Windows
Analysis Report
https://service.clearservice.com/constructionns/track/link.jsp?id1=7962783&id2=1118626513&link=https://watercolorjourney.net/afew/ribs.html
Overview
General Information
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 2012 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 5908 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2272 --fi eld-trial- handle=209 2,i,164130 1859114644 3083,10011 0089431945 15223,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- chrome.exe (PID: 1880 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://servi ce.clearse rvice.com/ constructi onns/track /link.jsp? id1=796278 3&id2=1118 626513&lin k=https:// watercolor journey.ne t/afew/rib s.html" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | LLM: |
Source: | Matcher: |
Source: | Matcher: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
1% | Virustotal | Browse | ||
100% | SlashNext | Credential Stealing type: Phishing & Social usering |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
100% | Avira URL Cloud | phishing | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
service.clearservice.com | 71.7.190.63 | true | false |
| unknown |
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false |
| unknown |
www.google.com | 142.250.185.132 | true | false |
| unknown |
watercolorjourney.net | 162.241.87.113 | true | false |
| unknown |
upload.wikimedia.org | 185.15.59.240 | true | false |
| unknown |
microsoft-10.ovslegodl.sched.ovscdns.com | 43.175.151.231 | true | false |
| unknown |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
true | unknown | ||
true | unknown | ||
false |
| unknown | |
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.241.87.113 | watercolorjourney.net | United States | 46606 | UNIFIEDLAYER-AS-1US | false | |
142.250.185.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
185.15.59.240 | upload.wikimedia.org | Netherlands | 14907 | WIKIMEDIAUS | false | |
71.7.190.63 | service.clearservice.com | Canada | 11260 | EASTLINK-HSICA | false |
IP |
---|
192.168.2.4 |
192.168.2.6 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1499035 |
Start date and time: | 2024-08-26 14:55:31 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 18s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://service.clearservice.com/constructionns/track/link.jsp?id1=7962783&id2=1118626513&link=https://watercolorjourney.net/afew/ribs.html |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal72.phis.win@22/11@10/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.74.195, 216.58.212.174, 64.233.184.84, 34.104.35.123, 142.250.74.202, 142.250.185.234, 142.250.186.42, 142.250.186.106, 216.58.212.170, 172.217.16.138, 142.250.185.202, 142.250.186.74, 172.217.18.106, 216.58.206.42, 142.250.185.170, 216.58.206.74, 172.217.16.202, 172.217.18.10, 142.250.181.234, 142.250.184.202, 13.85.23.86, 192.229.221.95, 20.3.187.198, 199.232.214.172, 13.95.31.18, 52.165.164.15, 142.250.186.35, 43.175.151.231, 131.107.255.255
- Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 315 |
Entropy (8bit): | 5.0572271090563765 |
Encrypted: | false |
SSDEEP: | 6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR |
MD5: | A34AC19F4AFAE63ADC5D2F7BC970C07F |
SHA1: | A82190FC530C265AA40A045C21770D967F4767B8 |
SHA-256: | D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3 |
SHA-512: | 42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765 |
Malicious: | false |
Reputation: | low |
URL: | https://watercolorjourney.net/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3163 |
Entropy (8bit): | 4.234213137700242 |
Encrypted: | false |
SSDEEP: | 96:pN7LWBJcU61ptk4fgquZpr6Lxm6ud94yU:pFW8U617k3quZpWLxmP94yU |
MD5: | 84E661E792967C393DA599B81EF41DC8 |
SHA1: | 501B90AB65C9F9F9B37EE2E938F77AE0E59F4B37 |
SHA-256: | 34EC1619E4A62515D67C5240FE5762EF5A1838FE67D2FB1FB0B001099CEBF1DB |
SHA-512: | B732E81F507DD02FBA66CC6C3B2B070F30EFAF6CBCA8B91EE9FF9A37EE07F0666907C7B87A9FC7FFD576B5DF57351ECD987415D7E3B4D7CE1E1946EC109DE827 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | 3:H17Y:q |
MD5: | 156DF0210BF420106CB8AFEBCB3A27D2 |
SHA1: | 970B5EA1194F50A291A239C58D73159FDEC1BA64 |
SHA-256: | EBDD332E8562CE34374C310F84F4527D93D3F9D2AC27410F824C6647A4DF1DDB |
SHA-512: | 9AE3CC4E8F274B2A5C2BAA6CE1163181C50071378BE3A782FBA8FF8D7F374E9408BCD137E5B217684DDC470244FEA8C6005AF5B96D25BA3AD086550679DF6578 |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzQSEAmmPyI_pAZQghIFDZjmzqo=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 315 |
Entropy (8bit): | 5.0572271090563765 |
Encrypted: | false |
SSDEEP: | 6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR |
MD5: | A34AC19F4AFAE63ADC5D2F7BC970C07F |
SHA1: | A82190FC530C265AA40A045C21770D967F4767B8 |
SHA-256: | D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3 |
SHA-512: | 42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765 |
Malicious: | false |
Reputation: | low |
URL: | https://watercolorjourney.net/afew/images/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3312 |
Entropy (8bit): | 5.252945502792911 |
Encrypted: | false |
SSDEEP: | 48:TmasTa5I42SVZ4sIZG838hbSVin4yaFGrcdiBx+2PGAV8TA/LdwASsrMeJ+bDIrO:TmGII8ftCSSX6iBJccwWQxD |
MD5: | 4110DAE92622E356577B4F5F69D773CD |
SHA1: | 7F58B87998BFB63F4F85DC5C827F729839006809 |
SHA-256: | 1F7CF859A51864122FD9E3A585F7B114BCF4186441D2D7D2300DE114EEA8FB58 |
SHA-512: | 2610C8E72477D66F8C9EDAB30448E93D859C785430CAED3524BCF45B7E1CDD0413F9D0D7FAA1BA0F16C5C8B6114F59E97A0266ACECC44567E54D4ABA5C0C50F9 |
Malicious: | false |
Reputation: | low |
URL: | https://watercolorjourney.net/afew/ribs.html |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3163 |
Entropy (8bit): | 4.234213137700242 |
Encrypted: | false |
SSDEEP: | 96:pN7LWBJcU61ptk4fgquZpr6Lxm6ud94yU:pFW8U617k3quZpWLxmP94yU |
MD5: | 84E661E792967C393DA599B81EF41DC8 |
SHA1: | 501B90AB65C9F9F9B37EE2E938F77AE0E59F4B37 |
SHA-256: | 34EC1619E4A62515D67C5240FE5762EF5A1838FE67D2FB1FB0B001099CEBF1DB |
SHA-512: | B732E81F507DD02FBA66CC6C3B2B070F30EFAF6CBCA8B91EE9FF9A37EE07F0666907C7B87A9FC7FFD576B5DF57351ECD987415D7E3B4D7CE1E1946EC109DE827 |
Malicious: | false |
Reputation: | low |
URL: | https://upload.wikimedia.org/wikipedia/commons/9/96/Microsoft_logo_%282012%29.svg |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 26, 2024 14:56:19.846307039 CEST | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:19.846335888 CEST | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:20.174489021 CEST | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:27.566644907 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:27.566668987 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:27.566723108 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:27.567399025 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:27.567415953 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.435189962 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.435265064 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:28.441436052 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:28.441442013 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.441900015 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.443798065 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:28.443919897 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:28.443926096 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.444130898 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:28.488500118 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.618370056 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.618475914 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:28.618527889 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:28.618693113 CEST | 49713 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:28.618706942 CEST | 443 | 49713 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:29.453846931 CEST | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:29.526053905 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:29.526079893 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:29.526173115 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:29.526526928 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:29.526567936 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:29.526635885 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:29.526776075 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:29.526792049 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:29.527031898 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:29.527050972 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:29.549591064 CEST | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:29.860308886 CEST | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:30.279624939 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.279886007 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.279895067 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.281009912 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.281068087 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.287786007 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.289485931 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.289509058 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.290210962 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.290280104 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.290421963 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.290432930 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.290615082 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.290703058 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.291022062 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.291100025 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.331372023 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.331376076 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.331384897 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.376384974 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.420794010 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.421371937 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.421427011 CEST | 443 | 49716 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:56:30.421483994 CEST | 49716 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:56:30.467408895 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:30.467434883 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:30.467534065 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:30.467731953 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:30.467744112 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:30.972389936 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:30.972810984 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:30.972830057 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:30.973906040 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:30.973980904 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:30.977505922 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:30.977571964 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:30.977947950 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:30.977955103 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:30.997783899 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:30.997802973 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:30.997878075 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:30.998451948 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:30.998466015 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:31.031754017 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.099075079 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.099095106 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.099144936 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.099203110 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.100002050 CEST | 49720 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.100017071 CEST | 443 | 49720 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.338650942 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.338670015 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.338725090 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.339689970 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.339703083 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.347527981 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:31.347562075 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:31.347630024 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:31.347826958 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:31.347839117 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:31.469647884 CEST | 443 | 49705 | 173.222.162.64 | 192.168.2.6 |
Aug 26, 2024 14:56:31.469738007 CEST | 49705 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:31.679281950 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:31.679879904 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:31.679888964 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:31.681371927 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:31.681444883 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:31.683501005 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:31.683588028 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:31.736171961 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:31.736179113 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:31.781724930 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:31.922171116 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.925359964 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.925368071 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.925750017 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.944999933 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.945120096 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:31.945302963 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:31.988492012 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:32.063565969 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:32.063628912 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:32.063673973 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:32.093950033 CEST | 49722 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:32.093959093 CEST | 443 | 49722 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:32.129129887 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.129384995 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.129395008 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.130666018 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.130729914 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.130736113 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.130769014 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.504307985 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:32.504345894 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:32.504412889 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:32.506023884 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:32.506037951 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:32.547343016 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.547544003 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.548500061 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.548516035 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.594949007 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.717693090 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.717716932 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.717781067 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.717787027 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.717819929 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.722929955 CEST | 49723 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:32.722949028 CEST | 443 | 49723 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:32.752173901 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:32.752201080 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:32.752320051 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:32.755479097 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:32.755494118 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.253161907 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.253274918 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.351569891 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.370378971 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:33.370409012 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.370835066 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.377078056 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:33.377160072 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.377373934 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:33.403181076 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.403204918 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.403469086 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.420501947 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.454449892 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.492429972 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.492507935 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.492624044 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:33.553514957 CEST | 49726 | 443 | 192.168.2.6 | 162.241.87.113 |
Aug 26, 2024 14:56:33.553528070 CEST | 443 | 49726 | 162.241.87.113 | 192.168.2.6 |
Aug 26, 2024 14:56:33.641328096 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.688504934 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.801722050 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:33.801750898 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:33.801840067 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:33.802263975 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:33.802274942 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:33.832345963 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.832412004 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.832565069 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.832926035 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.832947969 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.832993031 CEST | 49725 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.832998991 CEST | 443 | 49725 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.935545921 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.935610056 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:33.935771942 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.936053038 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:33.936104059 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:34.454919100 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.455521107 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.455532074 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.456626892 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.456703901 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.456711054 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.456768990 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.457285881 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.457348108 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.457700968 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.457705975 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.501281977 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.655909061 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:34.656001091 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:34.709300995 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:34.709310055 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:34.709614992 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:34.713300943 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:34.760509014 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:34.798501968 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.798532963 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.798589945 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.798600912 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.798613071 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.798641920 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.798690081 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.800410032 CEST | 49727 | 443 | 192.168.2.6 | 185.15.59.240 |
Aug 26, 2024 14:56:34.800429106 CEST | 443 | 49727 | 185.15.59.240 | 192.168.2.6 |
Aug 26, 2024 14:56:34.933382034 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:34.933449984 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:34.933657885 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:35.130316019 CEST | 49728 | 443 | 192.168.2.6 | 184.28.90.27 |
Aug 26, 2024 14:56:35.130336046 CEST | 443 | 49728 | 184.28.90.27 | 192.168.2.6 |
Aug 26, 2024 14:56:37.344300985 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:37.344337940 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:37.344427109 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:37.346111059 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:37.346124887 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.142128944 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.142245054 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:38.145414114 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:38.145426035 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.145785093 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.151212931 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:38.151276112 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:38.151283026 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.151427984 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:38.196501017 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.322206020 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.322408915 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:38.322489977 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:38.322623968 CEST | 49730 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:38.322649956 CEST | 443 | 49730 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:41.565094948 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:41.565176010 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:41.565232038 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:42.059381962 CEST | 49721 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:56:42.059411049 CEST | 443 | 49721 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:56:42.347162962 CEST | 49705 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:42.347919941 CEST | 49705 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:42.350419998 CEST | 49735 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:42.350457907 CEST | 443 | 49735 | 173.222.162.64 | 192.168.2.6 |
Aug 26, 2024 14:56:42.350533009 CEST | 49735 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:42.352792978 CEST | 443 | 49705 | 173.222.162.64 | 192.168.2.6 |
Aug 26, 2024 14:56:42.354190111 CEST | 443 | 49705 | 173.222.162.64 | 192.168.2.6 |
Aug 26, 2024 14:56:42.363091946 CEST | 49735 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:42.363110065 CEST | 443 | 49735 | 173.222.162.64 | 192.168.2.6 |
Aug 26, 2024 14:56:42.713927031 CEST | 50041 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:42.718832016 CEST | 53 | 50041 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:42.719085932 CEST | 50041 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:42.719207048 CEST | 50041 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:42.724571943 CEST | 53 | 50041 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:42.980930090 CEST | 443 | 49735 | 173.222.162.64 | 192.168.2.6 |
Aug 26, 2024 14:56:42.981008053 CEST | 49735 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:56:43.172168970 CEST | 53 | 50041 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:43.172772884 CEST | 50041 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:43.178256035 CEST | 53 | 50041 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:43.178489923 CEST | 50041 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:49.680471897 CEST | 57450 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:49.685209990 CEST | 53 | 57450 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:49.685277939 CEST | 57450 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:49.685378075 CEST | 57450 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:49.693593025 CEST | 53 | 57450 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:50.156239986 CEST | 53 | 57450 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:50.156549931 CEST | 57450 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:50.161659002 CEST | 53 | 57450 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:50.161761999 CEST | 57450 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:53.947267056 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:53.947319031 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:53.947392941 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:53.948674917 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:53.948685884 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.763276100 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.763348103 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.769135952 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.769146919 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.769383907 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.771255970 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.771401882 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.771413088 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.771589041 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.816495895 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.965804100 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.966150999 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:56:54.966392040 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.988720894 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.988720894 CEST | 57452 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:56:54.988749981 CEST | 443 | 57452 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:02.137603998 CEST | 443 | 49735 | 173.222.162.64 | 192.168.2.6 |
Aug 26, 2024 14:57:02.137758970 CEST | 49735 | 443 | 192.168.2.6 | 173.222.162.64 |
Aug 26, 2024 14:57:14.684562922 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:14.684607029 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:14.684678078 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:14.685260057 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:14.685281038 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.342966080 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:57:15.342974901 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:57:15.506980896 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.507082939 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:15.509008884 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:15.509028912 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.509368896 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.510947943 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:15.511010885 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:15.511024952 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.511419058 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:15.552500963 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.681457996 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.681660891 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.681804895 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:15.681977987 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:15.682001114 CEST | 443 | 57453 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:15.682023048 CEST | 57453 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:31.049328089 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:57:31.049458981 CEST | 443 | 49717 | 71.7.190.63 | 192.168.2.6 |
Aug 26, 2024 14:57:31.049551010 CEST | 49717 | 443 | 192.168.2.6 | 71.7.190.63 |
Aug 26, 2024 14:57:31.049681902 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:31.049726009 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:31.049792051 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:31.050021887 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:31.050031900 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:31.686424971 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:31.686827898 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:31.686855078 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:31.687151909 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:31.687617064 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:31.687676907 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:31.735928059 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:40.161402941 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:40.161441088 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:40.161504030 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:40.162241936 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:40.162252903 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:40.970746994 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:40.970813990 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:40.974035978 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:40.974045038 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:40.974272013 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:40.975804090 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:40.976039886 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:40.976046085 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:40.976316929 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:41.016504049 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:41.152199030 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:41.152714968 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:41.152826071 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:41.196609974 CEST | 57457 | 443 | 192.168.2.6 | 40.113.103.199 |
Aug 26, 2024 14:57:41.196624041 CEST | 443 | 57457 | 40.113.103.199 | 192.168.2.6 |
Aug 26, 2024 14:57:41.625129938 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:41.625215054 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Aug 26, 2024 14:57:41.625262022 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:41.751315117 CEST | 57456 | 443 | 192.168.2.6 | 142.250.185.132 |
Aug 26, 2024 14:57:41.751329899 CEST | 443 | 57456 | 142.250.185.132 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 26, 2024 14:56:27.402179003 CEST | 53 | 50336 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:27.542560101 CEST | 53 | 53652 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:28.726232052 CEST | 53 | 55722 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:29.305685997 CEST | 57007 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:29.308979034 CEST | 62022 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:29.524954081 CEST | 53 | 57007 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:29.525099993 CEST | 53 | 62022 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:30.427398920 CEST | 64753 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:30.427603960 CEST | 62389 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:30.466670036 CEST | 53 | 64753 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:30.466854095 CEST | 53 | 62389 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:30.987984896 CEST | 61006 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:30.988125086 CEST | 61269 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:30.996176004 CEST | 53 | 61006 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:30.996196985 CEST | 53 | 61269 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:31.336981058 CEST | 62182 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:31.337593079 CEST | 60951 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:31.346522093 CEST | 53 | 62182 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:31.346990108 CEST | 53 | 60951 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:31.387689114 CEST | 53 | 59687 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:33.793239117 CEST | 64114 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:33.793644905 CEST | 61815 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 26, 2024 14:56:33.800201893 CEST | 53 | 64114 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:33.801187038 CEST | 53 | 61815 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:42.712798119 CEST | 53 | 65304 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:45.637409925 CEST | 53 | 51420 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:56:49.679949045 CEST | 53 | 60552 | 1.1.1.1 | 192.168.2.6 |
Aug 26, 2024 14:57:26.783109903 CEST | 53 | 59000 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 26, 2024 14:56:29.305685997 CEST | 192.168.2.6 | 1.1.1.1 | 0x5992 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 26, 2024 14:56:29.308979034 CEST | 192.168.2.6 | 1.1.1.1 | 0x91a7 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 26, 2024 14:56:30.427398920 CEST | 192.168.2.6 | 1.1.1.1 | 0x9506 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 26, 2024 14:56:30.427603960 CEST | 192.168.2.6 | 1.1.1.1 | 0x6a23 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 26, 2024 14:56:30.987984896 CEST | 192.168.2.6 | 1.1.1.1 | 0xb214 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 26, 2024 14:56:30.988125086 CEST | 192.168.2.6 | 1.1.1.1 | 0x2673 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 26, 2024 14:56:31.336981058 CEST | 192.168.2.6 | 1.1.1.1 | 0x3264 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 26, 2024 14:56:31.337593079 CEST | 192.168.2.6 | 1.1.1.1 | 0x72e3 | Standard query (0) | 65 | IN (0x0001) | false | |
Aug 26, 2024 14:56:33.793239117 CEST | 192.168.2.6 | 1.1.1.1 | 0x20b9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 26, 2024 14:56:33.793644905 CEST | 192.168.2.6 | 1.1.1.1 | 0xbe0 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 26, 2024 14:56:29.524954081 CEST | 1.1.1.1 | 192.168.2.6 | 0x5992 | No error (0) | 71.7.190.63 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:30.466670036 CEST | 1.1.1.1 | 192.168.2.6 | 0x9506 | No error (0) | 162.241.87.113 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:30.996176004 CEST | 1.1.1.1 | 192.168.2.6 | 0xb214 | No error (0) | 142.250.185.132 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:30.996196985 CEST | 1.1.1.1 | 192.168.2.6 | 0x2673 | No error (0) | 65 | IN (0x0001) | false | |||
Aug 26, 2024 14:56:31.346522093 CEST | 1.1.1.1 | 192.168.2.6 | 0x3264 | No error (0) | 185.15.59.240 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:33.800201893 CEST | 1.1.1.1 | 192.168.2.6 | 0x20b9 | No error (0) | 185.15.59.240 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:40.572968006 CEST | 1.1.1.1 | 192.168.2.6 | 0x47fe | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:40.572968006 CEST | 1.1.1.1 | 192.168.2.6 | 0x47fe | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:42.100197077 CEST | 1.1.1.1 | 192.168.2.6 | 0x1be3 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:56:42.100197077 CEST | 1.1.1.1 | 192.168.2.6 | 0x1be3 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | microsoft-10.ovslegodl.sched.ovscdns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.151.231 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.151.206 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.152.28.43 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.152.29.78 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.151.207 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 101.33.11.219 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.151.230 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.152.68 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.152.28.41 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.152.66 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 101.33.11.246 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.152.26.80 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.152.67 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.152.29.63 | A (IP address) | IN (0x0001) | false | ||
Aug 26, 2024 14:57:41.676414013 CEST | 1.1.1.1 | 192.168.2.6 | 0xf3a0 | No error (0) | 43.175.151.205 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.6 | 49713 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:28 UTC | 71 | OUT | |
2024-08-26 12:56:28 UTC | 249 | OUT | |
2024-08-26 12:56:28 UTC | 1084 | OUT | |
2024-08-26 12:56:28 UTC | 218 | OUT | |
2024-08-26 12:56:28 UTC | 14 | IN | |
2024-08-26 12:56:28 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49716 | 71.7.190.63 | 443 | 5908 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:30 UTC | 773 | OUT | |
2024-08-26 12:56:30 UTC | 335 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49720 | 162.241.87.113 | 443 | 5908 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:30 UTC | 678 | OUT | |
2024-08-26 12:56:31 UTC | 206 | IN | |
2024-08-26 12:56:31 UTC | 3312 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49722 | 162.241.87.113 | 443 | 5908 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:31 UTC | 651 | OUT | |
2024-08-26 12:56:32 UTC | 164 | IN | |
2024-08-26 12:56:32 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49723 | 185.15.59.240 | 443 | 5908 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:32 UTC | 637 | OUT | |
2024-08-26 12:56:32 UTC | 1079 | IN | |
2024-08-26 12:56:32 UTC | 3163 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49726 | 162.241.87.113 | 443 | 5908 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:33 UTC | 612 | OUT | |
2024-08-26 12:56:33 UTC | 164 | IN | |
2024-08-26 12:56:33 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49725 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:33 UTC | 161 | OUT | |
2024-08-26 12:56:33 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49727 | 185.15.59.240 | 443 | 5908 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:34 UTC | 396 | OUT | |
2024-08-26 12:56:34 UTC | 1079 | IN | |
2024-08-26 12:56:34 UTC | 3163 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.6 | 49728 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:34 UTC | 239 | OUT | |
2024-08-26 12:56:34 UTC | 515 | IN | |
2024-08-26 12:56:34 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
9 | 192.168.2.6 | 49730 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:38 UTC | 71 | OUT | |
2024-08-26 12:56:38 UTC | 249 | OUT | |
2024-08-26 12:56:38 UTC | 1084 | OUT | |
2024-08-26 12:56:38 UTC | 218 | OUT | |
2024-08-26 12:56:38 UTC | 14 | IN | |
2024-08-26 12:56:38 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
10 | 192.168.2.6 | 57452 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:56:54 UTC | 71 | OUT | |
2024-08-26 12:56:54 UTC | 249 | OUT | |
2024-08-26 12:56:54 UTC | 1084 | OUT | |
2024-08-26 12:56:54 UTC | 218 | OUT | |
2024-08-26 12:56:54 UTC | 14 | IN | |
2024-08-26 12:56:54 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
11 | 192.168.2.6 | 57453 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:57:15 UTC | 71 | OUT | |
2024-08-26 12:57:15 UTC | 249 | OUT | |
2024-08-26 12:57:15 UTC | 1084 | OUT | |
2024-08-26 12:57:15 UTC | 218 | OUT | |
2024-08-26 12:57:15 UTC | 14 | IN | |
2024-08-26 12:57:15 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
12 | 192.168.2.6 | 57457 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-26 12:57:40 UTC | 71 | OUT | |
2024-08-26 12:57:40 UTC | 249 | OUT | |
2024-08-26 12:57:40 UTC | 1084 | OUT | |
2024-08-26 12:57:40 UTC | 218 | OUT | |
2024-08-26 12:57:41 UTC | 14 | IN | |
2024-08-26 12:57:41 UTC | 58 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:56:22 |
Start date: | 26/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:56:25 |
Start date: | 26/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 08:56:28 |
Start date: | 26/08/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |