&utm_medium=newsletter&utm_campaign=iuyi |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 809 |
Entropy (8bit): | 7.663299837754997 |
Encrypted: | false |
SSDEEP: | 24:2ne/Kw02Xir4MoizAhCXTYuBg9F6pFSFgPMCD1:2GzMoizAQt9bSFgV1 |
MD5: | 671FBA9A8BD618E3A78BA795ED8DDABA |
SHA1: | 067638A901F28A90CEE1D95599558CED0692C45A |
SHA-256: | 879565E64A6D2DC0DEDEF5E923FA2C6F4728C4081DA9CBECA2B20B3F36742C82 |
SHA-512: | FEE0322A7723F61AD6DE85F1317E8515BD11E330F6AAAE5E83C337F8D910ABAF1076D47241D60874CA86B6B78B33C29A2191A3CAD28C7BDEBC6E8ACF5311E7FA |
Malicious: | false |
Reputation: | low |
URL: | https://www.aatfinancialservices.com/wp-content/uploads/2019/09/cropped-favicon-32x32.png |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 3, 2024 14:04:45.083293915 CEST | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jul 3, 2024 14:04:45.083295107 CEST | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jul 3, 2024 14:04:45.192671061 CEST | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jul 3, 2024 14:04:54.688647032 CEST | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jul 3, 2024 14:04:54.721237898 CEST | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jul 3, 2024 14:04:54.798028946 CEST | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jul 3, 2024 14:04:55.295756102 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.295809031 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.295875072 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.296466112 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.296474934 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.296542883 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.296891928 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.296909094 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.297086000 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.297097921 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.987860918 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.987910032 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.997070074 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.997091055 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.997503042 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.997510910 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.998068094 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.998123884 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:55.998508930 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:55.998564005 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.002178907 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.002243042 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:56.005702972 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.005769968 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:56.006201982 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.006211996 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:56.047849894 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.047868967 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:56.047883034 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.094711065 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.438318014 CEST | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jul 3, 2024 14:04:56.438426018 CEST | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jul 3, 2024 14:04:56.585846901 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:56.585927010 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:56.586112976 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.590141058 CEST | 49709 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:04:56.590173960 CEST | 443 | 49709 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:04:56.619497061 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:56.619538069 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:56.619683981 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:56.620170116 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:56.620184898 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.080100060 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.080363035 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:57.080403090 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.081384897 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.081450939 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:57.506841898 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:57.507016897 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.507164955 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:57.507191896 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.549738884 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:57.551714897 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:57.551757097 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:04:57.551815987 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:57.552206039 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:57.552220106 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:04:57.662585974 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.662692070 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.662769079 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:57.707022905 CEST | 49713 | 443 | 192.168.2.5 | 104.18.68.40 |
Jul 3, 2024 14:04:57.707045078 CEST | 443 | 49713 | 104.18.68.40 | 192.168.2.5 |
Jul 3, 2024 14:04:57.852679014 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:57.852720022 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:57.852855921 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:57.854928017 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:57.854942083 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:57.924499989 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:57.924540043 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:57.924861908 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:57.925175905 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:57.925192118 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.193717957 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:04:58.202850103 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:58.202868938 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:04:58.203844070 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:04:58.203931093 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:58.205527067 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:58.205598116 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:04:58.252834082 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:58.252845049 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:04:58.299444914 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:04:58.429794073 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.430474043 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:58.430490971 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.431484938 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.431543112 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:58.432694912 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:58.432758093 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.433265924 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:58.433276892 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.484523058 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.484626055 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.485161066 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:58.492847919 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.492861986 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.493107080 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.533395052 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.547260046 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.547319889 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.547461033 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:58.584919930 CEST | 49716 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:58.584949970 CEST | 443 | 49716 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:58.588860989 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.636497021 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.792167902 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.792260885 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.792330980 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.792397022 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.792413950 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.792432070 CEST | 49715 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.792438030 CEST | 443 | 49715 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.824337959 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.824366093 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:58.824532986 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.824825048 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:58.824837923 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.039622068 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.039670944 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.039884090 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.040096045 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.040111065 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.478971004 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.479067087 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:59.481019020 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:59.481029987 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.481285095 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.482848883 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:59.510176897 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.510648012 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.510667086 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.511024952 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.512356997 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.512412071 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.512950897 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.528496981 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.560492039 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.623065948 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.623087883 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.623152971 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.623168945 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.666208982 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.709712982 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.709723949 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.709816933 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.710068941 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.710128069 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.710998058 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.711085081 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.712493896 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.712568045 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.719182968 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.719257116 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.750087976 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.750154018 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.750247955 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:59.756850958 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:59.756874084 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.756892920 CEST | 49717 | 443 | 192.168.2.5 | 23.43.61.160 |
Jul 3, 2024 14:04:59.756900072 CEST | 443 | 49717 | 23.43.61.160 | 192.168.2.5 |
Jul 3, 2024 14:04:59.796552896 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.796616077 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.796925068 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.796998978 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.797758102 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.797818899 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.798629999 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.798695087 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.799529076 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.799598932 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.800342083 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.800415039 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.806291103 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.806369066 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.883138895 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.883215904 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.883407116 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.883476973 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.884087086 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.884160042 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.884680033 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.884737968 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.884924889 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.884998083 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.885693073 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.885754108 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.885878086 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.885934114 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.886682987 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.886745930 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.887404919 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.887470961 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.887708902 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.887769938 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.888555050 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.888621092 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.892817020 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.892875910 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.893095970 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.893153906 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.893376112 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.893443108 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.970320940 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.970402956 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.970501900 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.970556021 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.970789909 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.970859051 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.971249104 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.971303940 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.971612930 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.971663952 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.971672058 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.971678019 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.971714020 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.972034931 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.972101927 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.972440004 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.972491026 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.972501040 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.972505093 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.972536087 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.972551107 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.975378036 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.975445986 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.975765944 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.975832939 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.975838900 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.975895882 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.976022005 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.976085901 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.981293917 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.981353998 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.981514931 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.981594086 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:04:59.981781960 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:04:59.981848955 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.057076931 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.057168007 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.057216883 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.057281971 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.057442904 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.057503939 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.057847977 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.057914019 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.058104038 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.058151960 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.058182001 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.058188915 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.058223009 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.058242083 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.058629990 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.058696985 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.058979988 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.059048891 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.059303999 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.059350014 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.059376001 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.059381962 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.059408903 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.059427977 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.059926987 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.059973955 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.059981108 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.059988976 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.060046911 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.060451984 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.060640097 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.062833071 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.067815065 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.067898035 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.068130016 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.068197012 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.068447113 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.068511009 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.143764019 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.143827915 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.143997908 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.144064903 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.144210100 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.144284964 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.144668102 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.144707918 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.144728899 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.144737959 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.144778967 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.144789934 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.145180941 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.145263910 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.145270109 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.145279884 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.145318031 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.145338058 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.145770073 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.145828009 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.145999908 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.146054029 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.146184921 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.146240950 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.146598101 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.146652937 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.146657944 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.146697044 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.146742105 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.229073048 CEST | 49718 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.229108095 CEST | 443 | 49718 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.751207113 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.751238108 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:00.751307011 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.752454042 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:00.752466917 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:01.221379042 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:01.266577959 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:01.552355051 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:01.552373886 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:01.552825928 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:01.557140112 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:01.557216883 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:01.557835102 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:01.600505114 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:02.399382114 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:02.399985075 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:02.400026083 CEST | 443 | 49719 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:02.400093079 CEST | 49719 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:02.641935110 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:02.641968966 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:02.642051935 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:02.642301083 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:02.642314911 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.111717939 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.112169027 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.112191916 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.113301039 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.113385916 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.117616892 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.117682934 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.117813110 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.117821932 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.172832012 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.225838900 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.225990057 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.226212978 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.226526976 CEST | 49720 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.226546049 CEST | 443 | 49720 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.419934034 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.419960022 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.420110941 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.420480013 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.420492887 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.892242908 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.892550945 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.892565012 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.893574953 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.893656969 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.894068003 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.894123077 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.894263983 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.938958883 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:03.938966036 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:03.985888004 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:04.003756046 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:04.003825903 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:04.005290985 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:04.005578041 CEST | 49721 | 443 | 192.168.2.5 | 66.70.176.204 |
Jul 3, 2024 14:05:04.005588055 CEST | 443 | 49721 | 66.70.176.204 | 192.168.2.5 |
Jul 3, 2024 14:05:08.115849018 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:08.115919113 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:08.115963936 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:05:09.378757954 CEST | 49714 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:05:09.378798962 CEST | 443 | 49714 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:10.415158987 CEST | 60771 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:10.420154095 CEST | 53 | 60771 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:10.420217991 CEST | 60771 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:10.420264959 CEST | 60771 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:10.425154924 CEST | 53 | 60771 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:10.889221907 CEST | 53 | 60771 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:10.889945030 CEST | 60771 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:10.897464991 CEST | 53 | 60771 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:10.897521973 CEST | 60771 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:26.015393972 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:05:26.015481949 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:05:26.015602112 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:05:27.545665026 CEST | 49710 | 443 | 192.168.2.5 | 18.172.153.4 |
Jul 3, 2024 14:05:27.545703888 CEST | 443 | 49710 | 18.172.153.4 | 192.168.2.5 |
Jul 3, 2024 14:05:57.596813917 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:05:57.596847057 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:57.596926928 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:05:57.597196102 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:05:57.597208977 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:58.225924969 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:58.226300955 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:05:58.226339102 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:58.226759911 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:58.227364063 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:05:58.227432013 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:05:58.282751083 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:06:08.141401052 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:06:08.141472101 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Jul 3, 2024 14:06:08.141537905 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:06:09.381803989 CEST | 60774 | 443 | 192.168.2.5 | 216.58.206.36 |
Jul 3, 2024 14:06:09.381875038 CEST | 443 | 60774 | 216.58.206.36 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 3, 2024 14:04:53.136900902 CEST | 53 | 56647 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:53.219727993 CEST | 53 | 61699 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:54.198633909 CEST | 53 | 54000 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:55.276238918 CEST | 57116 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:55.276336908 CEST | 64239 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:55.284672976 CEST | 53 | 57116 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:55.302196980 CEST | 53 | 64239 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:56.600892067 CEST | 53134 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:56.601685047 CEST | 56276 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:56.608251095 CEST | 53 | 53134 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:56.618746042 CEST | 53 | 56276 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:57.541435957 CEST | 65166 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:57.541837931 CEST | 62688 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:57.548856020 CEST | 53 | 65166 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:57.548892975 CEST | 53 | 62688 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:57.711715937 CEST | 63542 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:57.712070942 CEST | 57709 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:04:57.910550117 CEST | 53 | 63542 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:04:57.923841000 CEST | 53 | 57709 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:02.404454947 CEST | 52745 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:02.404866934 CEST | 54522 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:02.596935034 CEST | 53 | 52745 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:02.694188118 CEST | 53 | 54522 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:03.231333971 CEST | 57506 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:03.231746912 CEST | 60288 | 53 | 192.168.2.5 | 1.1.1.1 |
Jul 3, 2024 14:05:03.241683006 CEST | 53 | 60288 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:03.419424057 CEST | 53 | 57506 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:10.414737940 CEST | 53 | 64147 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:11.510801077 CEST | 53 | 61281 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:30.558811903 CEST | 53 | 55793 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:52.817826986 CEST | 53 | 52555 | 1.1.1.1 | 192.168.2.5 |
Jul 3, 2024 14:05:53.427829027 CEST | 53 | 65466 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jul 3, 2024 14:04:55.302299023 CEST | 192.168.2.5 | 1.1.1.1 | c26f | (Port unreachable) | Destination Unreachable |
Jul 3, 2024 14:05:02.694250107 CEST | 192.168.2.5 | 1.1.1.1 | c24c | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jul 3, 2024 14:04:55.276238918 CEST | 192.168.2.5 | 1.1.1.1 | 0x96dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 3, 2024 14:04:55.276336908 CEST | 192.168.2.5 | 1.1.1.1 | 0xdc12 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 3, 2024 14:04:56.600892067 CEST | 192.168.2.5 | 1.1.1.1 | 0x681d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 3, 2024 14:04:56.601685047 CEST | 192.168.2.5 | 1.1.1.1 | 0xee65 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 3, 2024 14:04:57.541435957 CEST | 192.168.2.5 | 1.1.1.1 | 0xedc5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 3, 2024 14:04:57.541837931 CEST | 192.168.2.5 | 1.1.1.1 | 0xaa1c | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 3, 2024 14:04:57.711715937 CEST | 192.168.2.5 | 1.1.1.1 | 0x9c44 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 3, 2024 14:04:57.712070942 CEST | 192.168.2.5 | 1.1.1.1 | 0x8c29 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 3, 2024 14:05:02.404454947 CEST | 192.168.2.5 | 1.1.1.1 | 0xa194 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 3, 2024 14:05:02.404866934 CEST | 192.168.2.5 | 1.1.1.1 | 0x20aa | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 3, 2024 14:05:03.231333971 CEST | 192.168.2.5 | 1.1.1.1 | 0x23d7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 3, 2024 14:05:03.231746912 CEST | 192.168.2.5 | 1.1.1.1 | 0x316e | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jul 3, 2024 14:04:55.284672976 CEST | 1.1.1.1 | 192.168.2.5 | 0x96dc | No error (0) | d1nhsro6ypf0az.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:55.284672976 CEST | 1.1.1.1 | 192.168.2.5 | 0x96dc | No error (0) | 18.172.153.4 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:55.284672976 CEST | 1.1.1.1 | 192.168.2.5 | 0x96dc | No error (0) | 18.172.153.78 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:55.284672976 CEST | 1.1.1.1 | 192.168.2.5 | 0x96dc | No error (0) | 18.172.153.42 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:55.284672976 CEST | 1.1.1.1 | 192.168.2.5 | 0x96dc | No error (0) | 18.172.153.36 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:55.302196980 CEST | 1.1.1.1 | 192.168.2.5 | 0xdc12 | No error (0) | d1nhsro6ypf0az.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:56.608251095 CEST | 1.1.1.1 | 192.168.2.5 | 0x681d | No error (0) | 104.18.68.40 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:56.608251095 CEST | 1.1.1.1 | 192.168.2.5 | 0x681d | No error (0) | 104.18.69.40 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:56.618746042 CEST | 1.1.1.1 | 192.168.2.5 | 0xee65 | No error (0) | 65 | IN (0x0001) | false | |||
Jul 3, 2024 14:04:57.548856020 CEST | 1.1.1.1 | 192.168.2.5 | 0xedc5 | No error (0) | 216.58.206.36 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:04:57.548892975 CEST | 1.1.1.1 | 192.168.2.5 | 0xaa1c | No error (0) | 65 | IN (0x0001) | false | |||
Jul 3, 2024 14:04:57.910550117 CEST | 1.1.1.1 | 192.168.2.5 | 0x9c44 | No error (0) | 66.70.176.204 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:02.596935034 CEST | 1.1.1.1 | 192.168.2.5 | 0xa194 | No error (0) | aatfinancialservices.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:02.596935034 CEST | 1.1.1.1 | 192.168.2.5 | 0xa194 | No error (0) | 66.70.176.204 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:02.694188118 CEST | 1.1.1.1 | 192.168.2.5 | 0x20aa | No error (0) | aatfinancialservices.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:03.241683006 CEST | 1.1.1.1 | 192.168.2.5 | 0x316e | No error (0) | aatfinancialservices.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:03.419424057 CEST | 1.1.1.1 | 192.168.2.5 | 0x23d7 | No error (0) | aatfinancialservices.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:03.419424057 CEST | 1.1.1.1 | 192.168.2.5 | 0x23d7 | No error (0) | 66.70.176.204 | A (IP address) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:06.652587891 CEST | 1.1.1.1 | 192.168.2.5 | 0xacc1 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 3, 2024 14:05:06.652587891 CEST | 1.1.1.1 | 192.168.2.5 | 0xacc1 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49709 | 18.172.153.4 | 443 | 3628 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:04:56 UTC | 1853 | OUT | |
2024-07-03 12:04:56 UTC | 1315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49713 | 104.18.68.40 | 443 | 3628 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:04:57 UTC | 1353 | OUT | |
2024-07-03 12:04:57 UTC | 665 | IN | |
2024-07-03 12:04:57 UTC | 165 | IN | |
2024-07-03 12:04:57 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49716 | 66.70.176.204 | 443 | 3628 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:04:58 UTC | 762 | OUT | |
2024-07-03 12:04:58 UTC | 342 | IN | |
2024-07-03 12:04:58 UTC | 345 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49715 | 23.43.61.160 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:04:58 UTC | 161 | OUT | |
2024-07-03 12:04:58 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49717 | 23.43.61.160 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:04:59 UTC | 239 | OUT | |
2024-07-03 12:04:59 UTC | 535 | IN | |
2024-07-03 12:04:59 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49718 | 66.70.176.204 | 443 | 3628 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:04:59 UTC | 763 | OUT | |
2024-07-03 12:04:59 UTC | 270 | IN | |
2024-07-03 12:04:59 UTC | 7922 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN | |
2024-07-03 12:04:59 UTC | 8000 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49719 | 66.70.176.204 | 443 | 3628 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:05:01 UTC | 700 | OUT | |
2024-07-03 12:05:02 UTC | 395 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49720 | 66.70.176.204 | 443 | 3628 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:05:03 UTC | 647 | OUT | |
2024-07-03 12:05:03 UTC | 267 | IN | |
2024-07-03 12:05:03 UTC | 809 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49721 | 66.70.176.204 | 443 | 3628 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-03 12:05:03 UTC | 404 | OUT | |
2024-07-03 12:05:03 UTC | 267 | IN | |
2024-07-03 12:05:03 UTC | 809 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:04:45 |
Start date: | 03/07/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:04:51 |
Start date: | 03/07/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 08:04:54 |
Start date: | 03/07/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |