Windows
Analysis Report
1El22bCuSq.html
Overview
General Information
Sample name: | 1El22bCuSq.htmlrenamed because original name is a hash value |
Original sample name: | 7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318.html |
Analysis ID: | 1542810 |
MD5: | d208d81ab739dc43291c2076a8c01e62 |
SHA1: | 36074c3c2f409c773e42f962e7ce446783a29d5f |
SHA256: | 7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318 |
Tags: | blogview-shophtmluser-JAMESWT_MHT |
Infos: | |
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 7004 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "C:\Us ers\user\D esktop\1El 22bCuSq.ht ml" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2088 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2028 --fi eld-trial- handle=187 2,i,869746 8142556874 598,116422 6471912955 7555,26214 4 /prefetc h:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
13% | ReversingLabs | Script-WScript.Trojan.Asthma |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.186.164 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.186.164 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.8 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1542810 |
Start date and time: | 2024-10-26 13:49:37 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 17s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowshtmlcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1El22bCuSq.htmlrenamed because original name is a hash value |
Original Sample Name: | 7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318.html |
Detection: | MAL |
Classification: | mal48.winHTML@22/6@2/3 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.78, 108.177.15.84, 142.250.181.227, 34.104.35.123, 199.232.214.172, 172.217.16.138, 142.250.185.74, 142.250.186.42, 142.250.185.106, 142.250.181.234, 142.250.185.202, 142.250.184.202, 142.250.186.74, 142.250.185.234, 142.250.185.138, 216.58.206.42, 172.217.18.10, 142.250.185.170, 142.250.186.106, 142.250.186.138, 216.58.212.138, 192.229.221.95, 142.250.186.131, 93.184.221.240, 172.217.23.110
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, clients.l.google.com, optimizationguide-pa.googleapis.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
- VT rate limit hit for: 1El22bCuSq.html
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
239.255.255.250 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | WinSearchAbuse | Browse | |||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | LonePage | Browse | |||
Get hash | malicious | LonePage | Browse | |||
Get hash | malicious | LonePage | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Phorpiex, Xmrig | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
28a2c9bd18a11de089ef85a160da29e4 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | WinSearchAbuse | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LonePage | Browse |
| ||
Get hash | malicious | LonePage | Browse |
| ||
Get hash | malicious | LonePage | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.981444858911369 |
Encrypted: | false |
SSDEEP: | 48:8e0daTmqzHLidAKZdA1oehwiZUklqeh6y+3:8epXA5y |
MD5: | 10BED557B37A243C923FB416887E6C4A |
SHA1: | D6CC09B00DC93074777CFAA6CDE52C0AE2D0613E |
SHA-256: | 60A33CCF152C50345037BB6F2CF9DFE4FC440B163FF6275ADE21D60008263D7D |
SHA-512: | 90543F19C1EA533BDD4E8A2676FC497EA62CFC54FFB3D7C358513108606FA0FC7E290E2DE31FA84B09D767B1DB051BC24CAA555F00365BDC94FD176FC2D69B7A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.995758167987962 |
Encrypted: | false |
SSDEEP: | 48:8Z0daTmqzHLidAKZdA1leh/iZUkAQkqehpy+2:8ZpX69Q8y |
MD5: | 2ADC7534F55BC20A70CD78193BA296F8 |
SHA1: | E48ABC2660AABDFD0C9543DCAEA9F01B74B8BC44 |
SHA-256: | 06221C2C850B94E382FE9386446DFB6BB941EBD179975FEABF342AF3950A7BE3 |
SHA-512: | 00E9E810D6246E8C633E06AF7AECFB860CCA8A1DEDD52A263F4B29324A7933CBE6ADBEBA22DB35C3FAABC16901256C21C071D05C9EA1DA0687E4C7FCD4510625 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.006938521370165 |
Encrypted: | false |
SSDEEP: | 48:8P0daTmqbHLidAKZdA14t5eh7sFiZUkmgqeh7sTy+BX:8PpXqnFy |
MD5: | 43B239A14CBD2B3E6798530604861D03 |
SHA1: | 5CAA94DB84FD838FEE7F0FB1E5035EA15BB42637 |
SHA-256: | 9B7E4A4398BA433CBDAB673C60DBCA5791918C31C16646191138E8F2A2851FCD |
SHA-512: | 3230E8D06CA85478059CDEC18CED96C00A16F5FD8889149C956D66E5A7561E8B1A5C561FB5E7FD32298F0982A0A84C2C131831C8AE2BA4B2FFF8CCE22453362A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9935064596147725 |
Encrypted: | false |
SSDEEP: | 48:8a0daTmqzHLidAKZdA16ehDiZUkwqeh9y+R:8apXxry |
MD5: | FDE20BF73E5AE34FEBDDC42523F7393D |
SHA1: | 33CE853227FCC210A609D89B2728EBEA10E1D2EB |
SHA-256: | 91A1FA2896BED617F7B999A174333046ED55999964A41ED4BDE1D6940405557D |
SHA-512: | 3BE82F5C3F002338ABCE980E8BE8454570F35E1920F47305BCA151B6663CC7FC5DE6FA58FD86DE3749AD8E2EF529F7465AEDEEF6C88904BCF686042C39725A9E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.983547418123504 |
Encrypted: | false |
SSDEEP: | 48:8A0daTmqzHLidAKZdA1UehBiZUk1W1qeh/y+C:8ApXx9fy |
MD5: | C0D3B0F86B808D2AF8BBDF021E8267F1 |
SHA1: | 3173EF7CB3942DEA1130120E9A7D1D87F596895E |
SHA-256: | 81EE1F14D45E0752770A11B28AD736F2A9A0822D82B6B6CF423612B827CA0806 |
SHA-512: | CB987DE2FD4BE51FD389B9095BD895CD4A7BF99F3E4296FE20C7FA1CE5CCB914EF3B982A7D456ADE5122AA004996BA9674D6A6A6CDF46C6C526CDE80BB14461F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9945064162904806 |
Encrypted: | false |
SSDEEP: | 48:8Z0daTmqzHLidAKZdA1duTrehOuTbbiZUk5OjqehOuTbFy+yT+:8ZpXOTYTbxWOvTbFy7T |
MD5: | 1607B855DDE5EBF898E56EAB7069408F |
SHA1: | 6358CC821DA77E6979627553061D0D2634B50DB5 |
SHA-256: | D7DC4903950ABA85A7E7E9F27ECAECE36B7B559DECB65A3D300CF32F60C121A9 |
SHA-512: | D478F97F671F399BB69E808AB6035ABEAF1770B2A0A5EDBB85C5DFA9E9947B4CB8C18BCFB48C26F5300C62EAE629C2652ED4319DFA69A5BF776A0B2FCBE01EAD |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.786919620216169 |
TrID: |
|
File name: | 1El22bCuSq.html |
File size: | 10'557 bytes |
MD5: | d208d81ab739dc43291c2076a8c01e62 |
SHA1: | 36074c3c2f409c773e42f962e7ce446783a29d5f |
SHA256: | 7d77653c3e9f83dd73da91f8ce6940323529515dadddcba3dbfb7be3dc623318 |
SHA512: | c7f9fed27c6b9d5de8d64d67fca440f5210ab76a27784987a3283e73d2a515b383cad68dad2656334d7539f31ee0d61e50a767f440dd9aab7dccd8ee47edca9e |
SSDEEP: | 192:4LgkJjnZJ0hQ1y3XIEgG+w3vl+/o8CMHNaPUpTrmmitxSv/kWm/T:4yQw3D+igD5p2AHkWM |
TLSH: | 212242927AAD48DF4005E15BE9147E497EEB40BE7BB7D71232B8387E6ED0420863831C |
File Content Preview: | <!DOCTYPE html>.<html lang="uk" data-bs-theme="light">.<head>.<STYLE TYPE="text/css">.@page SectionA {. margin-left: 20 mm;. margin-right: 10 mm;. margin-top: 10 mm;. margin-bottom: 10 mm;. mso-paper-source: 0;.}.DIV.Section {. page: SectionA;.}.BOD |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 26, 2024 13:50:30.722150087 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.725229979 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.743660927 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.743917942 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.743999004 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.746480942 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.746634960 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.751943111 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.767781973 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.767795086 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.767865896 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.770721912 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.771595955 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.771648884 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.771658897 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.771689892 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.771689892 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.774343014 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.779616117 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.852905989 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.855895996 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.874119043 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.874133110 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.874202967 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.874497890 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.874563932 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.874633074 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.877185106 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.877252102 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.882638931 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.898163080 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.900790930 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.901408911 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.901482105 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.903964996 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:30.909343958 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.983833075 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:30.987425089 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:31.004889965 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.004925966 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.004990101 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:31.008166075 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:31.008289099 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:31.014341116 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.028064013 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.031186104 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.031264067 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:31.114942074 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.138147116 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.138171911 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:50:31.138221979 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:31.188837051 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:50:31.438860893 CEST | 49671 | 443 | 192.168.2.8 | 204.79.197.203 |
Oct 26, 2024 13:50:31.798403978 CEST | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Oct 26, 2024 13:50:32.392106056 CEST | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 26, 2024 13:50:32.720177889 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 26, 2024 13:50:39.891985893 CEST | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
Oct 26, 2024 13:50:41.997997046 CEST | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 26, 2024 13:50:42.383348942 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 26, 2024 13:50:42.492722988 CEST | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Oct 26, 2024 13:50:44.088849068 CEST | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Oct 26, 2024 13:50:44.088936090 CEST | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 26, 2024 13:50:45.477463007 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:45.477538109 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:45.477646112 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:45.481623888 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:45.481646061 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:46.167239904 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:46.167362928 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:46.167566061 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:46.168962002 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:46.169015884 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:46.339330912 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:46.339603901 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:46.339632988 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:46.340660095 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:46.340732098 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:46.486088037 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:46.486238003 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:46.616676092 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:46.616693020 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:46.725759029 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:47.014695883 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.014938116 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.018625021 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.018651962 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.019068956 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.071304083 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.160522938 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.203337908 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.568227053 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.568398952 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.568548918 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.568550110 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.568646908 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.568694115 CEST | 49714 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.568713903 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.606678009 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.606765985 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:47.606966972 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.607121944 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:47.607146025 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:48.460279942 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:48.460366011 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:48.461904049 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:48.461946964 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:48.462379932 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:48.463510036 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:48.507350922 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:48.709597111 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:48.709662914 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:48.709723949 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:48.710666895 CEST | 49715 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 26, 2024 13:50:48.710680008 CEST | 443 | 49715 | 184.28.90.27 | 192.168.2.8 |
Oct 26, 2024 13:50:52.629590034 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:52.629683971 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:52.629812002 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:52.631041050 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:52.631076097 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:53.422636032 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:53.422836065 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:53.424932003 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:53.424951077 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:53.425205946 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:53.477813005 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.115187883 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.159337044 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.373883963 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.373912096 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.373919010 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.373964071 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.373976946 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.374006987 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.374027014 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.374062061 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.374080896 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.374082088 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.374082088 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.374105930 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.374732018 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.374805927 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:54.374815941 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.374944925 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:54.374993086 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:55.245007992 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:55.245007992 CEST | 49716 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:50:55.245079994 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:55.245112896 CEST | 443 | 49716 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:50:56.338299990 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:56.338458061 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:50:56.338520050 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:56.712229967 CEST | 49713 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:50:56.712261915 CEST | 443 | 49713 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:31.738358021 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:31.738471985 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:31.738553047 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:31.738934994 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:31.738969088 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.552207947 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.552298069 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.555851936 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.555875063 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.556201935 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.561455965 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.603332043 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.824877024 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.824954033 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.824999094 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.825032949 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.825093985 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.825130939 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.825155973 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.826332092 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.826384068 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.826404095 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.826421976 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.826450109 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.827025890 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.827086926 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.828186035 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.828229904 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:32.828257084 CEST | 49726 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 26, 2024 13:51:32.828273058 CEST | 443 | 49726 | 20.109.210.53 | 192.168.2.8 |
Oct 26, 2024 13:51:45.641901016 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:45.641957998 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:45.642034054 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:45.642261982 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:45.642280102 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:46.728976965 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:46.729378939 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:46.729413986 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:46.729796886 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:46.730144978 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:46.730222940 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:46.774600029 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:56.733558893 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:56.733633995 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:51:56.733926058 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:57.927402973 CEST | 49728 | 443 | 192.168.2.8 | 142.250.186.164 |
Oct 26, 2024 13:51:57.927460909 CEST | 443 | 49728 | 142.250.186.164 | 192.168.2.8 |
Oct 26, 2024 13:52:01.134293079 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:52:01.135062933 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 26, 2024 13:52:01.135118008 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:52:01.135211945 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 26, 2024 13:52:01.140522003 CEST | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 26, 2024 13:50:40.887902975 CEST | 53 | 52654 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:50:40.888464928 CEST | 53 | 57307 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:50:42.350502968 CEST | 53 | 62824 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:50:45.458894968 CEST | 60344 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 26, 2024 13:50:45.459290981 CEST | 55807 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 26, 2024 13:50:45.466686964 CEST | 53 | 60344 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:50:45.466967106 CEST | 53 | 55807 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:50:53.487464905 CEST | 53 | 54685 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:50:59.428646088 CEST | 53 | 52362 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:51:18.132899046 CEST | 53 | 54862 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:51:20.606221914 CEST | 138 | 138 | 192.168.2.8 | 192.168.2.255 |
Oct 26, 2024 13:51:40.738132000 CEST | 53 | 50076 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:51:41.033348083 CEST | 53 | 62191 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:52:09.902304888 CEST | 53 | 54802 | 1.1.1.1 | 192.168.2.8 |
Oct 26, 2024 13:52:54.310283899 CEST | 53 | 60275 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 26, 2024 13:50:45.458894968 CEST | 192.168.2.8 | 1.1.1.1 | 0x518e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 26, 2024 13:50:45.459290981 CEST | 192.168.2.8 | 1.1.1.1 | 0x607 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 26, 2024 13:50:45.466686964 CEST | 1.1.1.1 | 192.168.2.8 | 0x518e | No error (0) | 142.250.186.164 | A (IP address) | IN (0x0001) | false | ||
Oct 26, 2024 13:50:45.466967106 CEST | 1.1.1.1 | 192.168.2.8 | 0x607 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49714 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-26 11:50:47 UTC | 161 | OUT | |
2024-10-26 11:50:47 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49715 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-26 11:50:48 UTC | 239 | OUT | |
2024-10-26 11:50:48 UTC | 515 | IN | |
2024-10-26 11:50:48 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49716 | 20.109.210.53 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-26 11:50:54 UTC | 306 | OUT | |
2024-10-26 11:50:54 UTC | 560 | IN | |
2024-10-26 11:50:54 UTC | 15824 | IN | |
2024-10-26 11:50:54 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49726 | 20.109.210.53 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-26 11:51:32 UTC | 306 | OUT | |
2024-10-26 11:51:32 UTC | 560 | IN | |
2024-10-26 11:51:32 UTC | 15824 | IN | |
2024-10-26 11:51:32 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 07:50:36 |
Start date: | 26/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 2 |
Start time: | 07:50:39 |
Start date: | 26/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |