Windows
Analysis Report
https://blackshelter.org
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 3812 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2876 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1732 --fi eld-trial- handle=195 2,i,990596 2315094133 029,129466 9945762788 150,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 5860 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://black shelter.or g" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.181.68 | true | false | high | |
blackshelter.org | 185.228.234.75 | true | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
185.228.234.75 | blackshelter.org | Russian Federation | 64439 | ITOS-ASRU | false | |
142.250.181.68 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1573316 |
Start date and time: | 2024-12-11 20:12:17 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://blackshelter.org |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@18/6@4/4 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- URL not reachable
- Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.21.35, 172.217.19.238, 64.233.162.84, 172.217.17.46, 199.232.214.172, 192.229.221.95, 23.218.208.109, 20.109.210.53, 13.107.246.63
- Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, www.gstatic.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://blackshelter.org
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.980850018363937 |
Encrypted: | false |
SSDEEP: | 48:8vdQcTwA3PPHiidAKZdA19ehwiZUklqehRdy+3:8ScEgYwdy |
MD5: | 391D222C64F0F37138B738D54B45DAD9 |
SHA1: | 14CDFD559CFD3439233F33F9FCFE729B68BB1D5E |
SHA-256: | E5BA3AC1BECC132B718461A0F5F8CD9FA0EC6159F9FD944D43A9C2D50D3BC496 |
SHA-512: | 1EBDC313E9BDBF775C49336523FBA0B080E5999CEB9BCEFD1E4FCF4F7842F617E769E4491EA54FFF03FBF4EC11EEC07E3D800C3CA5DF0F3234FE4D888E01A92A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9942448632205014 |
Encrypted: | false |
SSDEEP: | 48:8BdQcTwA3PPHiidAKZdA1weh/iZUkAQkqehgdy+2:80cEgy9Q/dy |
MD5: | B15B3D4C1FD8880985EE871508D24F8A |
SHA1: | 926C4A61F033DB990CF19438F6B05B779CEAF9EA |
SHA-256: | 3592492482B0A1A85067994140BE33EEB55F198B5BE517F485EFB42F7C138F5F |
SHA-512: | 73684AAE34887645A285DEC3D291FE0A29A32A1DFAD7339E216E2FC390882627DA163D47FEC3372F7BFC5D4B2123A7071FD24A921F3DC199510B567BB8098047 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.010734175712871 |
Encrypted: | false |
SSDEEP: | 48:8xYdQcTwA3sHiidAKZdA14tseh7sFiZUkmgqeh7sGdy+BX:8xHcEg7ncdy |
MD5: | 2B97118DC4B511BEF22EC1A36F93F5F9 |
SHA1: | 34622EE4E326D09C1F16B3E428BA502E461D0FB4 |
SHA-256: | C2EA389F18E7F1FD4F0AB405F90D6AB134733103175773600BFDEC9334D1FAB2 |
SHA-512: | 9BEB4E934A7FF2089E394F1CB7EFF07E6C036AFC7BA571379EEE9D41116779C9DC4CD9C13316483D150480AD291817D882F03C56AFDECBE64E0E113AFFE7F974 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9944544989005615 |
Encrypted: | false |
SSDEEP: | 48:8adQcTwA3PPHiidAKZdA1vehDiZUkwqehEdy+R:8xcEgZudy |
MD5: | FB535DC9BC5E8265FCFA7B4906856136 |
SHA1: | FAA202E9C4D9E817C6C8A57FAC6B172FFA1B1813 |
SHA-256: | 2E16691982CD8194109BF21F7483411769D5968B4DD28276AFF6E3DA2EE3F060 |
SHA-512: | 98809489D850E5EDBAC76CD4CEA50FC7A128BE54EDAF164AFF01EBCE6868F9B060B0F01117C851F6A877C1FE9691364711B091B0320FB014F249C42F2B404571 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.983030388120461 |
Encrypted: | false |
SSDEEP: | 48:8CdQcTwA3PPHiidAKZdA1hehBiZUk1W1qehCdy+C:8ZcEgp9idy |
MD5: | 760E80B73608A0C83597387554CC820C |
SHA1: | 59A92410C43A5E5011DC5BBFF054FCDB18FFBC37 |
SHA-256: | E3E792B3CE3ABAC7936F11794DF46D31D8FB55BE01DC1ABDB806B76267258F4A |
SHA-512: | 620790701767F761406BCB4F03BA7C0C93DFFFC1F3C61D062AA4B0B5F7E039A3E7E1D99CD732134254F8D333C9DF513625066050CC7AA37BACB678EF385EC7AD |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.991895962026611 |
Encrypted: | false |
SSDEEP: | 48:8YdQcTwA3PPHiidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbcdy+yT+:8HcEg1T/TbxWOvTbcdy7T |
MD5: | 838059C39087E83BF898D410A378F130 |
SHA1: | ADB6408DBC637AB47FD8E811D1951FC9DD6CE220 |
SHA-256: | F9828F14EF1D7C69FC67A7CC5F588D7A695236DB0732FF54F1D79EC4BDDF7D9D |
SHA-512: | 1651419CBD164BAD8AE21396B8E0CFB674BB0200DD2E6373D8CDCFE0EDEDB0AFAE23465000612E39EB40437F6FAC09CA1F4E83C154D12295DA8C0F46CCA44719 |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 11, 2024 20:13:03.418587923 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 11, 2024 20:13:03.424611092 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 11, 2024 20:13:03.512294054 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 11, 2024 20:13:12.042149067 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:12.042197943 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:12.042296886 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:12.042572975 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:12.042584896 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:13.020376921 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 11, 2024 20:13:13.024801970 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 11, 2024 20:13:13.116328955 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 11, 2024 20:13:13.738390923 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:13.739047050 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:13.739109993 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:13.740797043 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:13.740953922 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:13.747431040 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:13.747524977 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:13.792284966 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:13.792351961 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:13.838788033 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:14.207379103 CET | 49714 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:14.207479954 CET | 443 | 49714 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:14.207664013 CET | 49714 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:14.208281040 CET | 49714 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:14.208282948 CET | 49715 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:14.208297014 CET | 443 | 49714 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:14.208334923 CET | 443 | 49715 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:14.208493948 CET | 49715 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:14.208766937 CET | 49715 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:14.208780050 CET | 443 | 49715 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:15.552526951 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Dec 11, 2024 20:13:15.552639008 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Dec 11, 2024 20:13:23.427443981 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:23.427599907 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:23.427730083 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:23.605238914 CET | 49712 | 443 | 192.168.2.5 | 142.250.181.68 |
Dec 11, 2024 20:13:23.605293036 CET | 443 | 49712 | 142.250.181.68 | 192.168.2.5 |
Dec 11, 2024 20:13:44.217504025 CET | 49714 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:44.217726946 CET | 443 | 49714 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:44.217778921 CET | 49715 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:44.217797041 CET | 49714 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:44.218024015 CET | 443 | 49715 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:44.218126059 CET | 49715 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:45.281413078 CET | 49763 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:45.281452894 CET | 443 | 49763 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:45.281538010 CET | 49763 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:45.281893015 CET | 49764 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:45.281935930 CET | 443 | 49764 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:45.282011032 CET | 49764 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:45.282382965 CET | 49763 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:45.282397032 CET | 443 | 49763 | 185.228.234.75 | 192.168.2.5 |
Dec 11, 2024 20:13:45.282524109 CET | 49764 | 443 | 192.168.2.5 | 185.228.234.75 |
Dec 11, 2024 20:13:45.282538891 CET | 443 | 49764 | 185.228.234.75 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 11, 2024 20:13:07.573960066 CET | 53 | 56864 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:07.584669113 CET | 53 | 61030 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:10.557200909 CET | 53 | 60657 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:11.901354074 CET | 52727 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 11, 2024 20:13:11.901494980 CET | 56506 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 11, 2024 20:13:12.039654016 CET | 53 | 52727 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:12.040884972 CET | 53 | 56506 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:13.486849070 CET | 59773 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 11, 2024 20:13:13.488611937 CET | 55097 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 11, 2024 20:13:14.112452984 CET | 53 | 55097 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:14.206598997 CET | 53 | 59773 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:27.415153980 CET | 53 | 58771 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:43.592123032 CET | 53 | 54360 | 1.1.1.1 | 192.168.2.5 |
Dec 11, 2024 20:13:46.289084911 CET | 53 | 54856 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 11, 2024 20:13:11.901354074 CET | 192.168.2.5 | 1.1.1.1 | 0xff12 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 11, 2024 20:13:11.901494980 CET | 192.168.2.5 | 1.1.1.1 | 0x7452 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 11, 2024 20:13:13.486849070 CET | 192.168.2.5 | 1.1.1.1 | 0xe300 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 11, 2024 20:13:13.488611937 CET | 192.168.2.5 | 1.1.1.1 | 0x2c71 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 11, 2024 20:13:12.039654016 CET | 1.1.1.1 | 192.168.2.5 | 0xff12 | No error (0) | 142.250.181.68 | A (IP address) | IN (0x0001) | false | ||
Dec 11, 2024 20:13:12.040884972 CET | 1.1.1.1 | 192.168.2.5 | 0x7452 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 11, 2024 20:13:14.206598997 CET | 1.1.1.1 | 192.168.2.5 | 0xe300 | No error (0) | 185.228.234.75 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 14:13:02 |
Start date: | 11/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 14:13:05 |
Start date: | 11/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 14:13:12 |
Start date: | 11/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |