Edit tour
Windows
Analysis Report
file.exe
Overview
General Information
Detection
Credential Flusher
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for submitted file
Yara detected Credential Flusher
AI detected suspicious sample
Binary is likely a compiled AutoIt script file
Found API chain indicative of sandbox detection
Machine Learning detection for sample
Contains functionality for read data from the clipboard
Contains functionality to block mouse and keyboard input (often used to hinder debugging)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to execute programs as a different user
Contains functionality to launch a process as a different user
Contains functionality to launch a program with higher privileges
Contains functionality to modify clipboard data
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality to simulate keystroke presses
Contains functionality to simulate mouse events
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
OS version to string mapping found (often used in BOTs)
Potential key logger detected (key state polling based)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Classification
- System is w10x64
- file.exe (PID: 6780 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 0083D14C374EACC7490D77CF1C0EC24D) - chrome.exe (PID: 6832 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ap p="https:/ /youtube.c om/account ?=https:// accounts.g oogle.com/ v3/signin/ challenge/ pwd" --sta rt-fullscr een --no-f irst-run - -disable-s ession-cra shed-bubbl e --disabl e-features =CrashReco very MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3244 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2136 --fi eld-trial- handle=208 0,i,138750 5458442546 2490,14288 1349427256 12422,2621 44 --disab le-feature s=CrashRec overy /pre fetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7816 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --m ojo-platfo rm-channel -handle=32 00 --field -trial-han dle=2080,i ,138750545 8442546249 0,14288134 9427256124 22,262144 --disable- features=C rashRecove ry /prefet ch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7824 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= video_capt ure.mojom. VideoCaptu reService --lang=en- US --servi ce-sandbox -type=none --mojo-pl atform-cha nnel-handl e=5540 --f ield-trial -handle=20 80,i,13875 0545844254 62490,1428 8134942725 612422,262 144 --disa ble-featur es=CrashRe covery /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialFlusher | Yara detected Credential Flusher | Joe Security | ||
JoeSecurity_CredentialFlusher | Yara detected Credential Flusher | Joe Security |
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00C4DBBE | |
Source: | Code function: | 0_2_00C568EE | |
Source: | Code function: | 0_2_00C5698F | |
Source: | Code function: | 0_2_00C4D076 | |
Source: | Code function: | 0_2_00C4D3A9 | |
Source: | Code function: | 0_2_00C59642 | |
Source: | Code function: | 0_2_00C5979D | |
Source: | Code function: | 0_2_00C59B2B | |
Source: | Code function: | 0_2_00C55C97 |
Source: | TCP traffic: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_00C5CE44 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00C5EAFF |
Source: | Code function: | 0_2_00C5ED6A |
Source: | Code function: | 0_2_00C5EAFF |
Source: | Code function: | 0_2_00C4AA57 |
Source: | Code function: | 0_2_00C79576 |
System Summary |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | memstr_6e354f6f-d | |
Source: | String found in binary or memory: | memstr_472f4578-e | |
Source: | String found in binary or memory: | memstr_7e81df6d-3 | |
Source: | String found in binary or memory: | memstr_ebf758a2-3 |
Source: | Code function: | 0_2_00C4D5EB |
Source: | Code function: | 0_2_00C41201 |
Source: | Code function: | 0_2_00C4E8F6 |
Source: | Code function: | 0_2_00C52046 | |
Source: | Code function: | 0_2_00BE8060 | |
Source: | Code function: | 0_2_00C48298 | |
Source: | Code function: | 0_2_00C1E4FF | |
Source: | Code function: | 0_2_00C1676B | |
Source: | Code function: | 0_2_00C74873 | |
Source: | Code function: | 0_2_00BECAF0 | |
Source: | Code function: | 0_2_00C0CAA0 | |
Source: | Code function: | 0_2_00BFCC39 | |
Source: | Code function: | 0_2_00C16DD9 | |
Source: | Code function: | 0_2_00BE91C0 | |
Source: | Code function: | 0_2_00BFB119 | |
Source: | Code function: | 0_2_00C01394 | |
Source: | Code function: | 0_2_00C01706 | |
Source: | Code function: | 0_2_00C0781B | |
Source: | Code function: | 0_2_00C019B0 | |
Source: | Code function: | 0_2_00BE7920 | |
Source: | Code function: | 0_2_00BF997D | |
Source: | Code function: | 0_2_00C07A4A | |
Source: | Code function: | 0_2_00C07CA7 | |
Source: | Code function: | 0_2_00C01C77 | |
Source: | Code function: | 0_2_00C19EEE | |
Source: | Code function: | 0_2_00C6BE44 | |
Source: | Code function: | 0_2_00C01F32 |
Source: | Code function: | ||
Source: | Code function: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00C537B5 |
Source: | Code function: | 0_2_00C410BF | |
Source: | Code function: | 0_2_00C416C3 |
Source: | Code function: | 0_2_00C551CD |
Source: | Code function: | 0_2_00C4D4DC |
Source: | Code function: | 0_2_00C5648E |
Source: | Code function: | 0_2_00BE42A2 |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Window detected: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00BE42DE |
Source: | Code function: | 0_2_00C00A89 | |
Source: | Code function: | 0_2_00BED01E | |
Source: | Code function: | 0_2_00BF1266 | |
Source: | Code function: | 0_2_00BF1262 | |
Source: | Code function: | 0_2_00BF1256 | |
Source: | Code function: | 0_2_00BF1252 | |
Source: | Code function: | 0_2_00BF124E | |
Source: | Code function: | 0_2_00BF124A | |
Source: | Code function: | 0_2_00C356DA | |
Source: | Code function: | 0_2_00C356EA | |
Source: | Code function: | 0_2_00C357E2 | |
Source: | Code function: | 0_2_00C357FE | |
Source: | Code function: | 0_2_00C3179D | |
Source: | Code function: | 0_2_00C31789 | |
Source: | Code function: | 0_2_00C3578A | |
Source: | Code function: | 0_2_00C3579A | |
Source: | Code function: | 0_2_00C317A1 | |
Source: | Code function: | 0_2_00C317A5 | |
Source: | Code function: | 0_2_00C317A9 | |
Source: | Code function: | 0_2_00C317AD | |
Source: | Code function: | 0_2_00C317B1 | |
Source: | Code function: | 0_2_00C357B6 | |
Source: | Code function: | 0_2_00C35742 | |
Source: | Code function: | 0_2_00C3575E | |
Source: | Code function: | 0_2_00C3576E | |
Source: | Code function: | 0_2_00C35712 | |
Source: | Code function: | 0_2_00C35706 | |
Source: | Code function: | 0_2_00C35732 | |
Source: | Code function: | 0_2_00C35802 | |
Source: | Code function: | 0_2_00C35806 | |
Source: | Code function: | 0_2_00C3580A |
Source: | Code function: | 0_2_00BFF98E | |
Source: | Code function: | 0_2_00C71C41 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Sandbox detection routine: | graph_0-96139 |
Source: | API coverage: |
Source: | Code function: | 0_2_00C4DBBE | |
Source: | Code function: | 0_2_00C568EE | |
Source: | Code function: | 0_2_00C5698F | |
Source: | Code function: | 0_2_00C4D076 | |
Source: | Code function: | 0_2_00C4D3A9 | |
Source: | Code function: | 0_2_00C59642 | |
Source: | Code function: | 0_2_00C5979D | |
Source: | Code function: | 0_2_00C59B2B | |
Source: | Code function: | 0_2_00C55C97 |
Source: | Code function: | 0_2_00BE42DE |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00C5EAA2 |
Source: | Code function: | 0_2_00C12622 |
Source: | Code function: | 0_2_00BE42DE |
Source: | Code function: | 0_2_00C04CE8 |
Source: | Code function: | 0_2_00C40B62 |
Source: | Code function: | 0_2_00C12622 | |
Source: | Code function: | 0_2_00C0083F | |
Source: | Code function: | 0_2_00C009D5 | |
Source: | Code function: | 0_2_00C00C21 |
Source: | Code function: | 0_2_00C41201 |
Source: | Code function: | 0_2_00C22BA5 |
Source: | Code function: | 0_2_00C4B226 |
Source: | Code function: | 0_2_00C622DA |
Source: | Code function: | 0_2_00C40B62 |
Source: | Code function: | 0_2_00C41663 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00C00698 |
Source: | Code function: | 0_2_00C58195 |
Source: | Code function: | 0_2_00C3D27A |
Source: | Code function: | 0_2_00C1BB6F |
Source: | Code function: | 0_2_00BE42DE |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_00C61204 | |
Source: | Code function: | 0_2_00C61806 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 2 Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 Exploitation for Privilege Escalation | 1 Disable or Modify Tools | 21 Input Capture | 2 System Time Discovery | Remote Services | 1 Archive Collected Data | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 2 Valid Accounts | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 1 Account Discovery | Remote Desktop Protocol | 21 Input Capture | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 2 Valid Accounts | 2 Obfuscated Files or Information | Security Account Manager | 1 File and Directory Discovery | SMB/Windows Admin Shares | 3 Clipboard Data | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 21 Access Token Manipulation | 1 DLL Side-Loading | NTDS | 15 System Information Discovery | Distributed Component Object Model | Input Capture | 4 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 2 Process Injection | 2 Valid Accounts | LSA Secrets | 12 Security Software Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Virtualization/Sandbox Evasion | Cached Domain Credentials | 1 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 21 Access Token Manipulation | DCSync | 3 Process Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 2 Process Injection | Proc Filesystem | 1 Application Window Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 1 System Owner/User Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
17% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
youtube-ui.l.google.com | 142.250.186.78 | true | false |
| unknown |
www3.l.google.com | 142.250.186.142 | true | false |
| unknown |
play.google.com | 216.58.206.78 | true | false |
| unknown |
www.google.com | 142.250.181.228 | true | false |
| unknown |
youtube.com | 216.58.206.78 | true | false |
| unknown |
accounts.youtube.com | unknown | unknown | false |
| unknown |
www.youtube.com | unknown | unknown | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.78 | youtube-ui.l.google.com | United States | 15169 | GOOGLEUS | false | |
216.58.206.78 | play.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.181.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.186.142 | www3.l.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1523788 |
Start date and time: | 2024-10-02 03:00:08 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 44s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal72.troj.evad.winEXE@36/30@12/6 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.184.195, 172.217.18.14, 142.251.173.84, 34.104.35.123, 172.217.18.3, 142.250.185.234, 142.250.181.234, 172.217.18.10, 142.250.184.202, 142.250.185.170, 142.250.186.74, 172.217.16.202, 142.250.184.234, 142.250.74.202, 142.250.186.42, 142.250.186.170, 172.217.16.138, 216.58.206.74, 216.58.206.42, 142.250.186.106, 142.250.185.202, 142.250.185.74, 142.250.186.138, 216.58.212.170, 172.217.23.106, 172.217.18.106, 93.184.221.240, 192.229.221.95, 142.250.186.163, 108.177.15.84, 172.217.16.206
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, clients.l.google.com, www.gstatic.com, optimizationguide-pa.googleapis.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
⊘No simulations
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
239.255.255.250 | Get hash | malicious | Credential Flusher | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Credential Flusher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HtmlDropper | Browse | |||
Get hash | malicious | Credential Flusher | Browse |
⊘No context
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
28a2c9bd18a11de089ef85a160da29e4 | Get hash | malicious | Credential Flusher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
|
⊘No context
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1858 |
Entropy (8bit): | 5.298162049824456 |
Encrypted: | false |
SSDEEP: | 48:o7vGoolL3ALFKphnpiu7xOKAcfO/3d/rYh4vZorw:o/QLUFUL4KA+2y0Mw |
MD5: | CE055F881BDAB4EF6C1C8AA4B3890348 |
SHA1: | 2671741A70E9F5B608F690AAEEA4972003747654 |
SHA-256: | 9B91C23691D6032CDFE28863E369624B2EDB033E1487A1D1BB0977E3590E5462 |
SHA-512: | 8A22250628985C2E570E6FBADFC0D5CB6753F0735130F9E74962A409476C2859C5C81F8A0F5C427A9F13ED399C8E251FA43FF67AD5F16860640D45E7A538E857 |
Malicious: | false |
Reputation: | low |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=iAskyc,ziXSP" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3131 |
Entropy (8bit): | 5.355381206612617 |
Encrypted: | false |
SSDEEP: | 48:o7FEEM3MtH15jNQ8jsK3rnw0dkckTrKEp/OqLE9xz0W5Bzv3M6hIHYA+JITbwrF8:oq675jOArwoAmI/DLaxNPL5m+m6w |
MD5: | E2A7251AD83A0D0634FEA2703D10ED07 |
SHA1: | 90D72011F31FC40D3DA3748F2817F90A29EB5C01 |
SHA-256: | 1079B49C4AAF5C10E4F2E6A086623F40D200A71FF2A1F64E88AA6C91E4BE7A6F |
SHA-512: | CD6D75580EA8BD97CF7C7C0E0BD9D9A54FB6EA7DF1DDB5A95E94D38B260F9EE1425C640839ECD229B8D01E145CF2786CA374D31EC537EB8FE17FF415D5B985F5 |
Malicious: | false |
Reputation: | low |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ZwDk9d,RMhBfe" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Reputation: | high, very likely benign file |
URL: | https://www.google.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 698314 |
Entropy (8bit): | 5.595120835898624 |
Encrypted: | false |
SSDEEP: | 6144:TJvaKtQfcxene0F2HhPM8RGYcBlKmd5r6XISxi7SlncOpYMSrBg5X3O4mAEFD7:TJyKtkIct842ISxXJ09 |
MD5: | F82438F9EAD5F57493C673008EED9E09 |
SHA1: | E4681E68FD66D8C76C6ACBC21E2C45F36FD645BC |
SHA-256: | B4B092F54EAAA82BFAA159B8D61FB867B51C3067CBD60F4904A205A11F503250 |
SHA-512: | 89027A7B1B3A080D40411F2E6E3B62BF57AC60879223566E71BD41D900C17051F0A058EFE04F8F1FED5E05DC54617D7A86F83D21BDED0F79347795C8B980B4B2 |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=LEikZe,_b,_tp,byfTOb,lsjVmc/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=n73qwf,SCuOPb,IZT63,vfuNJf,UUJqVe,ws9Tlc,siKnQd,XVq9Qb,STuCOe,njlZCf,m9oV,vjKJJ,y5vRwf,iyZMqd,NTMZac,mzzZzc,rCcCxc,vvMGie,K1ZKnb,ziZ8Mc,b3kMqb,mvkUhe,CMcBD,Fndnac,t2srLd,EN3i8d,z0u0L,xiZRqc,NOeYWe,O6y8ed,L9OGUe,PrPYRd,MpJwZc,qPfo0c,cYShmd,hc6Ubd,Rkm0ef,KUM7Z,oLggrd,inNHtf,L1AAkb,WpP9Yc,lwddkf,gJzDyc,SpsfSb,aC1iue,tUnxGc,aW3pY,ZakeSe,EFQ78c,xQtZb,I6YDgd,zbML3c,zr1jrb,vHEMJe,YHI3We,YTxL4,bSspM,Uas9Hd,zy0vNb,K0PMbc,AvtSve,qmdT9,MY7mZe,xBaz7b,GwYlN,eVCnO,EIOG1e,LDQI" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 22833 |
Entropy (8bit): | 5.425034548615223 |
Encrypted: | false |
SSDEEP: | 384:7lFo6ZEdpgtmyiPixV9OX9gMBpHkHnfst9lZulagGcwYHiRFjJzN7:77o6ZviPixV8xpEHn89l4IgGcwYCRtb7 |
MD5: | 749B18538FE32BFE0815D75F899F5B21 |
SHA1: | AF95A019211AF69F752A43CAA54A83C2AFD41D28 |
SHA-256: | 116B2687C1D5E00DB56A79894AB0C12D4E2E000B9379B7E7AD751B84DF611F3F |
SHA-512: | E4B6F4556AA0FD9979BB52681508F5E26FFB256473803F74F7F5C8D93FA3636D7D0A5835618FBC6123022805CE0D9616A7451A0F302C665E28A6090B5D588505 |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=RqjULd" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4066 |
Entropy (8bit): | 5.363016925556486 |
Encrypted: | false |
SSDEEP: | 96:G2CiFZX5BReR68ujioIRVrqtyzBeTV6SfyAKLif9c7w:bCMZXVeR6jiosVrqtyzBaImyAKw9x |
MD5: | FC5E597D923838E10390DADD12651A81 |
SHA1: | C9959F8D539DB5DF07B8246EC12539B6A9CC101F |
SHA-256: | A7EBD5280C50AE93C061EAE1E9727329E015E97531F8F2D82D0E3EA76ADB37B4 |
SHA-512: | 784CA572808F184A849388723FBB3701E6981D885BBA8A330A933F90BF0B36A2E4A491D4463A27911B1D9F7A7134F23E15F187FC7CB4554EAE9BC252513EED7C |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=sOXFj,q0xTif,ZZ4WUe" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 52280 |
Entropy (8bit): | 7.995413196679271 |
Encrypted: | true |
SSDEEP: | 1536:1rvqtK8DZilXxwJ8mMwAZy7phqsFLdG3B4d:xytBZits8bw4wzbFxG3B4d |
MD5: | F61F0D4D0F968D5BBA39A84C76277E1A |
SHA1: | AA3693EA140ECA418B4B2A30F6A68F6F43B4BEB2 |
SHA-256: | 57147F08949ABABE7DEEF611435AE418475A693E3823769A25C2A39B6EAD9CCC |
SHA-512: | 6C3BD90F709BCF9151C9ED9FFEA55C4F6883E7FDA2A4E26BF018C83FE1CFBE4F4AA0DB080D6D024070D53B2257472C399C8AC44EEFD38B9445640EFA85D5C487 |
Malicious: | false |
URL: | https://fonts.gstatic.com/s/googlesans/v58/4UaRrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iq2vgCI.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 9210 |
Entropy (8bit): | 5.404371326611379 |
Encrypted: | false |
SSDEEP: | 192:EEFZpeip4HzZlY0If0Ma23jcUcrhCx6VD1TYPi8:Es/p4jgjUhtD1TY68 |
MD5: | 21E893B65627B397E22619A9F5BB9662 |
SHA1: | F561B0F66211C1E7B22F94B4935C312AB7087E85 |
SHA-256: | FFA9B8BC8EF2CDFF5EB4BA1A0BA1710A253A5B42535E2A369D5026967DCF4673 |
SHA-512: | 3DE3CD6A4E9B06AB3EB324E90A40B5F2AEEA8D7D6A2651C310E993CF79EEB5AC6E2E33C587F46B2DD20CC862354FD1A61AEBB9B990E6805F6629404BA285F8FA |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PrPYRd,Rkm0ef,SCuOPb,STuCOe,SpsfSb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,ZakeSe,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,byfTOb,cYShmd,eVCnO,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,qPfo0c,qmdT9,rCcCxc,siKnQd,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ltDFwf,SD8Jgb,rmumx,E87wgc,qPYxq,Tbb4sb,pxq3x,f8Gu1e,soHxf,YgOFye,yRXbo,bTi8wc,ywOR5c,PHUIyb" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1460 |
Entropy (8bit): | 5.291808298251231 |
Encrypted: | false |
SSDEEP: | 24:kMYD7DuZvuhqCsNRxoYTY9/qoVk7hz1l2p6vDMW94uEQOeGbCx4VGbgCSFBV87OU:o7DuZWhv6oy12kvwKEeGbC6GbHSh/Hrw |
MD5: | 4CA7ADFE744A690411EA4D3EA8DB9E4B |
SHA1: | 2CF1777A199E25378D330DA68BED1871B5C5BC32 |
SHA-256: | 128129BA736B3094323499B0498A5B3A909C1529717461C34B70080A5B1603BD |
SHA-512: | 8BD3477AF41D1F0FE74AFFCB177BEC0F5F4FDCBBA6BD29D9C2567E6FFDEF5DEB7FF74BF348F33209C39D7BB4958E748DF6731D3DC8F6947352276BC92EAF9E79 |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=P6sQOc" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 743936 |
Entropy (8bit): | 5.791086230020914 |
Encrypted: | false |
SSDEEP: | 6144:YVXWBQkPdzg5pTX1ROv/duPzd8C3s891/N:Nfd8j91/N |
MD5: | 1A3606C746E7B1C949D9078E8E8C1244 |
SHA1: | 56A3EB1E93E61ACD7AAD39DC3526CB60E23651B1 |
SHA-256: | 5F49AE5162183E2EF6F082B29EC99F18DB0212B8ADDB03699B1BFB0AC7869742 |
SHA-512: | F2D15243311C472331C5F3F083BB6C18D38EC0247A3F3CBAFD96DBA40E4EAE489CDA04176672E39FE3760EF7347596B2A5EAB0FB0125E881EF514475C99863B9 |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/excm=_b,_tp,identifierview/ed=1/dg=0/wt=2/ujg=1/rs=AOaEmlE6O04h0gj7Nu50q-nmaRKM6WWcJw/m=_b,_tp" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3467 |
Entropy (8bit): | 5.514745431912774 |
Encrypted: | false |
SSDEEP: | 96:ozbld2fNUmeqJNizhNtt1W8t//loyIpXmdVE2w:onSKE8PWe/Cy4X3j |
MD5: | 8DEF399E8355ABC23E64505281005099 |
SHA1: | 24FF74C3AEFD7696D84FF148465DF4B1B60B1696 |
SHA-256: | F128D7218E1286B05DF11310AD3C8F4CF781402698E45448850D2A3A22F5F185 |
SHA-512: | 33721DD47658D8E12ADF6BD9E9316EB89F5B6297927F7FD60F954E04B829DCBF0E1AE6DDD9A3401F45E0011AE4B1397B960C218238A3D0F633A2173D8E604082 |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,iAskyc,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,wg1P6b,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziXSP,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=Wt6vjf,hhhU8,FCpbqb,WhJNk" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 84 |
Entropy (8bit): | 4.875266466142591 |
Encrypted: | false |
SSDEEP: | 3:DZFJu0+WVTBCq2Bjdw2KsJJuYHSKnZ:lFJuuVTBudw29nu4SKZ |
MD5: | 87B6333E98B7620EA1FF98D1A837A39E |
SHA1: | 105DE6815B0885357DE1414BFC0D77FCC9E924EF |
SHA-256: | DCD3C133C5C40BECD4100BBE6EDAE84C9735E778E4234A5E8395C56FF8A733BA |
SHA-512: | 867D7943D813685FAA76394E53199750C55817E836FD19C933F74D11E9657CE66719A6D6B2E39EE1DE62358BCE364E38A55F4E138DF92337DE6985DDCD5D0994 |
Malicious: | false |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISHgmA6QC9dWevzxIFDRkBE_oSBQ3oIX6GEgUN05ioBw==?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1608 |
Entropy (8bit): | 5.257113147606035 |
Encrypted: | false |
SSDEEP: | 48:o72ZrNZ4yNAbU+15fMxIdf5WENoBCbw7DbG2bEJrw:oyNNAY+1i4HoBNG2Ilw |
MD5: | F06E2DC5CC446B39F878B5F8E4D78418 |
SHA1: | 9F1F34FDD8F8DAB942A9B95D9F720587B6F6AD48 |
SHA-256: | 118E4D2FE7CEF205F9AFC87636554C6D8220882B158333EE3D1990282D158B8F |
SHA-512: | 893C4F883CD1C88C6AAF5A6E7F232D62823A53E1FFDE5C1C52BB066D75781DD041F4D281CDBF18070D921CE862652D8863E2B9D5E0190CFA4128890D62C44168 |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=w9hDv,ZDZcre,A7fCU" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5050 |
Entropy (8bit): | 5.289052544075544 |
Encrypted: | false |
SSDEEP: | 96:o4We0hP7OBFXYvB1sig3Fd8HkaXzLmUrv8Vh1WJlLQXT2v2gqw:655758Fd8HkaPZ0GmAD |
MD5: | 26E26FD11772DFF5C7004BEA334289CC |
SHA1: | 638DAAF541BDE31E95AEE4F8ADA677434D7051DB |
SHA-256: | ADFE3E4960982F5EF4C043052A9990D8683C5FC2B590E817B6B1A5774DDE2CE3 |
SHA-512: | C31929EB6D1C60D6A84A2574FF60490394A6D6F9B354972F3328952F570D80B3F2AEC916B0E1B66DDB1AC056EB75BFAC477E7AF631D0AD1810EDBAF025465D66 |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=A7fCU,AvtSve,CMcBD,E87wgc,EFQ78c,EIOG1e,EN3i8d,Fndnac,GwYlN,I6YDgd,IZT63,K0PMbc,K1ZKnb,KUM7Z,L1AAkb,L9OGUe,LDQI,LEikZe,MY7mZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,P6sQOc,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,SCuOPb,SD8Jgb,STuCOe,SpsfSb,Tbb4sb,UUJqVe,Uas9Hd,WpP9Yc,XVq9Qb,YHI3We,YTxL4,YgOFye,ZDZcre,ZZ4WUe,ZakeSe,ZwDk9d,_b,_tp,aC1iue,aW3pY,b3kMqb,bSspM,bTi8wc,byfTOb,cYShmd,eVCnO,f8Gu1e,gJzDyc,hc6Ubd,iAskyc,inNHtf,iyZMqd,lsjVmc,ltDFwf,lwddkf,m9oV,mvkUhe,mzzZzc,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPYxq,qPfo0c,qmdT9,rCcCxc,rmumx,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,vjKJJ,vvMGie,w9hDv,ws9Tlc,xBaz7b,xQtZb,xiZRqc,y5vRwf,yRXbo,ywOR5c,z0u0L,zbML3c,ziXSP,ziZ8Mc,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=wg1P6b" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32500 |
Entropy (8bit): | 5.378903546681047 |
Encrypted: | false |
SSDEEP: | 768:zYlbuROstb0e39nKGrkysU0smpu4OLOdzIf1p/5GeSsngurz6aKEEEGo/:zYl61Cysbu4OLOdzIfrIen72ZFo/ |
MD5: | BF4BF9728A7C302FBA5B14F3D0F1878B |
SHA1: | 2607CA7A93710D629400077FF3602CB207E6F53D |
SHA-256: | 8981E7B228DF7D6A8797C0CD1E9B0F1F88337D5F0E1C27A04E7A57D2C4309798 |
SHA-512: | AC9E170FC3AFDC0CF6BB8E926B93EF129A5FAD1BBA51B60BABCF3555E9B652E98F86A00FB099879DED35DD3FFE72ECFA597E20E6CA8CF402BEDEC40F78412EDA |
Malicious: | false |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/ck=boq-identity.AccountsSignInUi.gAiX_O5afVA.L.B1.O/am=xIFgKBi2EQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/exm=_b,_tp/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlG_aYNE-Dz95N0OV63231Yfi4Jf5g/ee=ASJRFf:DAnQ7e;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:GwYlN;EmZ2Bf:zr1jrb;JsbNhc:Xd8iUd;K5nYTd:ZDZcre;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;ScI3Yc:e7Hzgb;UpnZUd:nnwwYc;Uvc8o:VDovNc;XdiAjb:NLiXbe;YIZmRd:A1yn5d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;dowIGb:ebZ3mb;eBAeSb:zbML3c;iFQyKf:vfuNJf;lOO0Vd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:L9OGUe;qafBPd:yDVVkb;qddgKe:xQtZb;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=byfTOb,lsjVmc,LEikZe" |
Preview: |
File type: | |
Entropy (8bit): | 6.581111526455095 |
TrID: |
|
File name: | file.exe |
File size: | 918'016 bytes |
MD5: | 0083d14c374eacc7490d77cf1c0ec24d |
SHA1: | 3712e1ccd617a7a16bb987e48bdbd832378d9a69 |
SHA256: | ed2cd00fc7953f7fe548e562e2efba931572e187b681ffa6c4e550a337974efa |
SHA512: | 501331e4023cec09692e322417e28c9300816c713ef34185fc1a88cdcead847b62b1aa8f21a48980741af06e2dcd5806a8346569d2bf9093f9d760a5cb00d963 |
SSDEEP: | 12288:BqDEvFo+yo4DdbbMWu/jrQu4M9lBAlKhQcDGB3cuBNGE6iOrpfe4JdaDgaTTQ:BqDEvCTbMWu7rQYlBQcBiT6rprG8anQ |
TLSH: | 66159E0273D1C062FFAB92334B5AF6515BBC69260123E61F13981DB9BE701B1563E7A3 |
File Content Preview: | MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................j:......j:..C...j:......@.*...............................n.......~.............{.......{.......{.........z.... |
Icon Hash: | aaf3e3e3938382a0 |
Entrypoint: | 0x420577 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66FC9852 [Wed Oct 2 00:48:18 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | 948cc502fe9226992dce9417f952fce3 |
Instruction |
---|
call 00007F3E847D6133h |
jmp 00007F3E847D5A3Fh |
push ebp |
mov ebp, esp |
push esi |
push dword ptr [ebp+08h] |
mov esi, ecx |
call 00007F3E847D5C1Dh |
mov dword ptr [esi], 0049FDF0h |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
and dword ptr [ecx+04h], 00000000h |
mov eax, ecx |
and dword ptr [ecx+08h], 00000000h |
mov dword ptr [ecx+04h], 0049FDF8h |
mov dword ptr [ecx], 0049FDF0h |
ret |
push ebp |
mov ebp, esp |
push esi |
push dword ptr [ebp+08h] |
mov esi, ecx |
call 00007F3E847D5BEAh |
mov dword ptr [esi], 0049FE0Ch |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
and dword ptr [ecx+04h], 00000000h |
mov eax, ecx |
and dword ptr [ecx+08h], 00000000h |
mov dword ptr [ecx+04h], 0049FE14h |
mov dword ptr [ecx], 0049FE0Ch |
ret |
push ebp |
mov ebp, esp |
push esi |
mov esi, ecx |
lea eax, dword ptr [esi+04h] |
mov dword ptr [esi], 0049FDD0h |
and dword ptr [eax], 00000000h |
and dword ptr [eax+04h], 00000000h |
push eax |
mov eax, dword ptr [ebp+08h] |
add eax, 04h |
push eax |
call 00007F3E847D87DDh |
pop ecx |
pop ecx |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
lea eax, dword ptr [ecx+04h] |
mov dword ptr [ecx], 0049FDD0h |
push eax |
call 00007F3E847D8828h |
pop ecx |
ret |
push ebp |
mov ebp, esp |
push esi |
mov esi, ecx |
lea eax, dword ptr [esi+04h] |
mov dword ptr [esi], 0049FDD0h |
push eax |
call 00007F3E847D8811h |
test byte ptr [ebp+08h], 00000001h |
pop ecx |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xc8e64 | 0x17c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xd4000 | 0x9750 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xde000 | 0x7594 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0xb0ff0 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0xc3400 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0xb1010 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x9c000 | 0x894 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x9ab1d | 0x9ac00 | 0a1473f3064dcbc32ef93c5c8a90f3a6 | False | 0.565500681542811 | data | 6.668273581389308 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x9c000 | 0x2fb82 | 0x2fc00 | c9cf2468b60bf4f80f136ed54b3989fb | False | 0.35289185209424084 | data | 5.691811547483722 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xcc000 | 0x706c | 0x4800 | 53b9025d545d65e23295e30afdbd16d9 | False | 0.04356553819444445 | DOS executable (block device driver @\273\) | 0.5846666986982398 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0xd4000 | 0x9750 | 0x9800 | 1f4c8f5b1284def9e60d0d6135a1801f | False | 0.29438219572368424 | data | 5.225999060905397 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xde000 | 0x7594 | 0x7600 | c68ee8931a32d45eb82dc450ee40efc3 | False | 0.7628111758474576 | data | 6.7972128181359786 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xd45a8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.7466216216216216 |
RT_ICON | 0xd46d0 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors | English | Great Britain | 0.3277027027027027 |
RT_ICON | 0xd47f8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.3885135135135135 |
RT_ICON | 0xd4920 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | Great Britain | 0.3333333333333333 |
RT_ICON | 0xd4c08 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | Great Britain | 0.5 |
RT_ICON | 0xd4d30 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | English | Great Britain | 0.2835820895522388 |
RT_ICON | 0xd5bd8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | English | Great Britain | 0.37906137184115524 |
RT_ICON | 0xd6480 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | English | Great Britain | 0.23699421965317918 |
RT_ICON | 0xd69e8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | English | Great Britain | 0.13858921161825727 |
RT_ICON | 0xd8f90 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | Great Britain | 0.25070356472795496 |
RT_ICON | 0xda038 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | Great Britain | 0.3173758865248227 |
RT_MENU | 0xda4a0 | 0x50 | data | English | Great Britain | 0.9 |
RT_STRING | 0xda4f0 | 0x594 | data | English | Great Britain | 0.3333333333333333 |
RT_STRING | 0xdaa84 | 0x68a | data | English | Great Britain | 0.2735961768219833 |
RT_STRING | 0xdb110 | 0x490 | data | English | Great Britain | 0.3715753424657534 |
RT_STRING | 0xdb5a0 | 0x5fc | data | English | Great Britain | 0.3087467362924282 |
RT_STRING | 0xdbb9c | 0x65c | data | English | Great Britain | 0.34336609336609336 |
RT_STRING | 0xdc1f8 | 0x466 | data | English | Great Britain | 0.3605683836589698 |
RT_STRING | 0xdc660 | 0x158 | Matlab v4 mat-file (little endian) n, numeric, rows 0, columns 0 | English | Great Britain | 0.502906976744186 |
RT_RCDATA | 0xdc7b8 | 0xa18 | data | 1.0042569659442724 | ||
RT_GROUP_ICON | 0xdd1d0 | 0x76 | data | English | Great Britain | 0.6610169491525424 |
RT_GROUP_ICON | 0xdd248 | 0x14 | data | English | Great Britain | 1.25 |
RT_GROUP_ICON | 0xdd25c | 0x14 | data | English | Great Britain | 1.15 |
RT_GROUP_ICON | 0xdd270 | 0x14 | data | English | Great Britain | 1.25 |
RT_VERSION | 0xdd284 | 0xdc | data | English | Great Britain | 0.6181818181818182 |
RT_MANIFEST | 0xdd360 | 0x3ef | ASCII text, with CRLF line terminators | English | Great Britain | 0.5074478649453823 |
DLL | Import |
---|---|
WSOCK32.dll | gethostbyname, recv, send, socket, inet_ntoa, setsockopt, ntohs, WSACleanup, WSAStartup, sendto, htons, __WSAFDIsSet, select, accept, listen, bind, inet_addr, ioctlsocket, recvfrom, WSAGetLastError, closesocket, gethostname, connect |
VERSION.dll | GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW |
WINMM.dll | timeGetTime, waveOutSetVolume, mciSendStringW |
COMCTL32.dll | ImageList_ReplaceIcon, ImageList_Destroy, ImageList_Remove, ImageList_SetDragCursorImage, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_EndDrag, ImageList_DragMove, InitCommonControlsEx, ImageList_Create |
MPR.dll | WNetGetConnectionW, WNetCancelConnection2W, WNetUseConnectionW, WNetAddConnection2W |
WININET.dll | HttpOpenRequestW, InternetCloseHandle, InternetOpenW, InternetSetOptionW, InternetCrackUrlW, HttpQueryInfoW, InternetQueryOptionW, InternetConnectW, HttpSendRequestW, FtpOpenFileW, FtpGetFileSize, InternetOpenUrlW, InternetReadFile, InternetQueryDataAvailable |
PSAPI.DLL | GetProcessMemoryInfo |
IPHLPAPI.DLL | IcmpSendEcho, IcmpCloseHandle, IcmpCreateFile |
USERENV.dll | DestroyEnvironmentBlock, LoadUserProfileW, CreateEnvironmentBlock, UnloadUserProfile |
UxTheme.dll | IsThemeActive |
KERNEL32.dll | DuplicateHandle, CreateThread, WaitForSingleObject, HeapAlloc, GetProcessHeap, HeapFree, Sleep, GetCurrentThreadId, MultiByteToWideChar, MulDiv, GetVersionExW, IsWow64Process, GetSystemInfo, FreeLibrary, LoadLibraryA, GetProcAddress, SetErrorMode, GetModuleFileNameW, WideCharToMultiByte, lstrcpyW, lstrlenW, GetModuleHandleW, QueryPerformanceCounter, VirtualFreeEx, OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateFileW, SetFilePointerEx, SetEndOfFile, ReadFile, WriteFile, FlushFileBuffers, TerminateProcess, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetFileTime, GetFileAttributesW, FindFirstFileW, FindClose, GetLongPathNameW, GetShortPathNameW, DeleteFileW, IsDebuggerPresent, CopyFileExW, MoveFileW, CreateDirectoryW, RemoveDirectoryW, SetSystemPowerState, QueryPerformanceFrequency, LoadResource, LockResource, SizeofResource, OutputDebugStringW, GetTempPathW, GetTempFileNameW, DeviceIoControl, LoadLibraryW, GetLocalTime, CompareStringW, GetCurrentThread, EnterCriticalSection, LeaveCriticalSection, GetStdHandle, CreatePipe, InterlockedExchange, TerminateThread, LoadLibraryExW, FindResourceExW, CopyFileW, VirtualFree, FormatMessageW, GetExitCodeProcess, GetPrivateProfileStringW, WritePrivateProfileStringW, GetPrivateProfileSectionW, WritePrivateProfileSectionW, GetPrivateProfileSectionNamesW, FileTimeToLocalFileTime, FileTimeToSystemTime, SystemTimeToFileTime, LocalFileTimeToFileTime, GetDriveTypeW, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetVolumeInformationW, SetVolumeLabelW, CreateHardLinkW, SetFileAttributesW, CreateEventW, SetEvent, GetEnvironmentVariableW, SetEnvironmentVariableW, GlobalLock, GlobalUnlock, GlobalAlloc, GetFileSize, GlobalFree, GlobalMemoryStatusEx, Beep, GetSystemDirectoryW, HeapReAlloc, HeapSize, GetComputerNameW, GetWindowsDirectoryW, GetCurrentProcessId, GetProcessIoCounters, CreateProcessW, GetProcessId, SetPriorityClass, VirtualAlloc, GetCurrentDirectoryW, lstrcmpiW, DecodePointer, GetLastError, RaiseException, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, InterlockedDecrement, InterlockedIncrement, ResetEvent, WaitForSingleObjectEx, IsProcessorFeaturePresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, CloseHandle, GetFullPathNameW, GetStartupInfoW, GetSystemTimeAsFileTime, InitializeSListHead, RtlUnwind, SetLastError, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, ExitProcess, GetModuleHandleExW, ExitThread, ResumeThread, FreeLibraryAndExitThread, GetACP, GetDateFormatW, GetTimeFormatW, LCMapStringW, GetStringTypeW, GetFileType, SetStdHandle, GetConsoleCP, GetConsoleMode, ReadConsoleW, GetTimeZoneInformation, FindFirstFileExW, IsValidCodePage, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableA, SetCurrentDirectoryW, FindNextFileW, WriteConsoleW |
USER32.dll | GetKeyboardLayoutNameW, IsCharAlphaW, IsCharAlphaNumericW, IsCharLowerW, IsCharUpperW, GetMenuStringW, GetSubMenu, GetCaretPos, IsZoomed, GetMonitorInfoW, SetWindowLongW, SetLayeredWindowAttributes, FlashWindow, GetClassLongW, TranslateAcceleratorW, IsDialogMessageW, GetSysColor, InflateRect, DrawFocusRect, DrawTextW, FrameRect, DrawFrameControl, FillRect, PtInRect, DestroyAcceleratorTable, CreateAcceleratorTableW, SetCursor, GetWindowDC, GetSystemMetrics, GetActiveWindow, CharNextW, wsprintfW, RedrawWindow, DrawMenuBar, DestroyMenu, SetMenu, GetWindowTextLengthW, CreateMenu, IsDlgButtonChecked, DefDlgProcW, CallWindowProcW, ReleaseCapture, SetCapture, PeekMessageW, GetInputState, UnregisterHotKey, CharLowerBuffW, MonitorFromPoint, MonitorFromRect, LoadImageW, mouse_event, ExitWindowsEx, SetActiveWindow, FindWindowExW, EnumThreadWindows, SetMenuDefaultItem, InsertMenuItemW, IsMenu, ClientToScreen, GetCursorPos, DeleteMenu, CheckMenuRadioItem, GetMenuItemID, GetMenuItemCount, SetMenuItemInfoW, GetMenuItemInfoW, SetForegroundWindow, IsIconic, FindWindowW, SystemParametersInfoW, LockWindowUpdate, SendInput, GetAsyncKeyState, SetKeyboardState, GetKeyboardState, GetKeyState, VkKeyScanW, LoadStringW, DialogBoxParamW, MessageBeep, EndDialog, SendDlgItemMessageW, GetDlgItem, SetWindowTextW, CopyRect, ReleaseDC, GetDC, EndPaint, BeginPaint, GetClientRect, GetMenu, DestroyWindow, EnumWindows, GetDesktopWindow, IsWindow, IsWindowEnabled, IsWindowVisible, EnableWindow, InvalidateRect, GetWindowLongW, GetWindowThreadProcessId, AttachThreadInput, GetFocus, GetWindowTextW, SendMessageTimeoutW, EnumChildWindows, CharUpperBuffW, GetClassNameW, GetParent, GetDlgCtrlID, SendMessageW, MapVirtualKeyW, PostMessageW, GetWindowRect, SetUserObjectSecurity, CloseDesktop, CloseWindowStation, OpenDesktopW, RegisterHotKey, GetCursorInfo, SetWindowPos, CopyImage, AdjustWindowRectEx, SetRect, SetClipboardData, EmptyClipboard, CountClipboardFormats, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, BlockInput, TrackPopupMenuEx, GetMessageW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, GetUserObjectSecurity, MessageBoxW, DefWindowProcW, MoveWindow, SetFocus, PostQuitMessage, KillTimer, CreatePopupMenu, RegisterWindowMessageW, SetTimer, ShowWindow, CreateWindowExW, RegisterClassExW, LoadIconW, LoadCursorW, GetSysColorBrush, GetForegroundWindow, MessageBoxA, DestroyIcon, DispatchMessageW, keybd_event, TranslateMessage, ScreenToClient |
GDI32.dll | EndPath, DeleteObject, GetTextExtentPoint32W, ExtCreatePen, StrokeAndFillPath, GetDeviceCaps, SetPixel, CloseFigure, LineTo, AngleArc, MoveToEx, Ellipse, CreateCompatibleBitmap, CreateCompatibleDC, PolyDraw, BeginPath, Rectangle, SetViewportOrgEx, GetObjectW, SetBkMode, RoundRect, SetBkColor, CreatePen, SelectObject, StretchBlt, CreateSolidBrush, SetTextColor, CreateFontW, GetTextFaceW, GetStockObject, CreateDCW, GetPixel, DeleteDC, GetDIBits, StrokePath |
COMDLG32.dll | GetSaveFileNameW, GetOpenFileNameW |
ADVAPI32.dll | GetAce, RegEnumValueW, RegDeleteValueW, RegDeleteKeyW, RegEnumKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, RegConnectRegistryW, InitializeSecurityDescriptor, InitializeAcl, AdjustTokenPrivileges, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, CreateProcessAsUserW, CreateProcessWithLogonW, GetLengthSid, CopySid, LogonUserW, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, GetTokenInformation, RegCreateKeyExW, GetSecurityDescriptorDacl, GetAclInformation, GetUserNameW, AddAce, SetSecurityDescriptorDacl, InitiateSystemShutdownExW |
SHELL32.dll | DragFinish, DragQueryPoint, ShellExecuteExW, DragQueryFileW, SHEmptyRecycleBinW, SHGetPathFromIDListW, SHBrowseForFolderW, SHCreateShellItem, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetFolderPathW, SHFileOperationW, ExtractIconExW, Shell_NotifyIconW, ShellExecuteW |
ole32.dll | CoTaskMemAlloc, CoTaskMemFree, CLSIDFromString, ProgIDFromCLSID, CLSIDFromProgID, OleSetMenuDescriptor, MkParseDisplayName, OleSetContainedObject, CoCreateInstance, IIDFromString, StringFromGUID2, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoInitialize, CoUninitialize, GetRunningObjectTable, CoGetInstanceFromFile, CoGetObject, CoInitializeSecurity, CoCreateInstanceEx, CoSetProxyBlanket |
OLEAUT32.dll | CreateStdDispatch, CreateDispTypeInfo, UnRegisterTypeLib, UnRegisterTypeLibForUser, RegisterTypeLibForUser, RegisterTypeLib, LoadTypeLibEx, VariantCopyInd, SysReAllocString, SysFreeString, VariantChangeType, SafeArrayDestroyData, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayAllocData, SafeArrayAllocDescriptorEx, SafeArrayCreateVector, SysStringLen, QueryPathOfRegTypeLib, SysAllocString, VariantInit, VariantClear, DispCallFunc, VariantTimeToSystemTime, VarR8FromDec, SafeArrayGetVartype, SafeArrayDestroyDescriptor, VariantCopy, OleLoadPicture |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | Great Britain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 2, 2024 03:01:00.694494963 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:00.694593906 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:00.694663048 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:00.695451021 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:00.695487976 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.348037958 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.376781940 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.376804113 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.377224922 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.377279997 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.378552914 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.378597021 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.382900953 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.382967949 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.383429050 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.383439064 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.433551073 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.629956961 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.630069971 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.630125999 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.631402969 CEST | 49732 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:01.631441116 CEST | 443 | 49732 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.642836094 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:01.642874002 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:01.642936945 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:01.643569946 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:01.643589020 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.282176971 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.282449961 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.282479048 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.283020020 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.283088923 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.284045935 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.284099102 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.285056114 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.285140991 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.285270929 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.285280943 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.332438946 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.579858065 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.579909086 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.580085993 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.580095053 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:02.580152988 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.582070112 CEST | 49736 | 443 | 192.168.2.4 | 142.250.186.78 |
Oct 2, 2024 03:01:02.582093000 CEST | 443 | 49736 | 142.250.186.78 | 192.168.2.4 |
Oct 2, 2024 03:01:03.941863060 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Oct 2, 2024 03:01:05.004761934 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.004801989 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:05.004885912 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.005053997 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.005072117 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:05.175656080 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:05.175685883 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:05.175759077 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:05.177318096 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:05.177329063 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:05.648680925 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:05.648890018 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.648905993 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:05.650305986 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:05.650362015 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.651281118 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.651360989 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:05.698733091 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.698748112 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:05.745599031 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:05.816350937 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:05.816423893 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:05.820323944 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:05.820331097 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:05.820573092 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:05.870709896 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.293081045 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.339410067 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:06.478005886 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:06.478075981 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:06.478123903 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.478233099 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.478249073 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:06.478260040 CEST | 49742 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.478266001 CEST | 443 | 49742 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:06.720010996 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.720046997 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:06.720104933 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.721445084 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:06.721458912 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.446871996 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.447045088 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:07.451109886 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:07.451117992 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.451329947 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.455260992 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:07.499433994 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.729756117 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.729830027 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.731513023 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:07.732444048 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:07.732444048 CEST | 49745 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 03:01:07.732460022 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:07.732466936 CEST | 443 | 49745 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 03:01:09.724523067 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:09.724550962 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:09.724610090 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:09.724800110 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:09.724811077 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.371251106 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.371412992 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.371426105 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.371808052 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.371867895 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.372415066 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.372466087 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.373351097 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.373408079 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.373614073 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.373621941 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.417812109 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.694205999 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.694252968 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.694284916 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.694303036 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.694320917 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.694339037 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.700153112 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.700210094 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.700218916 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.706537008 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.706568003 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.706605911 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.706615925 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.706660032 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.712691069 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.712759018 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.718885899 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.718966007 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.718998909 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.719044924 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.760442972 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:10.760485888 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:10.760545015 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:10.760744095 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:10.760757923 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:10.784420967 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.784460068 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.784496069 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.784516096 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.784528017 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.784557104 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.784564972 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.784606934 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.790138006 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.790178061 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.790206909 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.790218115 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.790261984 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.796197891 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.796267986 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.802360058 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.802416086 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.802424908 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.808700085 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.808763981 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.808773041 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.815180063 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.815244913 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.815253019 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.815496922 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.815542936 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.827594995 CEST | 49756 | 443 | 192.168.2.4 | 142.250.186.142 |
Oct 2, 2024 03:01:10.827614069 CEST | 443 | 49756 | 142.250.186.142 | 192.168.2.4 |
Oct 2, 2024 03:01:10.877407074 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:10.877429008 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:10.877506971 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:10.877794027 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:10.877813101 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.409322977 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.409549952 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.409569025 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.409926891 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.409986973 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.410655022 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.410702944 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.411715031 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.411824942 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.411962986 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.411969900 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.464099884 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.593663931 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.593888998 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.593903065 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.594230890 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.594288111 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.594829082 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.594882011 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.595002890 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.595052958 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.595154047 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.595161915 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.636384010 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.712574005 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.712637901 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.712681055 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.713105917 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.713118076 CEST | 443 | 49760 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.713125944 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.713160038 CEST | 49760 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.713875055 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.713906050 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.713959932 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.714176893 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.714190006 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.893675089 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.894233942 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.894247055 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.894268036 CEST | 443 | 49762 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.894299984 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.894336939 CEST | 49762 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.895051003 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.895083904 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:11.895155907 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.895428896 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:11.895442009 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.347667933 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.347863913 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.347901106 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.348216057 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.348289013 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.348820925 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.348872900 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.348967075 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.349035978 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.349081039 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.349097967 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.349106073 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.403511047 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.528419018 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.528610945 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.528621912 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.528944969 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.528999090 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.529572010 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.529627085 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.529973984 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.530029058 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.530093908 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.530102015 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.530117989 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.565659046 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.565776110 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.565830946 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.566365004 CEST | 49765 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.566380024 CEST | 443 | 49765 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.568964958 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:12.575402975 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.575948954 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.615401983 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:12.746422052 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.747231960 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.747292995 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.748162031 CEST | 49767 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:12.748169899 CEST | 443 | 49767 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:12.834820986 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:12.834965944 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:12.835021019 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:12.835036039 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:12.835131884 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:12.835180044 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:12.835186005 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:12.835468054 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:12.835515022 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:12.835702896 CEST | 49741 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:01:12.835706949 CEST | 443 | 49741 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:01:16.692779064 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:16.692815065 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:16.692928076 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:16.694108963 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:16.694118023 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:17.486896992 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:17.486970901 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:17.490113974 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:17.490122080 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:17.490346909 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:17.542351007 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:18.208303928 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:18.251426935 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467694044 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467713118 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467719078 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467731953 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467739105 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467741013 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467765093 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:18.467772961 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.467799902 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:18.467819929 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:18.468583107 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.468635082 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:18.468640089 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.468657970 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:18.469042063 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:18.765635014 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:18.765659094 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:18.765810966 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:18.766100883 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:18.766112089 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.250158072 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:19.250179052 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:19.250199080 CEST | 49773 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:19.250205040 CEST | 443 | 49773 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:19.406492949 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.406795025 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:19.406810045 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.407124043 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.407409906 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:19.407465935 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.407546043 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:19.407557964 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:19.407566071 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.726253033 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.727643013 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:19.731453896 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:19.732206106 CEST | 49778 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:19.732218981 CEST | 443 | 49778 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:41.670578957 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:41.670634031 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:41.670727968 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:41.671034098 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:41.671051979 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.296426058 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.312237024 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.312269926 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.312622070 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.312952042 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.313013077 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.313128948 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.313146114 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.313157082 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.454272032 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.454303026 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.454451084 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.454679012 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.454689980 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.553391933 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.553500891 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.553710938 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.553878069 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.553916931 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.596589088 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.597495079 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:42.597572088 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.597692966 CEST | 49781 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:42.597702980 CEST | 443 | 49781 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.091984034 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.092241049 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.092258930 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.092609882 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.092892885 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.092952013 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.093044043 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.093081951 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.093086004 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.200934887 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.201148987 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.201178074 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.201536894 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.201817989 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.201889038 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.201917887 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.201968908 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.201982021 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.246298075 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.391711950 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.392556906 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.392616987 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.393105030 CEST | 49782 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.393117905 CEST | 443 | 49782 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.503635883 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.504663944 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:43.504750967 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.504815102 CEST | 49783 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:01:43.504846096 CEST | 443 | 49783 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:01:55.503118992 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:55.503158092 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:55.503221035 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:55.503566980 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:55.503580093 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.281124115 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.281200886 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.287349939 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.287362099 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.287604094 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.316056967 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.363400936 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.614425898 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.614449024 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.614463091 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.614511013 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.614537001 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.614552021 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.614590883 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.615483999 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.615523100 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.615536928 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.615542889 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.615569115 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.615569115 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.615606070 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.644160986 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.644179106 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:01:56.644190073 CEST | 49784 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 2, 2024 03:01:56.644195080 CEST | 443 | 49784 | 4.175.87.197 | 192.168.2.4 |
Oct 2, 2024 03:02:05.059547901 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:05.059582949 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:05.059662104 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:05.059907913 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:05.059926033 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:05.722795963 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:05.723052025 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:05.723078012 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:05.723366022 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:05.723632097 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:05.723689079 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:05.776918888 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:10.232196093 CEST | 49724 | 80 | 192.168.2.4 | 199.232.214.172 |
Oct 2, 2024 03:02:10.237442017 CEST | 80 | 49724 | 199.232.214.172 | 192.168.2.4 |
Oct 2, 2024 03:02:10.237519979 CEST | 49724 | 80 | 192.168.2.4 | 199.232.214.172 |
Oct 2, 2024 03:02:13.420778036 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:13.420830011 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:13.420883894 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:13.421392918 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:13.421420097 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:13.421477079 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:13.421658039 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:13.421672106 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:13.421821117 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:13.421838045 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.101203918 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.101572990 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.101588964 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.101917028 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.102224112 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.102277040 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.102277994 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.102380991 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.102400064 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.102407932 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.102485895 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.102499008 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.102818012 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.103068113 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.103125095 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.103207111 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.103221893 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.103235006 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.400619984 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.401086092 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.401212931 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.401278019 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.401752949 CEST | 49789 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.401767015 CEST | 443 | 49789 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.401930094 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:14.401973963 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.402270079 CEST | 49788 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:14.402286053 CEST | 443 | 49788 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:15.633614063 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:15.633683920 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:15.633734941 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:28.322160959 CEST | 49786 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:02:28.322185993 CEST | 443 | 49786 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:02:32.387687922 CEST | 55426 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:02:32.392575026 CEST | 53 | 55426 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:32.392689943 CEST | 55426 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:02:32.392738104 CEST | 55426 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:02:32.397871017 CEST | 53 | 55426 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:32.844121933 CEST | 53 | 55426 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:32.844973087 CEST | 55426 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:02:32.850002050 CEST | 53 | 55426 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:32.850106955 CEST | 55426 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:02:43.536245108 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:43.536298990 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:43.536376953 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:43.536737919 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:43.536753893 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:43.767721891 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:43.767761946 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:43.767821074 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:43.768076897 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:43.768091917 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.170566082 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.170893908 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.170916080 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.171233892 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.171484947 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.171541929 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.171612978 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.171632051 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.171642065 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.397099972 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.397360086 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.397382975 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.397701025 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.397993088 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.398051023 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.398128986 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.398149967 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.398160934 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.469968081 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.470624924 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.470680952 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.470782042 CEST | 55428 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.470801115 CEST | 443 | 55428 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.694279909 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.695090055 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:02:44.695147991 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.695405006 CEST | 55429 | 443 | 192.168.2.4 | 216.58.206.78 |
Oct 2, 2024 03:02:44.695417881 CEST | 443 | 55429 | 216.58.206.78 | 192.168.2.4 |
Oct 2, 2024 03:03:05.122500896 CEST | 55430 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:03:05.122530937 CEST | 443 | 55430 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:03:05.122602940 CEST | 55430 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:03:05.122883081 CEST | 55430 | 443 | 192.168.2.4 | 142.250.181.228 |
Oct 2, 2024 03:03:05.122898102 CEST | 443 | 55430 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:03:05.773521900 CEST | 443 | 55430 | 142.250.181.228 | 192.168.2.4 |
Oct 2, 2024 03:03:05.824466944 CEST | 55430 | 443 | 192.168.2.4 | 142.250.181.228 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 2, 2024 03:01:00.644874096 CEST | 53 | 54687 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:00.670622110 CEST | 51086 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:00.670778990 CEST | 57006 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:00.680566072 CEST | 53 | 57006 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:00.680743933 CEST | 53 | 51086 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:00.691694975 CEST | 53 | 63760 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:01.634242058 CEST | 60564 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:01.634407043 CEST | 56500 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:01.640862942 CEST | 53 | 60564 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:01.641448975 CEST | 53 | 56500 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:01.710680008 CEST | 53 | 54539 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:04.996521950 CEST | 62489 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:04.996588945 CEST | 59593 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:05.003854036 CEST | 53 | 62489 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:05.003901958 CEST | 53 | 59593 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:06.914540052 CEST | 53 | 62341 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:09.707880974 CEST | 54613 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:09.708040953 CEST | 62154 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:09.714474916 CEST | 53 | 54613 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:09.715394974 CEST | 53 | 62154 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:10.741667986 CEST | 64472 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:10.741818905 CEST | 52786 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:01:10.749495983 CEST | 53 | 64472 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:10.750228882 CEST | 53 | 52786 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:12.801067114 CEST | 53 | 61671 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:18.667090893 CEST | 53 | 63165 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:01:21.799177885 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Oct 2, 2024 03:01:37.653053045 CEST | 53 | 59492 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:00.335366964 CEST | 53 | 62501 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:00.435928106 CEST | 53 | 52168 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:11.789369106 CEST | 53 | 51190 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:13.353992939 CEST | 54727 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:02:13.354113102 CEST | 53396 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 03:02:13.419821978 CEST | 53 | 54727 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:13.420214891 CEST | 53 | 53396 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:28.329862118 CEST | 53 | 54843 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 03:02:32.386821032 CEST | 53 | 52680 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 2, 2024 03:01:00.670622110 CEST | 192.168.2.4 | 1.1.1.1 | 0x70c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 03:01:00.670778990 CEST | 192.168.2.4 | 1.1.1.1 | 0xd831 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 03:01:01.634242058 CEST | 192.168.2.4 | 1.1.1.1 | 0x93df | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 03:01:01.634407043 CEST | 192.168.2.4 | 1.1.1.1 | 0xf8c4 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 03:01:04.996521950 CEST | 192.168.2.4 | 1.1.1.1 | 0xf89e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 03:01:04.996588945 CEST | 192.168.2.4 | 1.1.1.1 | 0x9bd | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 03:01:09.707880974 CEST | 192.168.2.4 | 1.1.1.1 | 0x4120 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 03:01:09.708040953 CEST | 192.168.2.4 | 1.1.1.1 | 0x9b6e | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 03:01:10.741667986 CEST | 192.168.2.4 | 1.1.1.1 | 0x9584 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 03:01:10.741818905 CEST | 192.168.2.4 | 1.1.1.1 | 0x77b7 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 03:02:13.353992939 CEST | 192.168.2.4 | 1.1.1.1 | 0xf433 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 03:02:13.354113102 CEST | 192.168.2.4 | 1.1.1.1 | 0xaee3 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 2, 2024 03:01:00.680566072 CEST | 1.1.1.1 | 192.168.2.4 | 0xd831 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 2, 2024 03:01:00.680743933 CEST | 1.1.1.1 | 192.168.2.4 | 0x70c0 | No error (0) | 216.58.206.78 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | youtube-ui.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.186.78 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.186.46 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 216.58.206.78 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 216.58.206.46 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 216.58.212.174 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.185.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.181.238 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.185.174 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.184.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.184.238 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 172.217.16.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.74.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.186.110 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.185.238 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 142.250.186.174 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.640862942 CEST | 1.1.1.1 | 192.168.2.4 | 0x93df | No error (0) | 172.217.18.14 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.641448975 CEST | 1.1.1.1 | 192.168.2.4 | 0xf8c4 | No error (0) | youtube-ui.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:01.641448975 CEST | 1.1.1.1 | 192.168.2.4 | 0xf8c4 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 2, 2024 03:01:05.003854036 CEST | 1.1.1.1 | 192.168.2.4 | 0xf89e | No error (0) | 142.250.181.228 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:05.003901958 CEST | 1.1.1.1 | 192.168.2.4 | 0x9bd | No error (0) | 65 | IN (0x0001) | false | |||
Oct 2, 2024 03:01:09.714474916 CEST | 1.1.1.1 | 192.168.2.4 | 0x4120 | No error (0) | www3.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:09.714474916 CEST | 1.1.1.1 | 192.168.2.4 | 0x4120 | No error (0) | 142.250.186.142 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:09.715394974 CEST | 1.1.1.1 | 192.168.2.4 | 0x9b6e | No error (0) | www3.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 2, 2024 03:01:10.749495983 CEST | 1.1.1.1 | 192.168.2.4 | 0x9584 | No error (0) | 216.58.206.78 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 03:02:13.419821978 CEST | 1.1.1.1 | 192.168.2.4 | 0xf433 | No error (0) | 216.58.206.78 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49732 | 216.58.206.78 | 443 | 3244 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-02 01:01:01 UTC | 851 | OUT | |
2024-10-02 01:01:01 UTC | 1704 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49736 | 142.250.186.78 | 443 | 3244 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-02 01:01:02 UTC | 869 | OUT | |
2024-10-02 01:01:02 UTC | 2634 | IN |