Windows
Analysis Report
http://45.17.195.156
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 1292 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6204 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2084 --fi eld-trial- handle=200 0,i,137176 8553676033 4418,18077 5335534062 98805,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 5668 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://45.17. 195.156" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.185.228 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.185.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
45.17.195.156 | unknown | United States | 7018 | ATT-INTERNET4US | false |
IP |
---|
192.168.2.8 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1543825 |
Start date and time: | 2024-10-28 14:24:11 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://45.17.195.156 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | UNKNOWN |
Classification: | unknown0.win@20/6@2/4 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- URL not reachable
- Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.185.238, 74.125.71.84, 34.104.35.123, 184.28.90.27, 4.175.87.197, 2.19.126.154, 2.19.126.137, 192.229.221.95, 52.165.164.15
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
- VT rate limit hit for: http://45.17.195.156
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9734806107570306 |
Encrypted: | false |
SSDEEP: | 48:8160dqTWu/HjidAKZdA1oehwiZUklqehZy+3:8EFDkOy |
MD5: | 00FC2AE53E1AEFCA68C6EEBBC00D2E50 |
SHA1: | 5F3AB8694D574A8A9C96136217AACB73E1F50480 |
SHA-256: | B4E7D799A635A25F4D185AB730F4F87E0D550DBCABC2AC00921CCB492AD64B0E |
SHA-512: | D939F37476B90A4735B43450C12A7C8782305E725D13CF796095D7DD6BEC74D5D5AEAE377F75030FF30D446BD34BD558B86A9243E0D4B5546DBA2532288C93A7 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.988270069947384 |
Encrypted: | false |
SSDEEP: | 48:8h60dqTWu/HjidAKZdA1leh/iZUkAQkqeh+y+2:8AFDW9Q3y |
MD5: | 9782A076400F7C97983B4433C2529B95 |
SHA1: | FA220A6565678F266458ECFB4CF0D33421091470 |
SHA-256: | A9F4D11448CCF1039001FFA03CEB2E3CC8E1D5B4F2F68A1058BFAEB3602F3434 |
SHA-512: | 989987042E2AEF61C241505826051535A1B47FD9E73F6CF0744BC5BCF8AED590E5D4316E65CF43B10A2EB63D8F75C437DEFFA9C46359FFE9251C526B170B3E11 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 3.9981131104955745 |
Encrypted: | false |
SSDEEP: | 48:8C60dqTWubHjidAKZdA14t5eh7sFiZUkmgqeh7ssy+BX:8DFD6nSy |
MD5: | 09C0CD26118AD3F91F8BE35EEC218BE9 |
SHA1: | DD413618D3AA8EDCF6399FC31C93FBA51AE6EA7A |
SHA-256: | 9D3418D39CDF8B2B8951FAD62E6F171517235134DE1D198F2FF586567A2EEA34 |
SHA-512: | 82FE463C11BBBFF719471B14EAB90FC1607899E1E640348B75D2598B701C8F6E413903BCDE966B4CC9CD38C9016B86E9150A7E98B33C706834C045C8738FC955 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9838062001822747 |
Encrypted: | false |
SSDEEP: | 48:82660dqTWu/HjidAKZdA16ehDiZUkwqehKy+R:82rFDNEy |
MD5: | C213DB55A6BB6A94CE440EB0576E9685 |
SHA1: | 18A3806DCB92E0385F0FEEC0C5687EDFD223E5F4 |
SHA-256: | 457A475F564733A5D0ED759F23B154B2C915F37E6E1C59DD2A991D7D6D51FBCC |
SHA-512: | 13615389BC48CD36509F77CC4495212F8F4C03F7AD68168FF49FBA8115ADF8CB7910A65AFB4A17FBDD3BFD64E4886B43B6B35F1335B16F1C6795FE702C21DE5C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.97297603624272 |
Encrypted: | false |
SSDEEP: | 48:8p60dqTWu/HjidAKZdA1UehBiZUk1W1qehgy+C:84FDt9Ay |
MD5: | C74F54E4E710DB1B56B2A2DF904C54F6 |
SHA1: | 13B725FF8DB650FD82F11F7FCB312F9DB587BC4D |
SHA-256: | 9BE1C6B8669772151626028448A1AC299641D4B7F0F32E9D6A10420D788E895B |
SHA-512: | CD2E106D2D9EE7A45DDC378A3B6F702CDECC9E6541A04DF53A9241C1F9FCEB5AF80598B9183B6BFFC1FDDFC773CF962C1DA2D0BE4BCED517430DDC95E476189E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9844844559857853 |
Encrypted: | false |
SSDEEP: | 48:86f60dqTWu/HjidAKZdA1duTrehOuTbbiZUk5OjqehOuTbSy+yT+:8vFDqTYTbxWOvTbSy7T |
MD5: | 2966C68C5D48E9B324767079C5A048CA |
SHA1: | 8AAB1CB2967D33ACBA8DD83B15BCF9095B64ADB3 |
SHA-256: | 22BBF88FD4FB74B3147D2C5425DFE156C4A002A4779F3C5DE44552E597BD87B1 |
SHA-512: | 95A9D0A42CB9CE84B7913FA03609DF098168C75D4258AC2196F93F0F90F1417763E51DBD9BC21517AF981BC989FBCA6874B6E95B6F790E00A775F4F9DB68722E |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 28, 2024 14:25:02.799622059 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.799721956 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.800915003 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.801059961 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.801836014 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.805093050 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.806349039 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.850768089 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.927237988 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.927325010 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.927387953 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.927409887 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.928261995 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.928332090 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.928412914 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.928608894 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.928663015 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.928884029 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.931905031 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.932230949 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.933044910 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.933522940 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.933667898 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:02.937182903 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.937521935 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.938606977 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.938855886 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:02.939299107 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.059228897 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.059247971 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.059359074 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.059442043 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.061763048 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.061846972 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.061867952 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.062390089 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.062442064 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.062453985 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.062573910 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.064049959 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.065198898 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.065282106 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.065831900 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.068118095 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.069545984 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.070573092 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.070804119 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.071171045 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.190146923 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.190217018 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.190229893 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.190313101 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.191239119 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.191296101 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.192418098 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.192441940 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.192456007 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.192470074 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.192490101 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.192528009 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.192827940 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.194180965 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.194228888 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.194606066 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.197107077 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.197192907 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.197700024 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.197945118 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.200046062 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.202799082 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.202992916 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.203376055 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.325297117 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.328254938 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.328273058 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.328351974 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.328367949 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.328423977 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.328509092 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.328758955 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.328814030 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.329349995 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.332238913 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.332441092 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.334678888 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.334994078 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.337650061 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.337909937 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.340030909 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.456883907 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.459470987 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.459527969 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.459542990 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.459582090 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.459618092 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.461426973 CET | 443 | 49703 | 13.107.246.45 | 192.168.2.8 |
Oct 28, 2024 14:25:03.503690958 CET | 49703 | 443 | 192.168.2.8 | 13.107.246.45 |
Oct 28, 2024 14:25:03.738226891 CET | 49671 | 443 | 192.168.2.8 | 204.79.197.203 |
Oct 28, 2024 14:25:04.238043070 CET | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 28, 2024 14:25:04.284964085 CET | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Oct 28, 2024 14:25:04.738073111 CET | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 28, 2024 14:25:12.253627062 CET | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
Oct 28, 2024 14:25:13.839236021 CET | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 28, 2024 14:25:14.339238882 CET | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 28, 2024 14:25:14.913944960 CET | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Oct 28, 2024 14:25:15.472563982 CET | 49710 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:15.472835064 CET | 49711 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:15.477983952 CET | 80 | 49710 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:15.478137970 CET | 80 | 49711 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:15.478204012 CET | 49710 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:15.478210926 CET | 49711 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:15.548615932 CET | 49712 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:15.548656940 CET | 443 | 49712 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:15.548732042 CET | 49712 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:15.548993111 CET | 49712 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:15.549001932 CET | 443 | 49712 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:15.935998917 CET | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Oct 28, 2024 14:25:15.936105967 CET | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 28, 2024 14:25:15.999882936 CET | 80 | 49711 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:15.999938965 CET | 49711 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.027333975 CET | 80 | 49710 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:16.027395964 CET | 49710 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.617573977 CET | 49711 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.617623091 CET | 49710 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.622988939 CET | 80 | 49711 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:16.623003960 CET | 80 | 49710 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:16.631696939 CET | 443 | 49712 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:16.631761074 CET | 49712 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.631964922 CET | 49712 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.632003069 CET | 443 | 49712 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:16.635230064 CET | 49715 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.635288000 CET | 443 | 49715 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:16.635356903 CET | 49715 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.635663033 CET | 49715 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:16.635685921 CET | 443 | 49715 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:17.950901031 CET | 443 | 49715 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:17.950993061 CET | 49715 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:17.961522102 CET | 49715 | 443 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:17.961544037 CET | 443 | 49715 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:17.963213921 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:17.963262081 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:17.964435101 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:17.964878082 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:17.964894056 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:17.988085032 CET | 49717 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:17.993619919 CET | 80 | 49717 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:17.993696928 CET | 49717 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:17.994090080 CET | 49717 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:17.999557972 CET | 80 | 49717 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:18.463496923 CET | 49717 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:18.510755062 CET | 80 | 49717 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:18.537451029 CET | 80 | 49717 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:18.537508011 CET | 49717 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:18.822134018 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:18.822462082 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:18.822526932 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:18.823568106 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:18.823637962 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:19.230408907 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:19.230576038 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:19.280531883 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:19.280589104 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:19.470801115 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:19.583127975 CET | 49719 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:19.583404064 CET | 49720 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:19.588696957 CET | 80 | 49719 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:19.588768005 CET | 80 | 49720 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:19.588804007 CET | 49719 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:19.588831902 CET | 49720 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:19.637388945 CET | 49720 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:19.642769098 CET | 80 | 49720 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.111886978 CET | 80 | 49719 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.113722086 CET | 49719 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.166961908 CET | 80 | 49720 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.169225931 CET | 49720 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.381791115 CET | 49720 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.382172108 CET | 49719 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.383018970 CET | 49721 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.387222052 CET | 80 | 49720 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.387531996 CET | 80 | 49719 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.388503075 CET | 80 | 49721 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.388573885 CET | 49721 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.389038086 CET | 49721 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.394409895 CET | 80 | 49721 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.944848061 CET | 80 | 49721 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:20.944912910 CET | 49721 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.945256948 CET | 49721 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:20.950985909 CET | 80 | 49721 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:22.052751064 CET | 49723 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.052877903 CET | 49724 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.224668980 CET | 80 | 49723 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:22.224682093 CET | 80 | 49724 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:22.224782944 CET | 49724 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.224782944 CET | 49723 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.225147009 CET | 49724 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.230978012 CET | 80 | 49724 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:22.746213913 CET | 80 | 49724 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:22.749218941 CET | 49724 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.752258062 CET | 80 | 49723 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:22.752330065 CET | 49723 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.835079908 CET | 49724 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:22.841978073 CET | 80 | 49724 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:23.671926975 CET | 49723 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:23.677453041 CET | 80 | 49723 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:27.790836096 CET | 49730 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:27.791258097 CET | 49731 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:27.796324015 CET | 80 | 49730 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:27.796391010 CET | 49730 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:27.796802998 CET | 80 | 49731 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:27.796911955 CET | 49731 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:27.821825981 CET | 49730 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:27.827230930 CET | 80 | 49730 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.326750040 CET | 80 | 49731 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.326859951 CET | 49731 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.332266092 CET | 80 | 49730 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.332329035 CET | 49730 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.334739923 CET | 49730 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.335776091 CET | 49731 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.336541891 CET | 49732 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.340204954 CET | 80 | 49730 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.341175079 CET | 80 | 49731 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.341833115 CET | 80 | 49732 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.341907024 CET | 49732 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.342324018 CET | 49732 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.347613096 CET | 80 | 49732 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.983962059 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:28.984029055 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Oct 28, 2024 14:25:28.984131098 CET | 80 | 49732 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:28.984201908 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:28.984220028 CET | 49732 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.984569073 CET | 49732 | 80 | 192.168.2.8 | 45.17.195.156 |
Oct 28, 2024 14:25:28.990076065 CET | 80 | 49732 | 45.17.195.156 | 192.168.2.8 |
Oct 28, 2024 14:25:29.669037104 CET | 49716 | 443 | 192.168.2.8 | 142.250.185.228 |
Oct 28, 2024 14:25:29.669064045 CET | 443 | 49716 | 142.250.185.228 | 192.168.2.8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 28, 2024 14:25:13.495038986 CET | 53 | 60691 | 1.1.1.1 | 192.168.2.8 |
Oct 28, 2024 14:25:13.510989904 CET | 53 | 55304 | 1.1.1.1 | 192.168.2.8 |
Oct 28, 2024 14:25:14.765366077 CET | 53 | 64371 | 1.1.1.1 | 192.168.2.8 |
Oct 28, 2024 14:25:17.901810884 CET | 59359 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 28, 2024 14:25:17.909909964 CET | 53 | 59359 | 1.1.1.1 | 192.168.2.8 |
Oct 28, 2024 14:25:17.911736012 CET | 49799 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 28, 2024 14:25:17.919157982 CET | 53 | 49799 | 1.1.1.1 | 192.168.2.8 |
Oct 28, 2024 14:25:32.286911964 CET | 53 | 50141 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 28, 2024 14:25:17.901810884 CET | 192.168.2.8 | 1.1.1.1 | 0xc2a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 14:25:17.911736012 CET | 192.168.2.8 | 1.1.1.1 | 0x2c64 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 28, 2024 14:25:17.909909964 CET | 1.1.1.1 | 192.168.2.8 | 0xc2a0 | No error (0) | 142.250.185.228 | A (IP address) | IN (0x0001) | false | ||
Oct 28, 2024 14:25:17.919157982 CET | 1.1.1.1 | 192.168.2.8 | 0x2c64 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 28, 2024 14:25:26.519970894 CET | 1.1.1.1 | 192.168.2.8 | 0x15b2 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 28, 2024 14:25:26.519970894 CET | 1.1.1.1 | 192.168.2.8 | 0x15b2 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49717 | 45.17.195.156 | 80 | 6204 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 28, 2024 14:25:17.994090080 CET | 428 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49720 | 45.17.195.156 | 80 | 6204 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 28, 2024 14:25:19.637388945 CET | 454 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49721 | 45.17.195.156 | 80 | 6204 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 28, 2024 14:25:20.389038086 CET | 454 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49724 | 45.17.195.156 | 80 | 6204 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 28, 2024 14:25:22.225147009 CET | 454 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49730 | 45.17.195.156 | 80 | 6204 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 28, 2024 14:25:27.821825981 CET | 454 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.8 | 49732 | 45.17.195.156 | 80 | 6204 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 28, 2024 14:25:28.342324018 CET | 454 | OUT |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 09:25:06 |
Start date: | 28/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 09:25:11 |
Start date: | 28/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 09:25:13 |
Start date: | 28/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |