Windows
Analysis Report
https://dvmtp.r.ag.d.sendibm3.com/mk/un/sh/1t6AVsdYhqSR1o1yYHZUELgBUnazHr/j54QtPSXoIeR
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 4176 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3236 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2040 --fi eld-trial- handle=196 0,i,159261 7208819277 5073,14715 2943645624 04812,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6572 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://dvmtp .r.ag.d.se ndibm3.com /mk/un/sh/ 1t6AVsdYhq SR1o1yYHZU ELgBUnazHr /j54QtPSXo IeR" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
Phishing |
---|
Source: | LLM: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | unknown | |
r1.mailin.fr | 1.179.112.195 | true | false | unknown | |
www.google.com | 142.250.74.196 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown | |
dvmtp.r.ag.d.sendibm3.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
1.179.112.195 | r1.mailin.fr | Australia | 9723 | ISEEK-AS-APiseekCommunicationsPtyLtdAU | false | |
1.179.112.197 | unknown | Australia | 9723 | ISEEK-AS-APiseekCommunicationsPtyLtdAU | false | |
142.250.74.196 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1487427 |
Start date and time: | 2024-08-04 03:39:01 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://dvmtp.r.ag.d.sendibm3.com/mk/un/sh/1t6AVsdYhqSR1o1yYHZUELgBUnazHr/j54QtPSXoIeR |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.phis.win@21/2@6/5 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.99, 64.233.184.84, 142.250.184.238, 34.104.35.123, 13.85.23.86, 199.232.214.172, 192.229.221.95, 20.242.39.171, 52.165.164.15, 142.250.186.35
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1238 |
Entropy (8bit): | 5.369619985639332 |
Encrypted: | false |
SSDEEP: | 24:hMNmlhsTsft+0NzIhCnox3d+esOLo/Rc/57lY1z0Xl/UslYRXVQZNvH7:ImgIF7IhCnu3d+esOk/Rc/57lYeV/BYo |
MD5: | 721CE8C2FA127E87489BDE8560D9211B |
SHA1: | 2AC566454513C48A492352663F1C77642D67FA33 |
SHA-256: | 559B2767E2EB4478A7CC935CABFFF18B4D0F9F3DE82052180FD807BE842CB163 |
SHA-512: | 14C010A2BBC107B8B49391C926F00EF64D5B5219F4836678F8AE6C9A119F5FB8F75A255DD7FC963F1D8C7EC87657345982D0DAEF281B18401DE5C59B79FA923A |
Malicious: | false |
Reputation: | low |
URL: | https://dvmtp.r.ag.d.sendibm3.com/mk/un/sh/1t6AVsdYhqSR1o1yYHZUELgBUnazHr/j54QtPSXoIeR |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 4, 2024 03:39:51.348617077 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Aug 4, 2024 03:39:59.935694933 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:39:59.935741901 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:39:59.935857058 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:39:59.936033964 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:39:59.936045885 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:39:59.936105013 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:39:59.936335087 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:39:59.936348915 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:39:59.936553001 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:39:59.936561108 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.585305929 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.585551977 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.585566044 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.587204933 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.587379932 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.588197947 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.588296890 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.588408947 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.588417053 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.630352974 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.685134888 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.685419083 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.685432911 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.689004898 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.689611912 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.689939022 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.690103054 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.740343094 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.740355015 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.786761045 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.920412064 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.920698881 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.920854092 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.921220064 CEST | 49736 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:00.921241999 CEST | 443 | 49736 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:00.969233036 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:01.016505003 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:01.152458906 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:01.152662992 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:01.152712107 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:01.154201984 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:01.154226065 CEST | 443 | 49735 | 1.179.112.195 | 192.168.2.4 |
Aug 4, 2024 03:40:01.154236078 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:01.154264927 CEST | 49735 | 443 | 192.168.2.4 | 1.179.112.195 |
Aug 4, 2024 03:40:01.176408052 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.176513910 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:01.176592112 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.176789999 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.176836014 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:01.883259058 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:01.904234886 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.904304981 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:01.905862093 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:01.906035900 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.922643900 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.922775984 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.922846079 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:01.972901106 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:01.972939014 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:02.019685030 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:02.363327980 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:02.363468885 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:02.363535881 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:02.378479004 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:02.378560066 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:02.378670931 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:02.379112005 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:02.379188061 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:02.380937099 CEST | 49739 | 443 | 192.168.2.4 | 1.179.112.197 |
Aug 4, 2024 03:40:02.380985022 CEST | 443 | 49739 | 1.179.112.197 | 192.168.2.4 |
Aug 4, 2024 03:40:03.021930933 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:03.022778988 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:03.022838116 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:03.024466038 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:03.024540901 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:03.039391994 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:03.039622068 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:03.087181091 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:03.087239027 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:03.133860111 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:03.208085060 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:03.208167076 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:03.208276987 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:03.211509943 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:03.211586952 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:03.877661943 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:03.877846003 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:03.885320902 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:03.885371923 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:03.885801077 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:03.930857897 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:03.932460070 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:03.976545095 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:04.455104113 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:04.455172062 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:04.455401897 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:04.455543995 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:04.455583096 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:04.455622911 CEST | 49741 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:04.455637932 CEST | 443 | 49741 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:04.571136951 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:04.571218014 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:04.571305990 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:04.581764936 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:04.581836939 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.237025023 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.237133026 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:05.238967896 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:05.238996983 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.239356041 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.241251945 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:05.288544893 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.761497021 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.761584044 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.761682987 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:05.764070034 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:05.764157057 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:05.764200926 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Aug 4, 2024 03:40:05.764219046 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Aug 4, 2024 03:40:12.942982912 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:12.943167925 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:12.943358898 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:15.246296883 CEST | 49740 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:40:15.246357918 CEST | 443 | 49740 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:40:17.093651056 CEST | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Aug 4, 2024 03:40:17.099107027 CEST | 80 | 49723 | 199.232.210.172 | 192.168.2.4 |
Aug 4, 2024 03:40:17.099255085 CEST | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Aug 4, 2024 03:40:20.667685986 CEST | 64383 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:20.672552109 CEST | 53 | 64383 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:20.672616959 CEST | 64383 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:20.672665119 CEST | 64383 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:20.677454948 CEST | 53 | 64383 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:21.151849985 CEST | 53 | 64383 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:21.152503014 CEST | 64383 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:21.158083916 CEST | 53 | 64383 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:21.158142090 CEST | 64383 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:41:02.101850986 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:02.101932049 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:02.102057934 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:02.102469921 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:02.102523088 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:02.738893032 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:02.739157915 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:02.739221096 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:02.740325928 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:02.740679979 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:02.740863085 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:02.787658930 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:03.396647930 CEST | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Aug 4, 2024 03:41:03.402228117 CEST | 80 | 49724 | 199.232.210.172 | 192.168.2.4 |
Aug 4, 2024 03:41:03.402295113 CEST | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Aug 4, 2024 03:41:12.666351080 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:12.666502953 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Aug 4, 2024 03:41:12.666655064 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:13.089838028 CEST | 64387 | 443 | 192.168.2.4 | 142.250.74.196 |
Aug 4, 2024 03:41:13.089903116 CEST | 443 | 64387 | 142.250.74.196 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 4, 2024 03:39:58.428823948 CEST | 53 | 57626 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:39:58.494916916 CEST | 53 | 61414 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:39:59.545485020 CEST | 53 | 62565 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:39:59.923176050 CEST | 64822 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:39:59.923508883 CEST | 49624 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:39:59.933777094 CEST | 53 | 49624 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:39:59.934987068 CEST | 53 | 64822 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:01.159549952 CEST | 52011 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:01.160847902 CEST | 49735 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:01.175090075 CEST | 53 | 49735 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:01.176004887 CEST | 53 | 52011 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:02.051129103 CEST | 55151 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:02.051667929 CEST | 51937 | 53 | 192.168.2.4 | 1.1.1.1 |
Aug 4, 2024 03:40:02.364628077 CEST | 53 | 55151 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:02.364639997 CEST | 53 | 51937 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:14.994611025 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Aug 4, 2024 03:40:16.612166882 CEST | 53 | 56888 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:20.667256117 CEST | 53 | 64485 | 1.1.1.1 | 192.168.2.4 |
Aug 4, 2024 03:40:58.062750101 CEST | 53 | 63346 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 4, 2024 03:39:59.923176050 CEST | 192.168.2.4 | 1.1.1.1 | 0x7877 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 4, 2024 03:39:59.923508883 CEST | 192.168.2.4 | 1.1.1.1 | 0xd9ee | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 4, 2024 03:40:01.159549952 CEST | 192.168.2.4 | 1.1.1.1 | 0xd276 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 4, 2024 03:40:01.160847902 CEST | 192.168.2.4 | 1.1.1.1 | 0xd446 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 4, 2024 03:40:02.051129103 CEST | 192.168.2.4 | 1.1.1.1 | 0x793e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 4, 2024 03:40:02.051667929 CEST | 192.168.2.4 | 1.1.1.1 | 0x2c5c | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 4, 2024 03:39:59.933777094 CEST | 1.1.1.1 | 192.168.2.4 | 0xd9ee | No error (0) | r.mailin.fr | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 4, 2024 03:39:59.934987068 CEST | 1.1.1.1 | 192.168.2.4 | 0x7877 | No error (0) | r.mailin.fr | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 4, 2024 03:39:59.934987068 CEST | 1.1.1.1 | 192.168.2.4 | 0x7877 | No error (0) | r1.mailin.fr | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 4, 2024 03:39:59.934987068 CEST | 1.1.1.1 | 192.168.2.4 | 0x7877 | No error (0) | 1.179.112.195 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:39:59.934987068 CEST | 1.1.1.1 | 192.168.2.4 | 0x7877 | No error (0) | 1.179.112.197 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:39:59.934987068 CEST | 1.1.1.1 | 192.168.2.4 | 0x7877 | No error (0) | 1.179.112.196 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:01.175090075 CEST | 1.1.1.1 | 192.168.2.4 | 0xd446 | No error (0) | r.mailin.fr | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:01.176004887 CEST | 1.1.1.1 | 192.168.2.4 | 0xd276 | No error (0) | r.mailin.fr | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:01.176004887 CEST | 1.1.1.1 | 192.168.2.4 | 0xd276 | No error (0) | r1.mailin.fr | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:01.176004887 CEST | 1.1.1.1 | 192.168.2.4 | 0xd276 | No error (0) | 1.179.112.197 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:01.176004887 CEST | 1.1.1.1 | 192.168.2.4 | 0xd276 | No error (0) | 1.179.112.196 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:01.176004887 CEST | 1.1.1.1 | 192.168.2.4 | 0xd276 | No error (0) | 1.179.112.195 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:02.364628077 CEST | 1.1.1.1 | 192.168.2.4 | 0x793e | No error (0) | 142.250.74.196 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:02.364639997 CEST | 1.1.1.1 | 192.168.2.4 | 0x2c5c | No error (0) | 65 | IN (0x0001) | false | |||
Aug 4, 2024 03:40:16.559511900 CEST | 1.1.1.1 | 192.168.2.4 | 0x457a | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:16.559511900 CEST | 1.1.1.1 | 192.168.2.4 | 0x457a | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:17.949495077 CEST | 1.1.1.1 | 192.168.2.4 | 0xff9f | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 4, 2024 03:40:17.949495077 CEST | 1.1.1.1 | 192.168.2.4 | 0xff9f | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 1.179.112.195 | 443 | 3236 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-04 01:40:00 UTC | 720 | OUT | |
2024-08-04 01:40:00 UTC | 269 | IN | |
2024-08-04 01:40:00 UTC | 917 | IN | |
2024-08-04 01:40:00 UTC | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49735 | 1.179.112.195 | 443 | 3236 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-04 01:40:00 UTC | 658 | OUT | |
2024-08-04 01:40:01 UTC | 330 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49739 | 1.179.112.197 | 443 | 3236 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-04 01:40:01 UTC | 360 | OUT | |
2024-08-04 01:40:02 UTC | 330 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49741 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-04 01:40:03 UTC | 161 | OUT | |
2024-08-04 01:40:04 UTC | 494 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49742 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-04 01:40:05 UTC | 239 | OUT | |
2024-08-04 01:40:05 UTC | 514 | IN | |
2024-08-04 01:40:05 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 21:39:54 |
Start date: | 03/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 21:39:56 |
Start date: | 03/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 21:39:58 |
Start date: | 03/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |