Windows
Analysis Report
https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 744 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 7032 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2188 --fi eld-trial- handle=187 2,i,662276 1000618728 035,972235 9374662057 473,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6612 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://dl.dr opboxuserc ontent.com /scl/fi/xz q2rs33dpjd uvua667sd/ Rechnung-R E2024-0095 -vom-30.08 .2024.zip? rlkey=koe0 h2f8n3e9e0 lg1kwvqsis 1&st=s5ax4 axs&dl=0" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
edge-block-www-env.dropbox-dns.com | 162.125.66.15 | true | false | unknown | |
www.google.com | 142.250.186.100 | true | false | unknown | |
assets.dropbox.com | 52.222.236.19 | true | false | unknown | |
dl.dropboxusercontent.com | unknown | unknown | false | unknown | |
cfl.dropboxstatic.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.125.66.15 | edge-block-www-env.dropbox-dns.com | United States | 19679 | DROPBOXUS | false | |
216.58.206.36 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
52.222.236.51 | unknown | United States | 16509 | AMAZON-02US | false | |
52.222.236.19 | assets.dropbox.com | United States | 16509 | AMAZON-02US | false | |
142.250.186.100 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1516609 |
Start date and time: | 2024-09-24 13:19:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@17/10@14/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, SIHClient.exe, Sgr mBroker.exe, conhost.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.181.227, 1 42.250.185.206, 74.125.71.84, 34.104.35.123, 104.16.100.29, 104.16.99.29, 142.250.186.131, 142.250.186.78 - Excluded domains from analysis
(whitelisted): clients1.googl e.com, fs.microsoft.com, clien ts2.google.com, accounts.googl e.com, edgedl.me.gvt1.com, sls cr.update.microsoft.com, updat e.googleapis.com, clientservic es.googleapis.com, clients.l.g oogle.com, cfl.dropboxstatic.c om.cdn.cloudflare.net, fe3cr.d elivery.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: https:
//dl.dropboxusercontent.com/sc l/fi/xzq2rs33dpjduvua667sd/Rec hnung-RE2024-0095-vom-30.08.20 24.zip?rlkey=koe0h2f8n3e9e0lg1 kwvqsis1&st=s5ax4axs&d l=0
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9830286054038924 |
Encrypted: | false |
SSDEEP: | 48:8XYd5ThRVHYUidAKZdA1FehwiZUklqehiy+3:82ri6py |
MD5: | 39EC88F429F2A2AE9C0D7302D7DA16F7 |
SHA1: | 2C9D5D627A9EB7FAA0D4296A5AB35E2C740552D3 |
SHA-256: | 7821A5A28516B0B1A763CD9DBFE03C183BB7DE1C7DEF88FB82DF7CCF0E0EE2E1 |
SHA-512: | 5E8142F7761D4E3E9CBDA33CEFACE9F54978DEBCE101AA9FD7DE2C4A6BB6BB66AFBBCC7B040D99EF2FC4A25F152687AD56F5956F320D5CED45340684C6631085 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9984726750303796 |
Encrypted: | false |
SSDEEP: | 48:8nd5ThRVHYUidAKZdA1seh/iZUkAQkqehZy+2:8zri09Qsy |
MD5: | F4547B68A9B4C8533101FA7AE8CEEDC6 |
SHA1: | 382B6B7F966E70DE51B7D6A15FCF6FA59B6C8507 |
SHA-256: | 8AE30093C91B299B7CC53C9367C67E6CBAD0EBFAD5E07C8033660447407B60A7 |
SHA-512: | 9F40CB28E35977556763EBDCD7F195E1CD40BEB887A8385407800100C20F17507C676628491D6F799496F1EBF3B064AC08A8D3F309524FD5CCA3AB4A2CDE056E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.007314155566643 |
Encrypted: | false |
SSDEEP: | 48:8vd5ThRAHYUidAKZdA14meh7sFiZUkmgqeh7sLy+BX:8brj4ndy |
MD5: | 417FD0026B4E8BCDF39906337A64A6EF |
SHA1: | 1DC847671688FA80E69484913C01A6E854E96A51 |
SHA-256: | B1E9E64C75E9A729353A523B757AFE3143677C39CF1184BF633E136BBCF43283 |
SHA-512: | BA5F61E5286F575BE539CACDB0189822B651131C8F62991F15FD833326E271F408F0A57E327D04AAEC520FC5DD592ACB8B779E578CAD214E677236BCE3DAC95B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9949797862109784 |
Encrypted: | false |
SSDEEP: | 48:8Wd5ThRVHYUidAKZdA1TehDiZUkwqehFy+R:8UrivTy |
MD5: | 8CAB1E7DA3DA6CFE92F0603AC5F79926 |
SHA1: | EA25097AEFEC2BDAC31DC6FC5FBA58E7857BE172 |
SHA-256: | F8DDA1609CC059287BEEE400F3355955B31EFDE14AB440D2BBB3FD5695260857 |
SHA-512: | C78366E037FF86D0B869F9E057AC5568E1C099DACE766B2AB4B8F6B8B22AB0AB70E6209FFCA89C83BD574FB1CDE704657AD1992A45BAAA3264396E297BD8BBF1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.985443200707457 |
Encrypted: | false |
SSDEEP: | 48:8Qd5ThRVHYUidAKZdA1dehBiZUk1W1qehPy+C:8+riv9vy |
MD5: | 36EA64F7F7BA050F32A9A3299B0BCD36 |
SHA1: | 6453F64CCCB1229E93B8505E4965308906961513 |
SHA-256: | 4642C7750910F7E1155ADB1D6924B6990A900FB8A834DAFB921566612F3903A1 |
SHA-512: | FBC1E0CE827801D1420ABF7611296BAD68126BF54301BB1B16CFC9B25E79FC3C379A383B279DD635E386291ADB45D8A4E3E5B368379249086F36AE75116E2B8F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.995261642194944 |
Encrypted: | false |
SSDEEP: | 48:8wd5ThRVHYUidAKZdA1duTeehOuTbbiZUk5OjqehOuTbdy+yT+:8eriTTfTbxWOvTbdy7T |
MD5: | 17FA582570D957F1C4AE6E9B313E93CA |
SHA1: | 5D6B34C065C32F7734CD29B3D5351E254EB0F4C2 |
SHA-256: | B3EC95ADF0141CAA2DB61BE3676DF95E846DF335A9FD9877473FBE4B1EE45D93 |
SHA-512: | D198F1FFB087D82F8229007D1C595549DE89B26ACCA23ECE3C5139142D796FCE6A46E0C85C7514C4FB9CF22B9C78DFE42800D05ECAC539707EAACAB07B8AC3FF |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10635 |
Entropy (8bit): | 3.7708640282312342 |
Encrypted: | false |
SSDEEP: | 192:lwsp3KmiWvmeX8ogtlAt0ZpbQryQN4P49kPidCgRvFxInbHP:asJrvvXFht0Zpj040k6VRvFxE |
MD5: | 91BE8BB57512787AEA2A3765FD9850A5 |
SHA1: | 422D9E3C077D09B9D8CEC7C2F4273506203EC696 |
SHA-256: | 51CF6CE31001DD4D93E4C6B873F734F64522948A804F75D03104C1DD8A95D616 |
SHA-512: | 342C7FECA0B37FC53F7422ED6C1A8463061DF9C7EBA4FEAB17F8CA0B115594B75C808422F43AACD284C08D42CB7834DFA7C4DBDE627EAD1845C592951C3CB27B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4286 |
Entropy (8bit): | 3.6767668884768048 |
Encrypted: | false |
SSDEEP: | 48:wFFFFFFFFFFFFFFFFtJdFdFSFfyFbK9MFDFCFbXFbFexKFdFcFQrDFaFNGCF7sF9:nudyjwG+jeWqQmGDB5 |
MD5: | F25511F4158C2DFAB6AA11A07D026E4A |
SHA1: | 99F63CF1694FA5E52F43EB967462EA0D9EEF7513 |
SHA-256: | C0906D540D89DBE1F09B24F17B7F35B81350E8D381C1558B075C28EA913C450D |
SHA-512: | 0BFB19AEC453A1C4D4B8F39602BF8BBF0A98182A98E29E1E1708EABFD99E3168855994A56061ED462C29B099137C226E25DDD274B46ED2F443C2C515A530B731 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1457 |
Entropy (8bit): | 4.776404629803053 |
Encrypted: | false |
SSDEEP: | 24:hYjkspFAuaDg5+DCpdgcxtYKvjHpe02Xl2Xhs2XOj2X+3f2XJeA2Xp:4pl5lxNle0UwszfvmM |
MD5: | 52CFBC1B4884C4516016E2C8A7515B9F |
SHA1: | E129A780A626E1869EEE0852DE0462970A0D5501 |
SHA-256: | C8C3BCDB856B9ACFFA853124ED13A0CC96641691233004CBE9BF8E018EDB8F1B |
SHA-512: | CE1DD89707D51148A5336C91FE37C800BB82BD78E25451ED13793F4D7EA9373DF33AA9945C60BB1EB47615C98F4DABA3E5C9B136F270D4CB865B7A4185E6251B |
Malicious: | false |
Reputation: | low |
URL: | https://dl.dropboxusercontent.com/scl/fi/xzq2rs33dpjduvua667sd/Rechnung-RE2024-0095-vom-30.08.2024.zip?rlkey=koe0h2f8n3e9e0lg1kwvqsis1&st=s5ax4axs&dl=0 |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 152
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 24, 2024 13:19:38.056181908 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Sep 24, 2024 13:19:38.359877110 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Sep 24, 2024 13:19:38.964879990 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Sep 24, 2024 13:19:39.481264114 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:39.481312990 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:39.481390953 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:39.481663942 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:39.481725931 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:39.481801987 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:39.481919050 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:39.481936932 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:39.482124090 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:39.482156992 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.128479004 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.128849983 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.128889084 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.130564928 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.130682945 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.130722046 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.130784988 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.131896973 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.132013083 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.132179022 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.132205963 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.139797926 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.140083075 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.140100956 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.141563892 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.141642094 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.141650915 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.141691923 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.142000914 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.142080069 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.169038057 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Sep 24, 2024 13:19:40.184889078 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.184910059 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.184935093 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.231884956 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.616290092 CEST | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:19:40.915612936 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.915667057 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.915739059 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.915822029 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.915859938 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.915921926 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.922068119 CEST | 49707 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:19:40.922110081 CEST | 443 | 49707 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:19:40.960659027 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:40.960717916 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:40.960776091 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:40.961133957 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:40.961154938 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.605134964 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.605456114 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.605519056 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.607119083 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.607192039 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.608259916 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.608355999 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.609071016 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.609081030 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.654880047 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.871779919 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.890178919 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.890191078 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.890233994 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.890256882 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.890338898 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.890363932 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.890363932 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.890400887 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.890563011 CEST | 49711 | 443 | 192.168.2.16 | 52.222.236.19 |
Sep 24, 2024 13:19:41.890582085 CEST | 443 | 49711 | 52.222.236.19 | 192.168.2.16 |
Sep 24, 2024 13:19:41.915169954 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:41.915247917 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:41.915345907 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:41.915535927 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:41.915565968 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.552917004 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.553196907 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.553258896 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.556911945 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.556993008 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.557370901 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.557524920 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.557543993 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.577897072 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Sep 24, 2024 13:19:42.608886957 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.608923912 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.656897068 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.827996969 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.828100920 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.828120947 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.828155994 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.828176022 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.828177929 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.828234911 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.828264952 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.828264952 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.828367949 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:42.828430891 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.828795910 CEST | 49715 | 443 | 192.168.2.16 | 52.222.236.51 |
Sep 24, 2024 13:19:42.828828096 CEST | 443 | 49715 | 52.222.236.51 | 192.168.2.16 |
Sep 24, 2024 13:19:43.416356087 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:43.416470051 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:43.416541100 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:43.416754961 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:43.416790009 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:44.064943075 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:44.065216064 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:44.065295935 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:44.066946030 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:44.067065001 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:44.067959070 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:44.068053961 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:44.108897924 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:44.108923912 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:44.156941891 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:44.348830938 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:44.348927021 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:44.349029064 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:44.351476908 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:44.351509094 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.008717060 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.008850098 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.011970043 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.011997938 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.012413979 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.061280012 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.107407093 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.278094053 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.278248072 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.278367043 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.278477907 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.278506041 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.278522968 CEST | 49723 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.278531075 CEST | 443 | 49723 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.400876999 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.400926113 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:45.401026964 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.403043985 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:45.403067112 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.046335936 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.046427011 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:46.047595024 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:46.047612906 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.048511028 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.049887896 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:46.091418028 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.224216938 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Sep 24, 2024 13:19:46.319633007 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.319715977 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.319823980 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:46.320794106 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:46.320816994 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.320835114 CEST | 49724 | 443 | 192.168.2.16 | 184.28.90.27 |
Sep 24, 2024 13:19:46.320841074 CEST | 443 | 49724 | 184.28.90.27 | 192.168.2.16 |
Sep 24, 2024 13:19:46.525911093 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Sep 24, 2024 13:19:47.127954006 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Sep 24, 2024 13:19:47.287097931 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:47.287216902 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:47.287350893 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:47.288527966 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:47.288564920 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:47.382906914 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Sep 24, 2024 13:19:47.906322002 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:47.906395912 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:47.917766094 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:47.917785883 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:47.918051004 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:47.968920946 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.011328936 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.055411100 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.206841946 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.206878901 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.206886053 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.206895113 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.206937075 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.206968069 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.206993103 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.207031012 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.207093954 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.207483053 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.207541943 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.207547903 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.207602978 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.207653046 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.225008011 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.225034952 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.225054026 CEST | 49725 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:19:48.225060940 CEST | 443 | 49725 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:19:48.336934090 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Sep 24, 2024 13:19:50.687231064 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:19:50.750905991 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Sep 24, 2024 13:19:50.990907907 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:19:51.595977068 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:19:52.807991028 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:19:53.987898111 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:53.988065958 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:53.988169909 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:54.913480043 CEST | 49721 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:19:54.913547039 CEST | 443 | 49721 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:19:55.215991020 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:19:55.565967083 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Sep 24, 2024 13:19:56.988943100 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Sep 24, 2024 13:20:00.025044918 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:20:05.174062014 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Sep 24, 2024 13:20:09.625988960 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Sep 24, 2024 13:20:24.766876936 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:24.766918898 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:24.767041922 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:24.767483950 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:24.767498970 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:24.993300915 CEST | 49697 | 80 | 192.168.2.16 | 199.232.210.172 |
Sep 24, 2024 13:20:24.993300915 CEST | 49698 | 80 | 192.168.2.16 | 199.232.210.172 |
Sep 24, 2024 13:20:24.998398066 CEST | 80 | 49697 | 199.232.210.172 | 192.168.2.16 |
Sep 24, 2024 13:20:24.998491049 CEST | 49697 | 80 | 192.168.2.16 | 199.232.210.172 |
Sep 24, 2024 13:20:24.998878002 CEST | 80 | 49698 | 199.232.210.172 | 192.168.2.16 |
Sep 24, 2024 13:20:24.998976946 CEST | 49698 | 80 | 192.168.2.16 | 199.232.210.172 |
Sep 24, 2024 13:20:25.185008049 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:20:25.185025930 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:20:25.372284889 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.372385979 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.374063969 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.374073029 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.374465942 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.375873089 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.423405886 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.576122999 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.576178074 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.576220989 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.576261044 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.576273918 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.576303959 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.576319933 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.577545881 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.577589989 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.577613115 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.577617884 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.577641964 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.577785015 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.577838898 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.579319000 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.579330921 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:25.579351902 CEST | 49726 | 443 | 192.168.2.16 | 20.12.23.50 |
Sep 24, 2024 13:20:25.579356909 CEST | 443 | 49726 | 20.12.23.50 | 192.168.2.16 |
Sep 24, 2024 13:20:40.903563023 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:20:40.903798103 CEST | 443 | 49706 | 162.125.66.15 | 192.168.2.16 |
Sep 24, 2024 13:20:40.903892994 CEST | 49706 | 443 | 192.168.2.16 | 162.125.66.15 |
Sep 24, 2024 13:20:43.461293936 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:43.461333036 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:43.461451054 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:43.461683035 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:43.461698055 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:44.102813959 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:44.103157997 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:44.103174925 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:44.103888988 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:44.104214907 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:44.104305983 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:44.147273064 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:54.013293982 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:54.013448954 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:20:54.013641119 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:54.914921999 CEST | 49728 | 443 | 192.168.2.16 | 142.250.186.100 |
Sep 24, 2024 13:20:54.914937019 CEST | 443 | 49728 | 142.250.186.100 | 192.168.2.16 |
Sep 24, 2024 13:21:16.090451002 CEST | 49700 | 80 | 192.168.2.16 | 192.229.221.95 |
Sep 24, 2024 13:21:16.095776081 CEST | 80 | 49700 | 192.229.221.95 | 192.168.2.16 |
Sep 24, 2024 13:21:16.095865965 CEST | 49700 | 80 | 192.168.2.16 | 192.229.221.95 |
Sep 24, 2024 13:21:43.526621103 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Sep 24, 2024 13:21:43.526715040 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Sep 24, 2024 13:21:43.526828051 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Sep 24, 2024 13:21:43.527091980 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Sep 24, 2024 13:21:43.527113914 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Sep 24, 2024 13:21:44.171946049 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Sep 24, 2024 13:21:44.172329903 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Sep 24, 2024 13:21:44.172363997 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Sep 24, 2024 13:21:44.173877001 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Sep 24, 2024 13:21:44.174462080 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Sep 24, 2024 13:21:44.174900055 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Sep 24, 2024 13:21:44.228231907 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 24, 2024 13:19:38.641017914 CEST | 53 | 54063 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:38.653647900 CEST | 53 | 53141 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:39.460300922 CEST | 50378 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:39.460513115 CEST | 61891 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:39.468828917 CEST | 53 | 50378 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:39.480635881 CEST | 53 | 61891 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:39.705233097 CEST | 53 | 50976 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:40.938575029 CEST | 52738 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:40.939407110 CEST | 64914 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:40.940828085 CEST | 54034 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:40.941229105 CEST | 65170 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:40.950196028 CEST | 53 | 65170 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:40.960220098 CEST | 53 | 54034 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:41.895853996 CEST | 49204 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:41.896009922 CEST | 53464 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:41.903052092 CEST | 53 | 53464 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:41.914664984 CEST | 53 | 49204 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:43.333067894 CEST | 60140 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:43.333209991 CEST | 59724 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:43.406640053 CEST | 64440 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:43.406769037 CEST | 57676 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:19:43.413736105 CEST | 53 | 64440 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:43.415729046 CEST | 53 | 57676 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:19:56.788877010 CEST | 53 | 54439 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:20:15.802886009 CEST | 53 | 64949 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:20:38.568806887 CEST | 53 | 59138 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:20:38.804150105 CEST | 53 | 55274 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:20:42.383850098 CEST | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Sep 24, 2024 13:21:07.403579950 CEST | 53 | 62475 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:21:43.516273975 CEST | 61849 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:21:43.516479969 CEST | 57263 | 53 | 192.168.2.16 | 1.1.1.1 |
Sep 24, 2024 13:21:43.525033951 CEST | 53 | 61849 | 1.1.1.1 | 192.168.2.16 |
Sep 24, 2024 13:21:43.525738955 CEST | 53 | 57263 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 24, 2024 13:19:39.460300922 CEST | 192.168.2.16 | 1.1.1.1 | 0xd973 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 13:19:39.460513115 CEST | 192.168.2.16 | 1.1.1.1 | 0x93ac | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 13:19:40.938575029 CEST | 192.168.2.16 | 1.1.1.1 | 0xec31 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 13:19:40.939407110 CEST | 192.168.2.16 | 1.1.1.1 | 0x661e | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 13:19:40.940828085 CEST | 192.168.2.16 | 1.1.1.1 | 0x1d3f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 13:19:40.941229105 CEST | 192.168.2.16 | 1.1.1.1 | 0x78f0 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 13:19:41.895853996 CEST | 192.168.2.16 | 1.1.1.1 | 0xbd29 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 13:19:41.896009922 CEST | 192.168.2.16 | 1.1.1.1 | 0x12d3 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 13:19:43.333067894 CEST | 192.168.2.16 | 1.1.1.1 | 0x9ce8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 13:19:43.333209991 CEST | 192.168.2.16 | 1.1.1.1 | 0x1812 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 13:19:43.406640053 CEST | 192.168.2.16 | 1.1.1.1 | 0x6f8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 13:19:43.406769037 CEST | 192.168.2.16 | 1.1.1.1 | 0x35e7 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 13:21:43.516273975 CEST | 192.168.2.16 | 1.1.1.1 | 0x600a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 13:21:43.516479969 CEST | 192.168.2.16 | 1.1.1.1 | 0x582 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 24, 2024 13:19:39.468828917 CEST | 1.1.1.1 | 192.168.2.16 | 0xd973 | No error (0) | edge-block-www-env.dropbox-dns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:39.468828917 CEST | 1.1.1.1 | 192.168.2.16 | 0xd973 | No error (0) | 162.125.66.15 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:39.480635881 CEST | 1.1.1.1 | 192.168.2.16 | 0x93ac | No error (0) | edge-block-www-env.dropbox-dns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:40.948230982 CEST | 1.1.1.1 | 192.168.2.16 | 0x661e | No error (0) | cfl.dropboxstatic.com.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:40.949345112 CEST | 1.1.1.1 | 192.168.2.16 | 0xec31 | No error (0) | cfl.dropboxstatic.com.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:40.960220098 CEST | 1.1.1.1 | 192.168.2.16 | 0x1d3f | No error (0) | 52.222.236.19 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:40.960220098 CEST | 1.1.1.1 | 192.168.2.16 | 0x1d3f | No error (0) | 52.222.236.51 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:40.960220098 CEST | 1.1.1.1 | 192.168.2.16 | 0x1d3f | No error (0) | 52.222.236.37 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:40.960220098 CEST | 1.1.1.1 | 192.168.2.16 | 0x1d3f | No error (0) | 52.222.236.76 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:41.914664984 CEST | 1.1.1.1 | 192.168.2.16 | 0xbd29 | No error (0) | 52.222.236.51 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:41.914664984 CEST | 1.1.1.1 | 192.168.2.16 | 0xbd29 | No error (0) | 52.222.236.76 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:41.914664984 CEST | 1.1.1.1 | 192.168.2.16 | 0xbd29 | No error (0) | 52.222.236.37 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:41.914664984 CEST | 1.1.1.1 | 192.168.2.16 | 0xbd29 | No error (0) | 52.222.236.19 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:43.340756893 CEST | 1.1.1.1 | 192.168.2.16 | 0x1812 | No error (0) | cfl.dropboxstatic.com.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:43.340975046 CEST | 1.1.1.1 | 192.168.2.16 | 0x9ce8 | No error (0) | cfl.dropboxstatic.com.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:43.413736105 CEST | 1.1.1.1 | 192.168.2.16 | 0x6f8 | No error (0) | 142.250.186.100 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:19:43.415729046 CEST | 1.1.1.1 | 192.168.2.16 | 0x35e7 | No error (0) | 65 | IN (0x0001) | false | |||
Sep 24, 2024 13:21:43.525033951 CEST | 1.1.1.1 | 192.168.2.16 | 0x600a | No error (0) | 216.58.206.36 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 13:21:43.525738955 CEST | 1.1.1.1 | 192.168.2.16 | 0x582 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49707 | 162.125.66.15 | 443 | 7032 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 11:19:40 UTC | 785 | OUT | |
2024-09-24 11:19:40 UTC | 442 | IN | |
2024-09-24 11:19:40 UTC | 1457 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49711 | 52.222.236.19 | 443 | 7032 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 11:19:41 UTC | 596 | OUT | |
2024-09-24 11:19:41 UTC | 741 | IN | |
2024-09-24 11:19:41 UTC | 9594 | IN | |
2024-09-24 11:19:41 UTC | 1041 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49715 | 52.222.236.51 | 443 | 7032 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 11:19:42 UTC | 396 | OUT | |
2024-09-24 11:19:42 UTC | 741 | IN | |
2024-09-24 11:19:42 UTC | 10635 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49723 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 11:19:45 UTC | 161 | OUT | |
2024-09-24 11:19:45 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49724 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 11:19:46 UTC | 239 | OUT | |
2024-09-24 11:19:46 UTC | 514 | IN | |
2024-09-24 11:19:46 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49725 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 11:19:48 UTC | 306 | OUT | |
2024-09-24 11:19:48 UTC | 560 | IN | |
2024-09-24 11:19:48 UTC | 15824 | IN | |
2024-09-24 11:19:48 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49726 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 11:20:25 UTC | 306 | OUT | |
2024-09-24 11:20:25 UTC | 560 | IN | |
2024-09-24 11:20:25 UTC | 15824 | IN | |
2024-09-24 11:20:25 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 07:19:37 |
Start date: | 24/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 07:19:37 |
Start date: | 24/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 07:19:38 |
Start date: | 24/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |