Windows
Analysis Report
http://www.firsthealthbp.com
Overview
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 3916 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2828 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2436 --fi eld-trial- handle=223 2,i,957327 2668436057 6,16647637 5639710787 68,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction /pre fetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6504 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://www.fi rsthealthb p.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
100% | SlashNext | Rogue Software type: Phishing & Social Engineering |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.181.68 | true | false | high | |
www.firsthealthbp.com | 103.224.212.254 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false |
| unknown | |
false |
| unknown | |
true |
| unknown | |
true | unknown | ||
true |
| unknown | |
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
103.224.212.254 | www.firsthealthbp.com | Australia | 133618 | TRELLIAN-AS-APTrellianPtyLimitedAU | true | |
142.250.181.68 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1573321 |
Start date and time: | 2024-12-11 20:21:01 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://www.firsthealthbp.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal52.win@19/9@8/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.21.35, 64.233.162.84, 172.217.19.238, 142.250.181.142, 199.232.210.172, 192.229.221.95, 172.217.17.35, 23.218.208.109, 172.202.163.200, 13.107.246.63
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: http://www.firsthealthbp.com
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 94 |
Entropy (8bit): | 4.648751656165808 |
Encrypted: | false |
SSDEEP: | 3:qVZqcMsMgs0UL3AE+FoJRx+QVBK3z:qzsgs0HE+2XVBmz |
MD5: | E96DDCEB1C305B9AD21EAAE42522C26F |
SHA1: | AD08AE39A71ED5BA992B8B5DABC450D046354696 |
SHA-256: | 9221CFEDFC5E03790F46C7890BCA21FCC47C5788D89DAB0AA0799C492B6AE78A |
SHA-512: | 1CC850F76467645447E9935F4DE13EDE698727B4FB598C7BD36DE2779596D8B5A85CB94B0CF1FB2259AD1D988F1F199E3F4C310DFDC22FCDD378B8E773F0DBD5 |
Malicious: | false |
Reputation: | low |
URL: | https://www.firsthealthbp.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 34240 |
Entropy (8bit): | 5.66430270686102 |
Encrypted: | false |
SSDEEP: | 384:XhQYTcHRx9vfQxcuK83ERxXYxMvtTpIBNwBUZXLew5gc+RW7+5ERNFaqE8E0QI+V:XSbHRTArOGSoyISuNwxJzZbPePKe9y |
MD5: | 63F9FD621D1FBD53B7C5856E58C11CCD |
SHA1: | A46973C2FBDBFEB159E0D717A90F88307E274012 |
SHA-256: | C6BC28686490ABA34A53AB3B709AFA1FD73C21E60FEB25608B09F23EFE170089 |
SHA-512: | D4DF433C7368EC078FBC473398A4AB21E6DA20950AC4DB34338623296887DB40320B05B9BDE6130E43D2B55C82B81A56B60BAB0D6A4C97DF54A0CB7A8F09325B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1065 |
Entropy (8bit): | 5.1887447702390075 |
Encrypted: | false |
SSDEEP: | 24:esKNVvPCwlrGFAFybrPXvMXc7RdoFynaYJ36nGTwdnObkMxir+T:vcAKybrPXkWRkyx0dn8Pxir+T |
MD5: | EEE986773246D27C5BDF48AFAF619681 |
SHA1: | D3137013CDD7B69F702AECAE135863CD6962C147 |
SHA-256: | DF8A6FA40C52AF85AD68BB78CCDA803FE5F6D30328D8D89F8AECD630BED95DD6 |
SHA-512: | 352277D036E0A27F81C100808FEAB890D8BD46BB6EE536380D7AB2B8D6E117799048759DBF2655CA0006F41815F8FA72252634A28A197535BF045384F8F2DFAB |
Malicious: | false |
Reputation: | low |
URL: | https://www.firsthealthbp.com/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 34240 |
Entropy (8bit): | 5.66430270686102 |
Encrypted: | false |
SSDEEP: | 384:XhQYTcHRx9vfQxcuK83ERxXYxMvtTpIBNwBUZXLew5gc+RW7+5ERNFaqE8E0QI+V:XSbHRTArOGSoyISuNwxJzZbPePKe9y |
MD5: | 63F9FD621D1FBD53B7C5856E58C11CCD |
SHA1: | A46973C2FBDBFEB159E0D717A90F88307E274012 |
SHA-256: | C6BC28686490ABA34A53AB3B709AFA1FD73C21E60FEB25608B09F23EFE170089 |
SHA-512: | D4DF433C7368EC078FBC473398A4AB21E6DA20950AC4DB34338623296887DB40320B05B9BDE6130E43D2B55C82B81A56B60BAB0D6A4C97DF54A0CB7A8F09325B |
Malicious: | false |
Reputation: | low |
URL: | https://www.firsthealthbp.com/js/fingerprint/iife.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 19 |
Entropy (8bit): | 3.6163485660751657 |
Encrypted: | false |
SSDEEP: | 3:j4JELzY:SizY |
MD5: | 305CB0AE3D04BBB8913F1DB08A427936 |
SHA1: | F8B644FB4A33E5175ECEC45FD89994A681CE6667 |
SHA-256: | 54CCB48F3C66AED9F45099B18E1A15739746C03CDC958EBF061C4327CD5D6373 |
SHA-512: | 6E5C6098772AA278C5B5A16DFA068E93DEF472093D077DB9DE3A836C1276B91C07AFE23E7F1C00962159DE3A7896D55BD5E4D7DAA25921C45F7CE66E3BFF55FB |
Malicious: | false |
Reputation: | low |
URL: | https://www.firsthealthbp.com/?fp=5705e961739f25e027541c9b53d6b936 |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 11, 2024 20:21:51.110539913 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Dec 11, 2024 20:22:00.718399048 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Dec 11, 2024 20:22:02.658119917 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:02.658169031 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:02.658224106 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:02.658569098 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:02.658584118 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:04.378614902 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:04.378895998 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:04.378958941 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:04.380435944 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:04.380518913 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:04.381438017 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:04.381526947 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:04.424253941 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:04.424278021 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:04.470870972 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:04.841355085 CET | 49740 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:04.841701984 CET | 49741 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:04.935653925 CET | 49742 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:04.960800886 CET | 80 | 49740 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:04.960875988 CET | 49740 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:04.961071014 CET | 49740 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:04.961179018 CET | 80 | 49741 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:04.961642981 CET | 49741 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:05.055116892 CET | 80 | 49742 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:05.055188894 CET | 49742 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:05.080600977 CET | 80 | 49740 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:06.264036894 CET | 80 | 49740 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:06.264122009 CET | 80 | 49740 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:06.264262915 CET | 49740 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:06.313112974 CET | 49740 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:06.434247017 CET | 80 | 49740 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:06.467076063 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:06.467120886 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:06.467180967 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:06.467453003 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:06.467470884 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.023657084 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.023983955 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.024059057 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.024594069 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.024717093 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.025202036 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.025262117 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.030843019 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.030919075 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.030994892 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.031025887 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.080076933 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.633452892 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.633660078 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.634799004 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.638174057 CET | 49744 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.638217926 CET | 443 | 49744 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.683231115 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.683295012 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:08.683399916 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.683614016 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:08.683630943 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.229760885 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.230148077 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.230226994 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.230716944 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.231019974 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.231096029 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.231148005 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.271358967 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.278369904 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.779206991 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.779270887 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.779475927 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.779551029 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.779627085 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.812417030 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.812446117 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.812489033 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.812565088 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.812643051 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.812707901 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.994034052 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.994102001 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.994210005 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.994283915 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:10.994327068 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:10.994327068 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.003591061 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.003722906 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.003782988 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.003825903 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.003854990 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.003885031 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.012180090 CET | 49745 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.012245893 CET | 443 | 49745 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.048933983 CET | 80 | 49741 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.048953056 CET | 80 | 49741 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.049047947 CET | 49741 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.052159071 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.052251101 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.052350998 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.052572966 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.052608967 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.221514940 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.221616983 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.221724987 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.221968889 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.221996069 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.224242926 CET | 80 | 49742 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.224410057 CET | 80 | 49742 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.224498987 CET | 49742 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.402676105 CET | 49741 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.402676105 CET | 49741 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.402985096 CET | 49742 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.402985096 CET | 49742 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.403321028 CET | 49748 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.489377022 CET | 49749 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.529294014 CET | 80 | 49741 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.529313087 CET | 80 | 49741 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.529733896 CET | 80 | 49742 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.529747009 CET | 80 | 49742 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.529761076 CET | 80 | 49748 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.529973030 CET | 49748 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.530134916 CET | 49748 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.614981890 CET | 80 | 49749 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:11.615194082 CET | 49749 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:11.654643059 CET | 80 | 49748 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.765142918 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.768116951 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.768145084 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.768464088 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.768898964 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.768944979 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.769231081 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.797271013 CET | 80 | 49748 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.797318935 CET | 80 | 49748 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.797498941 CET | 49748 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.797631025 CET | 49748 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.799722910 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.799793005 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.799864054 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.800081015 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.800102949 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.811347961 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.881237030 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.881587982 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.881650925 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.882890940 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.882966995 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.885396004 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.885481119 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.885596037 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.885711908 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.885775089 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.917680025 CET | 80 | 49748 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.937665939 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:12.937726021 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:12.984090090 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.274183035 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.274266005 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.274343014 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.277033091 CET | 49746 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.277075052 CET | 443 | 49746 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.426531076 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.426561117 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.426570892 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.426604033 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.426618099 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.426624060 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.426743031 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.426743031 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.426816940 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.469835997 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.605756998 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.605773926 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.605834007 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.605845928 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.605859041 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.605935097 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.605977058 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.606004953 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.612626076 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.612715960 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.612730980 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.612787008 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.612818956 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:13.612874985 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.613339901 CET | 49747 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:13.613370895 CET | 443 | 49747 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:14.079601049 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:14.079694033 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:14.079916954 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:14.351541996 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:14.351804972 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:14.351841927 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:14.353018999 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:14.353363991 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:14.353512049 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:14.353521109 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:14.353538990 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:14.394136906 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:14.832586050 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:22:14.832655907 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:22:15.099739075 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:15.099950075 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:15.100008965 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:15.116367102 CET | 49750 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:15.116391897 CET | 443 | 49750 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:15.129750013 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:15.129838943 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:15.129909992 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:15.130115032 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:15.130156040 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:16.719706059 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:16.720122099 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:16.720187902 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:16.720576048 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:16.720935106 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:16.721007109 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:16.721033096 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:16.763331890 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:16.774938107 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:17.237309933 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:17.237392902 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:17.237462044 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:17.238605976 CET | 49752 | 443 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:17.238647938 CET | 443 | 49752 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:17.659420013 CET | 80 | 49749 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:17.659456968 CET | 80 | 49749 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:22:17.659506083 CET | 49749 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:22:18.482158899 CET | 80 | 49723 | 217.20.56.99 | 192.168.2.4 |
Dec 11, 2024 20:22:18.482333899 CET | 49723 | 80 | 192.168.2.4 | 217.20.56.99 |
Dec 11, 2024 20:22:18.482333899 CET | 49723 | 80 | 192.168.2.4 | 217.20.56.99 |
Dec 11, 2024 20:22:18.602869034 CET | 80 | 49723 | 217.20.56.99 | 192.168.2.4 |
Dec 11, 2024 20:22:29.488795996 CET | 80 | 49724 | 217.20.58.99 | 192.168.2.4 |
Dec 11, 2024 20:22:29.488931894 CET | 49724 | 80 | 192.168.2.4 | 217.20.58.99 |
Dec 11, 2024 20:22:29.489016056 CET | 49724 | 80 | 192.168.2.4 | 217.20.58.99 |
Dec 11, 2024 20:22:29.613969088 CET | 80 | 49724 | 217.20.58.99 | 192.168.2.4 |
Dec 11, 2024 20:23:02.580265999 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:02.580315113 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:02.580370903 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:02.580786943 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:02.580805063 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:02.665601015 CET | 49749 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:23:02.785408974 CET | 80 | 49749 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:23:04.276406050 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:04.276832104 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:04.276865959 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:04.277964115 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:04.278382063 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:04.278562069 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:04.328337908 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:12.829341888 CET | 49749 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:23:12.829341888 CET | 49749 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:23:12.949245930 CET | 80 | 49749 | 103.224.212.254 | 192.168.2.4 |
Dec 11, 2024 20:23:12.949356079 CET | 49749 | 80 | 192.168.2.4 | 103.224.212.254 |
Dec 11, 2024 20:23:13.967427969 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:13.967587948 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Dec 11, 2024 20:23:13.967772007 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:14.830128908 CET | 49776 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 11, 2024 20:23:14.830153942 CET | 443 | 49776 | 142.250.181.68 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 11, 2024 20:21:58.754271984 CET | 53 | 58067 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:01.568717003 CET | 53 | 57387 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:02.517179012 CET | 60180 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:02.517318010 CET | 59949 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:02.655409098 CET | 53 | 60180 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:02.656992912 CET | 53 | 59949 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:04.135571957 CET | 65070 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:04.137155056 CET | 52459 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:04.840224981 CET | 53 | 65070 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:04.840838909 CET | 53 | 52459 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:06.316797018 CET | 54088 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:06.317203045 CET | 60138 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:06.456682920 CET | 53 | 54088 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:06.457056046 CET | 53 | 60138 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:11.056061029 CET | 50874 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:11.056194067 CET | 61478 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 11, 2024 20:22:11.199111938 CET | 53 | 50874 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:11.221095085 CET | 53 | 61478 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:14.152158976 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Dec 11, 2024 20:22:18.580705881 CET | 53 | 62944 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:37.535109043 CET | 53 | 56066 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:22:58.047234058 CET | 53 | 57399 | 1.1.1.1 | 192.168.2.4 |
Dec 11, 2024 20:23:00.170145988 CET | 53 | 53786 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 11, 2024 20:22:02.517179012 CET | 192.168.2.4 | 1.1.1.1 | 0x991c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 11, 2024 20:22:02.517318010 CET | 192.168.2.4 | 1.1.1.1 | 0x9592 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 11, 2024 20:22:04.135571957 CET | 192.168.2.4 | 1.1.1.1 | 0xc4cb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 11, 2024 20:22:04.137155056 CET | 192.168.2.4 | 1.1.1.1 | 0x3a6e | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 11, 2024 20:22:06.316797018 CET | 192.168.2.4 | 1.1.1.1 | 0x9aed | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 11, 2024 20:22:06.317203045 CET | 192.168.2.4 | 1.1.1.1 | 0xe34c | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 11, 2024 20:22:11.056061029 CET | 192.168.2.4 | 1.1.1.1 | 0x89a1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 11, 2024 20:22:11.056194067 CET | 192.168.2.4 | 1.1.1.1 | 0x5c6d | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 11, 2024 20:22:02.655409098 CET | 1.1.1.1 | 192.168.2.4 | 0x991c | No error (0) | 142.250.181.68 | A (IP address) | IN (0x0001) | false | ||
Dec 11, 2024 20:22:02.656992912 CET | 1.1.1.1 | 192.168.2.4 | 0x9592 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 11, 2024 20:22:04.840224981 CET | 1.1.1.1 | 192.168.2.4 | 0xc4cb | No error (0) | 103.224.212.254 | A (IP address) | IN (0x0001) | false | ||
Dec 11, 2024 20:22:06.456682920 CET | 1.1.1.1 | 192.168.2.4 | 0x9aed | No error (0) | 103.224.212.254 | A (IP address) | IN (0x0001) | false | ||
Dec 11, 2024 20:22:11.199111938 CET | 1.1.1.1 | 192.168.2.4 | 0x89a1 | No error (0) | 103.224.212.254 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49740 | 103.224.212.254 | 80 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 11, 2024 20:22:04.961071014 CET | 436 | OUT | |
Dec 11, 2024 20:22:06.264036894 CET | 291 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49741 | 103.224.212.254 | 80 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 11, 2024 20:22:11.048933983 CET | 233 | IN | |
Dec 11, 2024 20:22:11.402676105 CET | 476 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49742 | 103.224.212.254 | 80 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 11, 2024 20:22:11.224242926 CET | 233 | IN | |
Dec 11, 2024 20:22:11.402985096 CET | 476 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49748 | 103.224.212.254 | 80 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 11, 2024 20:22:11.530134916 CET | 506 | OUT | |
Dec 11, 2024 20:22:12.797271013 CET | 231 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49749 | 103.224.212.254 | 80 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 11, 2024 20:22:17.659420013 CET | 233 | IN | |
Dec 11, 2024 20:23:02.665601015 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49744 | 103.224.212.254 | 443 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-11 19:22:08 UTC | 698 | OUT | |
2024-12-11 19:22:08 UTC | 176 | IN | |
2024-12-11 19:22:08 UTC | 1065 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49745 | 103.224.212.254 | 443 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-11 19:22:10 UTC | 587 | OUT | |
2024-12-11 19:22:10 UTC | 271 | IN | |
2024-12-11 19:22:10 UTC | 4073 | IN | |
2024-12-11 19:22:10 UTC | 10136 | IN | |
2024-12-11 19:22:10 UTC | 16320 | IN | |
2024-12-11 19:22:11 UTC | 3711 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49746 | 103.224.212.254 | 443 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-11 19:22:12 UTC | 632 | OUT | |
2024-12-11 19:22:13 UTC | 76 | IN | |
2024-12-11 19:22:13 UTC | 94 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49747 | 103.224.212.254 | 443 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-11 19:22:12 UTC | 405 | OUT | |
2024-12-11 19:22:13 UTC | 271 | IN | |
2024-12-11 19:22:13 UTC | 14209 | IN | |
2024-12-11 19:22:13 UTC | 16320 | IN | |
2024-12-11 19:22:13 UTC | 3711 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49750 | 103.224.212.254 | 443 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-11 19:22:14 UTC | 720 | OUT | |
2024-12-11 19:22:15 UTC | 151 | IN | |
2024-12-11 19:22:15 UTC | 19 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49752 | 103.224.212.254 | 443 | 2828 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-11 19:22:16 UTC | 668 | OUT | |
2024-12-11 19:22:17 UTC | 76 | IN | |
2024-12-11 19:22:17 UTC | 94 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 14:21:54 |
Start date: | 11/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 14:21:56 |
Start date: | 11/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 14:22:03 |
Start date: | 11/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |