Windows
Analysis Report
http://tpc.googlesyndication.wiki.
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 7036 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) chrome.exe (PID: 5440 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2572 --fi eld-trial- handle=252 0,i,130236 6254929210 2023,41863 5534992643 6822,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
chrome.exe (PID: 2552 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://tpc.go oglesyndic ation.wiki ." MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
tpc.googlesyndication.wiki | 34.90.60.144 | true | false | unknown | |
www.google.com | 142.250.185.100 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
34.90.60.144 | tpc.googlesyndication.wiki | United States | 15169 | GOOGLEUS | false | |
142.250.185.100 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.7 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1496544 |
Start date and time: | 2024-08-21 13:05:24 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://tpc.googlesyndication.wiki. |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@16/5@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S IHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.e xe, svchost.exe, UsoClient.exe - Excluded IPs from analysis (wh
itelisted): 142.250.185.131, 1 42.250.185.174, 64.233.167.84, 34.104.35.123, 93.184.221.240 , 20.190.159.23, 20.190.159.73 , 20.190.159.0, 20.190.159.2, 20.190.159.68, 40.126.31.67, 4 0.126.31.69, 40.126.31.73, 13. 85.23.86, 20.3.187.198, 13.85. 23.206, 172.217.18.99 - Excluded domains from analysis
(whitelisted): slscr.update.m icrosoft.com, clientservices.g oogleapis.com, time.windows.co m, wu.azureedge.net, clients2. google.com, login.live.com, bg .apr-52dd2-0503.edgecastdns.ne t, cs11.wpc.v0cdn.net, glb.cws .prod.dcat.dsp.trafficmanager. net, hlb.apr-52dd2-0.edgecastd ns.net, sls.update.microsoft.c om, update.googleapis.com, wu- b-net.trafficmanager.net, glb. sls.prod.dcat.dsp.trafficmanag er.net, prdv4a.aadg.msidentity .com, fs.microsoft.com, accoun ts.google.com, ctldl.windowsup date.com.delivery.microsoft.co m, wu.ec.azureedge.net, www.tm .v4.a.prd.aadg.akadns.net, set tings-win.data.microsoft.com, ctldl.windowsupdate.com, login .msa.msidentity.com, fe3cr.del ivery.mp.microsoft.com, fe3.de livery.mp.microsoft.com, edged l.me.gvt1.com, clients.l.googl e.com, www.tm.lg.prod.aadmsa.t rafficmanager.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: http:/
/tpc.googlesyndication.wiki.
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:F:F |
MD5: | 7215EE9C7D9DC229D2921A40E899EC5F |
SHA1: | B858CB282617FB0956D960215C8E84D1CCF909C6 |
SHA-256: | 36A9E7F1C95B82FFB99743E0C5C4CE95D83C9A430AAC59F84EF3CBFAB6145068 |
SHA-512: | F90DDD77E400DFE6A3FCF479B00B1EE29E7015C5BB8CD70F5F15B4886CC339275FF553FC8A053F8DDC7324F45168CFFAF81F8C3AC93996F6536EEF38E5E40768 |
Malicious: | false |
Reputation: | low |
URL: | http://tpc.googlesyndication.wiki./ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:F:F |
MD5: | 7215EE9C7D9DC229D2921A40E899EC5F |
SHA1: | B858CB282617FB0956D960215C8E84D1CCF909C6 |
SHA-256: | 36A9E7F1C95B82FFB99743E0C5C4CE95D83C9A430AAC59F84EF3CBFAB6145068 |
SHA-512: | F90DDD77E400DFE6A3FCF479B00B1EE29E7015C5BB8CD70F5F15B4886CC339275FF553FC8A053F8DDC7324F45168CFFAF81F8C3AC93996F6536EEF38E5E40768 |
Malicious: | false |
Reputation: | low |
URL: | http://tpc.googlesyndication.wiki./favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:F:F |
MD5: | 7215EE9C7D9DC229D2921A40E899EC5F |
SHA1: | B858CB282617FB0956D960215C8E84D1CCF909C6 |
SHA-256: | 36A9E7F1C95B82FFB99743E0C5C4CE95D83C9A430AAC59F84EF3CBFAB6145068 |
SHA-512: | F90DDD77E400DFE6A3FCF479B00B1EE29E7015C5BB8CD70F5F15B4886CC339275FF553FC8A053F8DDC7324F45168CFFAF81F8C3AC93996F6536EEF38E5E40768 |
Malicious: | false |
Reputation: | low |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 146
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 21, 2024 13:06:11.777550936 CEST | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:11.777565956 CEST | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:11.886945963 CEST | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:11.918616056 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Aug 21, 2024 13:06:12.230716944 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Aug 21, 2024 13:06:12.840044022 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Aug 21, 2024 13:06:14.043175936 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Aug 21, 2024 13:06:16.449423075 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Aug 21, 2024 13:06:19.677818060 CEST | 49704 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:19.678267956 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:19.684591055 CEST | 80 | 49704 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:19.684768915 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:19.684849024 CEST | 49704 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:19.686968088 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:19.688405991 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:19.693639040 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:20.304234982 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:20.352739096 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:20.357631922 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:20.462848902 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Aug 21, 2024 13:06:20.525309086 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:20.637649059 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:20.736835003 CEST | 49707 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:20.741872072 CEST | 80 | 49707 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:20.741997957 CEST | 49707 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:20.742206097 CEST | 49707 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:20.747045040 CEST | 80 | 49707 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:20.843817949 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Aug 21, 2024 13:06:21.278738976 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Aug 21, 2024 13:06:21.376487017 CEST | 80 | 49707 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:06:21.388124943 CEST | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:21.388128042 CEST | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:21.419214964 CEST | 49707 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:06:21.497370005 CEST | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:21.591104984 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Aug 21, 2024 13:06:22.761226892 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:22.761255026 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:22.761317015 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:22.763897896 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:22.763911009 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:23.090899944 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Aug 21, 2024 13:06:23.423146009 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:23.466778994 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:23.471632004 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:23.471649885 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:23.474050045 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:23.474137068 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:23.593585014 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:23.593791962 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:23.638464928 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:23.638490915 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:23.684650898 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:23.782900095 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:23.782926083 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:23.783083916 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:23.786344051 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:23.786380053 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:23.911302090 CEST | 443 | 49698 | 104.98.116.138 | 192.168.2.7 |
Aug 21, 2024 13:06:23.911649942 CEST | 49698 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:24.439573050 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:24.439704895 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:24.458169937 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:24.458192110 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:24.458432913 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:24.498511076 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:24.964160919 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.008497953 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.043617964 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:25.043654919 CEST | 443 | 49711 | 40.127.240.158 | 192.168.2.7 |
Aug 21, 2024 13:06:25.043804884 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:25.045202971 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:25.045217037 CEST | 443 | 49711 | 40.127.240.158 | 192.168.2.7 |
Aug 21, 2024 13:06:25.151258945 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.151343107 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.152426004 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.152426004 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.152709007 CEST | 49710 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.152721882 CEST | 443 | 49710 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.235903978 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.235918045 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.236093044 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.236998081 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.237010002 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.832806110 CEST | 443 | 49711 | 40.127.240.158 | 192.168.2.7 |
Aug 21, 2024 13:06:25.833136082 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:25.837869883 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:25.837877989 CEST | 443 | 49711 | 40.127.240.158 | 192.168.2.7 |
Aug 21, 2024 13:06:25.838161945 CEST | 443 | 49711 | 40.127.240.158 | 192.168.2.7 |
Aug 21, 2024 13:06:25.889169931 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:25.890957117 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.891163111 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.899584055 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.899595976 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.899843931 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:25.901046038 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:25.948510885 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:26.076652050 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Aug 21, 2024 13:06:26.170980930 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:26.171057940 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:26.173310995 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:26.219837904 CEST | 49712 | 443 | 192.168.2.7 | 184.28.90.27 |
Aug 21, 2024 13:06:26.219866991 CEST | 443 | 49712 | 184.28.90.27 | 192.168.2.7 |
Aug 21, 2024 13:06:26.689456940 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:26.689573050 CEST | 443 | 49711 | 40.127.240.158 | 192.168.2.7 |
Aug 21, 2024 13:06:26.689639091 CEST | 49711 | 443 | 192.168.2.7 | 40.127.240.158 |
Aug 21, 2024 13:06:30.887433052 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Aug 21, 2024 13:06:32.043646097 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Aug 21, 2024 13:06:32.414958954 CEST | 49698 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:32.419884920 CEST | 443 | 49698 | 104.98.116.138 | 192.168.2.7 |
Aug 21, 2024 13:06:32.427052975 CEST | 49720 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:32.427100897 CEST | 443 | 49720 | 104.98.116.138 | 192.168.2.7 |
Aug 21, 2024 13:06:32.431258917 CEST | 49720 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:32.432089090 CEST | 49720 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:06:32.432106972 CEST | 443 | 49720 | 104.98.116.138 | 192.168.2.7 |
Aug 21, 2024 13:06:33.323348999 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:33.323412895 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:33.323465109 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:34.603590965 CEST | 49709 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:06:34.603626966 CEST | 443 | 49709 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:06:36.618772030 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:36.618817091 CEST | 443 | 49725 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:36.619050980 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:36.619314909 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:36.619328976 CEST | 443 | 49725 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:37.441751957 CEST | 443 | 49725 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:37.441999912 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.442894936 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.442900896 CEST | 443 | 49725 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:37.443121910 CEST | 443 | 49725 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:37.450062037 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.450109959 CEST | 443 | 49725 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:37.450227976 CEST | 443 | 49725 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:37.450305939 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.450305939 CEST | 49725 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.506640911 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.506666899 CEST | 443 | 49726 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:37.506838083 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.506963968 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:37.506975889 CEST | 443 | 49726 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:38.311742067 CEST | 443 | 49726 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:38.311888933 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.312938929 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.312947989 CEST | 443 | 49726 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:38.313175917 CEST | 443 | 49726 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:38.314198971 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.314239025 CEST | 443 | 49726 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:38.314337015 CEST | 443 | 49726 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:38.314362049 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.317177057 CEST | 49726 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.384704113 CEST | 49727 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.384754896 CEST | 443 | 49727 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:38.384896040 CEST | 49727 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.386593103 CEST | 49727 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:38.386612892 CEST | 443 | 49727 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:39.207171917 CEST | 443 | 49727 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:39.207242966 CEST | 49727 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:39.210208893 CEST | 49727 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:39.210217953 CEST | 443 | 49727 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:39.210447073 CEST | 443 | 49727 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:39.212966919 CEST | 49727 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:39.213006973 CEST | 443 | 49727 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:39.213068962 CEST | 49727 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:39.327162027 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:39.327243090 CEST | 443 | 49729 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:39.327325106 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:39.327512026 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:39.327528000 CEST | 443 | 49729 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:40.169680119 CEST | 443 | 49729 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:40.169915915 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.175059080 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.175072908 CEST | 443 | 49729 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:40.175348997 CEST | 443 | 49729 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:40.179055929 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.179091930 CEST | 443 | 49729 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:40.179210901 CEST | 443 | 49729 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:40.179286957 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.179286957 CEST | 49729 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.676886082 CEST | 49730 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.676939011 CEST | 443 | 49730 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:40.677160025 CEST | 49730 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.677809954 CEST | 49730 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:40.677819967 CEST | 443 | 49730 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:41.469734907 CEST | 443 | 49730 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:41.469803095 CEST | 49730 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:41.473517895 CEST | 49730 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:41.473530054 CEST | 443 | 49730 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:41.474746943 CEST | 443 | 49730 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:41.477472067 CEST | 49730 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:41.477511883 CEST | 443 | 49730 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:41.477565050 CEST | 49730 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:41.925682068 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:41.925725937 CEST | 443 | 49731 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:41.925786972 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:41.926395893 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:41.926409006 CEST | 443 | 49731 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:42.740645885 CEST | 443 | 49731 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:42.743074894 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:42.763058901 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:42.763077974 CEST | 443 | 49731 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:42.763328075 CEST | 443 | 49731 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:42.767057896 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:42.767112970 CEST | 443 | 49731 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:42.767317057 CEST | 443 | 49731 | 51.124.78.146 | 192.168.2.7 |
Aug 21, 2024 13:06:42.767390013 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:42.767390013 CEST | 49731 | 443 | 192.168.2.7 | 51.124.78.146 |
Aug 21, 2024 13:06:43.949728966 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Aug 21, 2024 13:07:04.699611902 CEST | 49704 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:04.704802990 CEST | 80 | 49704 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:05.527780056 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:05.532638073 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:06.387142897 CEST | 49707 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:06.391944885 CEST | 80 | 49707 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:15.191852093 CEST | 443 | 49720 | 104.98.116.138 | 192.168.2.7 |
Aug 21, 2024 13:07:15.192060947 CEST | 49720 | 443 | 192.168.2.7 | 104.98.116.138 |
Aug 21, 2024 13:07:20.542897940 CEST | 80 | 49704 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:20.543046951 CEST | 80 | 49704 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:20.543082952 CEST | 49704 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:20.543194056 CEST | 49704 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:21.029853106 CEST | 49704 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:21.034773111 CEST | 80 | 49704 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:22.812845945 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:22.812897921 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:22.813225985 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:22.813546896 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:22.813565016 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:23.476689100 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:23.477032900 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:23.477060080 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:23.477369070 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:23.477971077 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:23.478034019 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:23.527991056 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:33.403244972 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:33.403312922 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:33.403354883 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:35.301959991 CEST | 49736 | 443 | 192.168.2.7 | 142.250.185.100 |
Aug 21, 2024 13:07:35.302022934 CEST | 443 | 49736 | 142.250.185.100 | 192.168.2.7 |
Aug 21, 2024 13:07:35.542119980 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:35.542177916 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:36.392604113 CEST | 80 | 49707 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:36.393163919 CEST | 49707 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:36.655411005 CEST | 49707 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:36.655657053 CEST | 49705 | 80 | 192.168.2.7 | 34.90.60.144 |
Aug 21, 2024 13:07:36.660355091 CEST | 80 | 49707 | 34.90.60.144 | 192.168.2.7 |
Aug 21, 2024 13:07:36.660444975 CEST | 80 | 49705 | 34.90.60.144 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 21, 2024 13:06:18.274197102 CEST | 53 | 57551 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:18.278481007 CEST | 53 | 49689 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:19.453269005 CEST | 53 | 58842 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:19.480812073 CEST | 50625 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 21, 2024 13:06:19.481173038 CEST | 60094 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 21, 2024 13:06:19.670685053 CEST | 53 | 50625 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:19.677169085 CEST | 53 | 60094 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:20.533379078 CEST | 55948 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 21, 2024 13:06:20.533379078 CEST | 58618 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 21, 2024 13:06:20.729944944 CEST | 53 | 58618 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:20.736047029 CEST | 53 | 55948 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:22.751293898 CEST | 60376 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 21, 2024 13:06:22.751439095 CEST | 52630 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 21, 2024 13:06:22.758239985 CEST | 53 | 52630 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:22.758435011 CEST | 53 | 60376 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:25.256433010 CEST | 123 | 123 | 192.168.2.7 | 40.119.148.38 |
Aug 21, 2024 13:06:25.796931028 CEST | 123 | 123 | 40.119.148.38 | 192.168.2.7 |
Aug 21, 2024 13:06:26.815715075 CEST | 123 | 123 | 192.168.2.7 | 40.119.148.38 |
Aug 21, 2024 13:06:26.992194891 CEST | 123 | 123 | 40.119.148.38 | 192.168.2.7 |
Aug 21, 2024 13:06:36.427751064 CEST | 53 | 55422 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:06:55.649759054 CEST | 53 | 51910 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:07:17.913731098 CEST | 53 | 52078 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:07:18.542813063 CEST | 53 | 55413 | 1.1.1.1 | 192.168.2.7 |
Aug 21, 2024 13:07:20.959270954 CEST | 138 | 138 | 192.168.2.7 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 21, 2024 13:06:19.480812073 CEST | 192.168.2.7 | 1.1.1.1 | 0x28e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 21, 2024 13:06:19.481173038 CEST | 192.168.2.7 | 1.1.1.1 | 0xba34 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 21, 2024 13:06:20.533379078 CEST | 192.168.2.7 | 1.1.1.1 | 0xa1f6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 21, 2024 13:06:20.533379078 CEST | 192.168.2.7 | 1.1.1.1 | 0x7c84 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 21, 2024 13:06:22.751293898 CEST | 192.168.2.7 | 1.1.1.1 | 0x4c20 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 21, 2024 13:06:22.751439095 CEST | 192.168.2.7 | 1.1.1.1 | 0xbbd5 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 21, 2024 13:06:19.670685053 CEST | 1.1.1.1 | 192.168.2.7 | 0x28e | No error (0) | 34.90.60.144 | A (IP address) | IN (0x0001) | false | ||
Aug 21, 2024 13:06:20.736047029 CEST | 1.1.1.1 | 192.168.2.7 | 0xa1f6 | No error (0) | 34.90.60.144 | A (IP address) | IN (0x0001) | false | ||
Aug 21, 2024 13:06:22.758239985 CEST | 1.1.1.1 | 192.168.2.7 | 0xbbd5 | No error (0) | 65 | IN (0x0001) | false | |||
Aug 21, 2024 13:06:22.758435011 CEST | 1.1.1.1 | 192.168.2.7 | 0x4c20 | No error (0) | 142.250.185.100 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49705 | 34.90.60.144 | 80 | 5440 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 21, 2024 13:06:19.688405991 CEST | 442 | OUT | |
Aug 21, 2024 13:06:20.304234982 CEST | 188 | IN | |
Aug 21, 2024 13:06:20.352739096 CEST | 398 | OUT | |
Aug 21, 2024 13:06:20.525309086 CEST | 176 | IN | |
Aug 21, 2024 13:07:05.527780056 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49707 | 34.90.60.144 | 80 | 5440 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 21, 2024 13:06:20.742206097 CEST | 291 | OUT | |
Aug 21, 2024 13:06:21.376487017 CEST | 176 | IN | |
Aug 21, 2024 13:07:06.387142897 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49704 | 34.90.60.144 | 80 | 5440 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 21, 2024 13:07:04.699611902 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49710 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-21 11:06:24 UTC | 161 | OUT | |
2024-08-21 11:06:25 UTC | 495 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49712 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-21 11:06:25 UTC | 239 | OUT | |
2024-08-21 11:06:26 UTC | 515 | IN | |
2024-08-21 11:06:26 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 07:06:14 |
Start date: | 21/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 07:06:17 |
Start date: | 21/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 07:06:18 |
Start date: | 21/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |