Windows
Analysis Report
https://tony.anka.cloudns.ch/
Overview
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 2472 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 4828 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2088 --fi eld-trial- handle=199 6,i,268182 2349777175 37,5996108 0673247311 32,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction /pre fetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6440 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://tony. anka.cloud ns.ch/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • AV Detection
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | unknown | |
www.google.com | 142.250.186.132 | true | false | unknown | |
anka-9vi.pages.dev | 172.66.47.81 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown | |
tony.anka.cloudns.ch | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false |
| unknown | |
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.66.47.81 | anka-9vi.pages.dev | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.186.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.8 |
192.168.2.7 |
192.168.2.4 |
192.168.2.5 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1516689 |
Start date and time: | 2024-09-24 14:34:58 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://tony.anka.cloudns.ch/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@21/5@8/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, W MIADAP.exe, SIHClient.exe, con host.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.185.206, 1 08.177.15.84, 142.250.185.227, 34.104.35.123, 13.85.23.86, 9 3.184.221.240, 13.95.31.18, 19 2.229.221.95, 142.250.185.131 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com.delivery.micr osoft.com, wu.ec.azureedge.net , clientservices.googleapis.co m, ctldl.windowsupdate.com, wu .azureedge.net, fe3cr.delivery .mp.microsoft.com, fe3.deliver y.mp.microsoft.com, clients2.g oogle.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52d d2-0503.edgecastdns.net, cs11. wpc.v0cdn.net, glb.cws.prod.dc at.dsp.trafficmanager.net, ocs p.edge.digicert.com, sls.updat e.microsoft.com, hlb.apr-52dd2 -0.edgecastdns.net, update.goo gleapis.com, clients.l.google. com, wu-b-net.trafficmanager.n et, glb.sls.prod.dcat.dsp.traf ficmanager.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - VT rate limit hit for: https:
//tony.anka.cloudns.ch/
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6755 |
Entropy (8bit): | 7.943115818179426 |
Encrypted: | false |
SSDEEP: | 96:JkBFJQh0YvZiy/G2XovJnx1dcFOBv+194cfd1eEwtD/8R1GeJrYcNmbTZgI46N57:JozlYvZiy/G2eNdPICcGHSdekmxNsKJB |
MD5: | 9CEF637DDFBA594AC6DEE7FD68E85A95 |
SHA1: | 2481A8461CFEEDFE82BC5F7257848B12140E30B4 |
SHA-256: | 698FC7056302AC9EA260AAD79C23B0F2428ED78A2434F2148D4EA4606BA00084 |
SHA-512: | 12C0561E62CFC78D98E0D8650C90C5E8B560CA6D3EDB2D61BD7FC0E7E210B6E47E98DE5157B20A0F30C54E6F8C64B12F661ED26768DE55D9E6A241A7B42150C7 |
Malicious: | false |
Reputation: | low |
URL: | https://tony.anka.cloudns.ch/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 318 |
Entropy (8bit): | 2.918342372066458 |
Encrypted: | false |
SSDEEP: | 3:PFErXllvlNl/AXll/lFl/Ft/HtAiotuZt/k7vnck2sLC1GDER9RrmvRSjJSEJlbA:k9ij1k7/D+1tSSd3rbD4qM/ |
MD5: | A14E5365CC2B27EC57E1AB7866C6A228 |
SHA1: | 37FC3645C16A1CBD74D8A6B7EF8756BBF0A3E857 |
SHA-256: | 43C6594EB74940C6E0FB38D55C634425860093660F4EB0CB89334608DD9947EB |
SHA-512: | C00B830BEEB9666EF83401919B1B5B564BC5FFE81073BB8B9094450DB1C838D9AB6A47E6C3F33730420F6B9F2151542F66E12F58B76E93F8840E0D0BECD7B862 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 44 |
Entropy (8bit): | 3.9905863803852366 |
Encrypted: | false |
SSDEEP: | 3:0MXAGkthjQMjLSABLn:0MQ95j39n |
MD5: | 9BA3C1B0D129DD5D647F87E2B04F125D |
SHA1: | 37C3571ED505E7505D256E2BA689DE5D1F91F5D4 |
SHA-256: | 15A3FACCCE6D4759E2426C91C6D1AE5E93AEEB49CB7B6CB5DEA76311EE45CDB2 |
SHA-512: | 09CA7B4DE67FF5C197F4B4367A3DCC264A46D789DE805CD2B6BD76D4D79AE93B0ADF65B6DF1D41F3896462F19E0DF762DA663A92B37C33DC76F092E26F2129A4 |
Malicious: | false |
Reputation: | low |
URL: | https://tony.anka.cloudns.ch/ |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 140
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 24, 2024 14:35:55.054474115 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Sep 24, 2024 14:35:56.331732988 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.331794024 CEST | 443 | 49735 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.331932068 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.332169056 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.332277060 CEST | 443 | 49736 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.332353115 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.332490921 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.332504988 CEST | 443 | 49735 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.332729101 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.332766056 CEST | 443 | 49736 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.806169033 CEST | 443 | 49735 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.806612968 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.806652069 CEST | 443 | 49735 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.807724953 CEST | 443 | 49735 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.807806015 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809154987 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809154987 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809267998 CEST | 443 | 49735 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.809281111 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809410095 CEST | 49735 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809565067 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809614897 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.809685946 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809875965 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.809890985 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.810180902 CEST | 443 | 49736 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.810405970 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.810439110 CEST | 443 | 49736 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.811479092 CEST | 443 | 49736 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.811539888 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.812494040 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.812522888 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.812551975 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.812578917 CEST | 443 | 49736 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.812623024 CEST | 49736 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.812803030 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.812840939 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:56.812906027 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.813080072 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:56.813097954 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.271568060 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.271929979 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.272000074 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.273027897 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.273127079 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.274498940 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.274575949 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.274837971 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.274857998 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.285024881 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.285260916 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.285317898 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.286375046 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.286546946 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.286765099 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.286835909 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.321327925 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.337263107 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:57.337299109 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:57.385134935 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:58.151976109 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.152031898 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:35:58.152118921 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.153085947 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.153104067 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:35:58.419562101 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:58.419641972 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:58.419698000 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:58.425349951 CEST | 49738 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:58.425368071 CEST | 443 | 49738 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:58.445554972 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:58.445615053 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.445679903 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:58.449647903 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:58.449675083 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.550115108 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:35:58.591434002 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:35:58.786361933 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:35:58.787492990 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.787528992 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:35:58.789002895 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:35:58.789074898 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.792932987 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.793064117 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:35:58.837940931 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.837986946 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:35:58.882184029 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:35:58.928546906 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.930023909 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:58.930042028 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.931180000 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.931262016 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:58.941688061 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:58.941848993 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.942476034 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:58.942487001 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.991544008 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.070377111 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.070458889 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.070511103 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.071013927 CEST | 49742 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.071042061 CEST | 443 | 49742 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.071997881 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.072050095 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.072118044 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.072505951 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.072524071 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.124157906 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:35:59.124212027 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:35:59.124295950 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:35:59.139586926 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:35:59.139631033 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:35:59.528110981 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.528677940 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.528714895 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.529078007 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.532834053 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.533066988 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.533126116 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.575408936 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.586572886 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.658725977 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.658889055 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.659363031 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.661247969 CEST | 49744 | 443 | 192.168.2.4 | 35.190.80.1 |
Sep 24, 2024 14:35:59.661278009 CEST | 443 | 49744 | 35.190.80.1 | 192.168.2.4 |
Sep 24, 2024 14:35:59.812299013 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:35:59.812422991 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:35:59.818783998 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:35:59.818800926 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:35:59.819113970 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:35:59.867834091 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:00.228766918 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:00.271404028 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:00.419420004 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:00.419960022 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:00.420160055 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:00.440361977 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:00.440387964 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:00.580413103 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:00.580471992 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:00.580544949 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:00.582947969 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:00.582967043 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.220901966 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.221023083 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:01.222372055 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:01.222408056 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.222688913 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.224440098 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:01.267401934 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.496860981 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.496928930 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.497160912 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:01.499027014 CEST | 49746 | 443 | 192.168.2.4 | 184.28.90.27 |
Sep 24, 2024 14:36:01.499042988 CEST | 443 | 49746 | 184.28.90.27 | 192.168.2.4 |
Sep 24, 2024 14:36:01.542675018 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.542745113 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.542783022 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.542824984 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.542850018 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.542860985 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.542927980 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.542964935 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.542989016 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.543004036 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.543081999 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.543139935 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.669053078 CEST | 49739 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.669105053 CEST | 443 | 49739 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.743144035 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.743213892 CEST | 443 | 49747 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:01.743290901 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.744272947 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:01.744307041 CEST | 443 | 49747 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.207093000 CEST | 443 | 49747 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.207442999 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.207487106 CEST | 443 | 49747 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.216725111 CEST | 443 | 49747 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.216813087 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.218684912 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.218751907 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.218841076 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.218864918 CEST | 443 | 49747 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.218926907 CEST | 49747 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.219584942 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.219630003 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.219796896 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.220124006 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.220136881 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.681297064 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.683897972 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.683936119 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.684990883 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.685066938 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.685511112 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.685753107 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.685754061 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.726351023 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:02.726389885 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:02.773247004 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:03.779537916 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:03.779639006 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:03.779697895 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:03.780723095 CEST | 49748 | 443 | 192.168.2.4 | 172.66.47.81 |
Sep 24, 2024 14:36:03.780750036 CEST | 443 | 49748 | 172.66.47.81 | 192.168.2.4 |
Sep 24, 2024 14:36:08.697587013 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:08.697674036 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:08.697837114 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:36:10.620075941 CEST | 49741 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:36:10.620121002 CEST | 443 | 49741 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:10.781414032 CEST | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Sep 24, 2024 14:36:11.086323977 CEST | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Sep 24, 2024 14:36:11.109435081 CEST | 80 | 49723 | 199.232.210.172 | 192.168.2.4 |
Sep 24, 2024 14:36:11.109519005 CEST | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Sep 24, 2024 14:36:11.110049963 CEST | 80 | 49723 | 199.232.210.172 | 192.168.2.4 |
Sep 24, 2024 14:36:35.312793016 CEST | 57689 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:36:35.317750931 CEST | 53 | 57689 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:35.317838907 CEST | 57689 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:36:35.317944050 CEST | 57689 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:36:35.322758913 CEST | 53 | 57689 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:35.776264906 CEST | 53 | 57689 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:35.783030033 CEST | 57689 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:36:35.788271904 CEST | 53 | 57689 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:35.788330078 CEST | 57689 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:36:58.166934013 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:36:58.166987896 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:58.167124033 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:36:58.167375088 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:36:58.167391062 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:58.831763029 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:58.832154989 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:36:58.832181931 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:58.832655907 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:58.833370924 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:36:58.833456039 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:36:58.885341883 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:37:00.073561907 CEST | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Sep 24, 2024 14:37:00.078784943 CEST | 80 | 49724 | 199.232.210.172 | 192.168.2.4 |
Sep 24, 2024 14:37:00.078876019 CEST | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Sep 24, 2024 14:37:07.396910906 CEST | 59690 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:37:07.401786089 CEST | 53 | 59690 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:37:07.401858091 CEST | 59690 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:37:07.401999950 CEST | 59690 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:37:07.407011986 CEST | 53 | 59690 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:37:07.845948935 CEST | 53 | 59690 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:37:07.846307993 CEST | 59690 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:37:07.851475954 CEST | 53 | 59690 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:37:07.851530075 CEST | 59690 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:37:08.737499952 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:37:08.737576962 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Sep 24, 2024 14:37:08.737642050 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:37:10.606934071 CEST | 57693 | 443 | 192.168.2.4 | 142.250.186.132 |
Sep 24, 2024 14:37:10.606965065 CEST | 443 | 57693 | 142.250.186.132 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 24, 2024 14:35:54.369360924 CEST | 53 | 61810 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:54.369458914 CEST | 53 | 54705 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:55.447381973 CEST | 53 | 63953 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:56.070605993 CEST | 65535 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:35:56.070761919 CEST | 63781 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:35:56.330543995 CEST | 53 | 65535 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:56.330595970 CEST | 53 | 63781 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.110553980 CEST | 51269 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:35:58.111002922 CEST | 64968 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:35:58.117940903 CEST | 53 | 51269 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.118130922 CEST | 53 | 64968 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.423533916 CEST | 52451 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:35:58.424088001 CEST | 55047 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:35:58.430587053 CEST | 53 | 52451 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:35:58.431921005 CEST | 53 | 55047 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:01.686959982 CEST | 51491 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:36:01.687294960 CEST | 56608 | 53 | 192.168.2.4 | 1.1.1.1 |
Sep 24, 2024 14:36:01.728408098 CEST | 53 | 51491 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:01.742491007 CEST | 53 | 56608 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:11.734477043 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Sep 24, 2024 14:36:12.517271042 CEST | 53 | 60139 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:31.268397093 CEST | 53 | 50359 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:35.312321901 CEST | 53 | 55548 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:36:54.211942911 CEST | 53 | 64902 | 1.1.1.1 | 192.168.2.4 |
Sep 24, 2024 14:37:07.394593954 CEST | 53 | 53367 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 24, 2024 14:35:56.070605993 CEST | 192.168.2.4 | 1.1.1.1 | 0xde87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 14:35:56.070761919 CEST | 192.168.2.4 | 1.1.1.1 | 0x9c0f | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 14:35:58.110553980 CEST | 192.168.2.4 | 1.1.1.1 | 0xbbfb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 14:35:58.111002922 CEST | 192.168.2.4 | 1.1.1.1 | 0x6090 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 14:35:58.423533916 CEST | 192.168.2.4 | 1.1.1.1 | 0x232a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 14:35:58.424088001 CEST | 192.168.2.4 | 1.1.1.1 | 0xe0f3 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 24, 2024 14:36:01.686959982 CEST | 192.168.2.4 | 1.1.1.1 | 0xb9dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 24, 2024 14:36:01.687294960 CEST | 192.168.2.4 | 1.1.1.1 | 0xf2c6 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 24, 2024 14:35:56.330543995 CEST | 1.1.1.1 | 192.168.2.4 | 0xde87 | No error (0) | anka-9vi.pages.dev | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 14:35:56.330543995 CEST | 1.1.1.1 | 192.168.2.4 | 0xde87 | No error (0) | 172.66.47.81 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 14:35:56.330543995 CEST | 1.1.1.1 | 192.168.2.4 | 0xde87 | No error (0) | 172.66.44.175 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 14:35:56.330595970 CEST | 1.1.1.1 | 192.168.2.4 | 0x9c0f | No error (0) | anka-9vi.pages.dev | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 14:35:56.330595970 CEST | 1.1.1.1 | 192.168.2.4 | 0x9c0f | No error (0) | 65 | IN (0x0001) | false | |||
Sep 24, 2024 14:35:58.117940903 CEST | 1.1.1.1 | 192.168.2.4 | 0xbbfb | No error (0) | 142.250.186.132 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 14:35:58.118130922 CEST | 1.1.1.1 | 192.168.2.4 | 0x6090 | No error (0) | 65 | IN (0x0001) | false | |||
Sep 24, 2024 14:35:58.430587053 CEST | 1.1.1.1 | 192.168.2.4 | 0x232a | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:01.728408098 CEST | 1.1.1.1 | 192.168.2.4 | 0xb9dc | No error (0) | anka-9vi.pages.dev | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:01.728408098 CEST | 1.1.1.1 | 192.168.2.4 | 0xb9dc | No error (0) | 172.66.47.81 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:01.728408098 CEST | 1.1.1.1 | 192.168.2.4 | 0xb9dc | No error (0) | 172.66.44.175 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:01.742491007 CEST | 1.1.1.1 | 192.168.2.4 | 0xf2c6 | No error (0) | anka-9vi.pages.dev | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:01.742491007 CEST | 1.1.1.1 | 192.168.2.4 | 0xf2c6 | No error (0) | 65 | IN (0x0001) | false | |||
Sep 24, 2024 14:36:12.446031094 CEST | 1.1.1.1 | 192.168.2.4 | 0x3b5c | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:12.446031094 CEST | 1.1.1.1 | 192.168.2.4 | 0x3b5c | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:27.594063997 CEST | 1.1.1.1 | 192.168.2.4 | 0x930d | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 24, 2024 14:36:27.594063997 CEST | 1.1.1.1 | 192.168.2.4 | 0x930d | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49738 | 172.66.47.81 | 443 | 4828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 12:35:57 UTC | 663 | OUT | |
2024-09-24 12:35:58 UTC | 529 | IN | |
2024-09-24 12:35:58 UTC | 44 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49739 | 172.66.47.81 | 443 | 4828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 12:35:58 UTC | 596 | OUT | |
2024-09-24 12:36:01 UTC | 1336 | IN | |
2024-09-24 12:36:01 UTC | 33 | IN | |
2024-09-24 12:36:01 UTC | 1369 | IN | |
2024-09-24 12:36:01 UTC | 1369 | IN | |
2024-09-24 12:36:01 UTC | 1369 | IN | |
2024-09-24 12:36:01 UTC | 1369 | IN | |
2024-09-24 12:36:01 UTC | 1254 | IN | |
2024-09-24 12:36:01 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49742 | 35.190.80.1 | 443 | 4828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 12:35:58 UTC | 553 | OUT | |
2024-09-24 12:35:59 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49744 | 35.190.80.1 | 443 | 4828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 12:35:59 UTC | 490 | OUT | |
2024-09-24 12:35:59 UTC | 390 | OUT | |
2024-09-24 12:35:59 UTC | 168 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49745 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 12:36:00 UTC | 161 | OUT | |
2024-09-24 12:36:00 UTC | 494 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49746 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 12:36:01 UTC | 239 | OUT | |
2024-09-24 12:36:01 UTC | 514 | IN | |
2024-09-24 12:36:01 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49748 | 172.66.47.81 | 443 | 4828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-24 12:36:02 UTC | 355 | OUT | |
2024-09-24 12:36:03 UTC | 1235 | IN | |
2024-09-24 12:36:03 UTC | 134 | IN | |
2024-09-24 12:36:03 UTC | 184 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:35:50 |
Start date: | 24/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:35:52 |
Start date: | 24/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 08:35:55 |
Start date: | 24/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |